Jump to content

Assistance needed


Recommended Posts

So if I followed the instructions correctly Im suppose to post this for assistance

Every time I try to install malware it goes and stop saying permission denied.

My screen background is blue, I know my software etc are still on the computer but I cant get to them. I tried other scans but I cant get this virus..off Frustrated :(

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_27

Run by Anna at 22:35:00 on 2012-01-08

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.495.96 [GMT -6:00]

.

AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}

.

============== Running Processes ===============

.

C:\PROGRA~1\AVG\AVG2012\avgrsx.exe

C:\Program Files\AVG\AVG2012\avgcsrvx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\Program Files\AVG\AVG2012\avgwdsvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\lxducoms.exe

C:\Program Files\AVG\AVG2012\avgnsx.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ltmoh\Ltmoh.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe

C:\Program Files\Lexmark 5600-6600 Series\lxduMsdMon.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\AVG\AVG2012\avgtray.exe

C:\Program Files\AVG Secure Search\vprot.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\System32\svchost.exe -k imgsvc

C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\System32\mshta.exe

C:\WINDOWS\System32\mshta.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\SoftwareDistribution\Download\Install\IE8-WindowsXP-x86-ENU.exe

c:\09d77ee047a5478352cf\update\iesetup.exe

C:\WINDOWS\System32\mshta.exe

C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

c:\09d77ee047a5478352cf\update\update.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.yahoo.com/

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyServer = http=127.0.0.1:50370

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll

BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.22\AVG Secure Search_toolbar.dll

TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File

TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.22\AVG Secure Search_toolbar.dll

{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [Google Update] "c:\documents and settings\anna\local settings\application data\google\update\GoogleUpdate.exe" /c

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe

uRun: [speedItUpEX] c:\program files\speeditup free\SpeedItUp.exe -MINI

uRun: [iSUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"

mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe

mRun: [AGRSMMSG] AGRSMMSG.exe

mRun: [soundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe

mRun: [soundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray

mRun: [TAudEffect] c:\program files\toshiba\taudeffect\TAudEff.exe /run

mRun: [dla] c:\windows\system32\dla\tfswctrl.exe

mRun: [CFSServ.exe] CFSServ.exe -NoClient

mRun: [lxdumon.exe] "c:\program files\lexmark 5600-6600 series\lxdumon.exe"

mRun: [lxduamon] "c:\program files\lexmark 5600-6600 series\lxduamon.exe"

mRun: [Lexmark 5600-6600 Series Fax Server] "c:\program files\lexmark 5600-6600 series\fm3032.exe" /s

mRun: [<NO NAME>]

mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"

mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"

mRun: [vProt] "c:\program files\avg secure search\vprot.exe"

mExplorerRun: [112442153] c:\docume~1\alluse~1\locals~1\temp\44c2f94c06b3bb3d.exe

uPolicies-explorer: NoDesktop = 1 (0x1)

uPolicies-system: DisableTaskMgr = 1 (0x1)

IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM

IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM

IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM

IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM

IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM

IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM

IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\anna\start menu\programs\imvu\Run IMVU.lnk

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab

DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab

DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab

DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} - hxxp://images.fotki.com/activex/FotkiUploader.cab

DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: DhcpNameServer = 192.168.2.1 192.168.2.1

TCP: Interfaces\{7B67BBD2-4DF6-42DA-AA1E-4FE16A76CFAD} : DhcpNameServer = 192.168.2.1 192.168.2.1

TCP: Interfaces\{C8B4A023-86B9-46CA-853D-55C908791CF1} : DhcpNameServer = 207.69.188.186 207.69.188.187

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\9.0.1\ViProtocol.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

LSA: Authentication Packages = msv1_0 nwprovau

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\anna\application data\mozilla\firefox\profiles\dxjt8jqw.default\

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: browser.search.selectedengine - Bing

FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/

FF - prefs.js: keyword.URL - hxxp://www.zstart.com/s/?site=Bing&src=FF-Address&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 50370

FF - prefs.js: network.proxy.type - 1

FF - component: c:\documents and settings\anna\application data\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@mmagoo.com\components\mmagootlf.dll

FF - plugin: c:\documents and settings\anna\application data\mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\documents and settings\anna\application data\mozilla\plugins\npgtpo3dautoplugin.dll

FF - plugin: c:\documents and settings\anna\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension

FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

.

============= SERVICES / DRIVERS ===============

.

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]

R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]

R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [2007-9-4 6528]

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-7-12 11608]

R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]

R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]

R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-7-12 136360]

R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-7-12 269480]

R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]

R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-7-12 66616]

R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]

R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]

R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\9.0.1\ToolbarUpdater.exe [2011-12-18 869216]

R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]

R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]

R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]

R3 TEchoCan;Toshiba Audio Effect;c:\windows\system32\drivers\TEchoCan.sys [2010-7-12 409984]

R3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys [2010-7-12 14208]

S2 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxduserv.exe [2010-7-16 98984]

S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2010-7-12 272128]

.

=============== Created Last 30 ================

.

2012-01-09 04:15:54 -------- d-----w- C:\09d77ee047a5478352cf

2011-12-31 20:44:35 -------- d-----w- c:\program files\Trend Micro

2011-12-31 01:41:52 -------- d-sh--w- C:\found.000

2011-12-27 01:36:20 709968 ----a-w- c:\windows\isRS-000.tmp

2011-12-18 21:51:02 -------- d-----w- c:\windows\system32\cache

2011-12-18 21:51:00 -------- d-----w- c:\documents and settings\all users\application data\AVG Secure Search

2011-12-11 02:46:38 -------- d-----w- c:\documents and settings\anna\application data\AVG2012

2011-12-11 02:43:15 -------- d-----w- c:\documents and settings\anna\application data\AVG Secure Search

2011-12-11 02:43:09 -------- d-----w- c:\program files\common files\AVG Secure Search

2011-12-11 02:43:08 -------- d-----w- c:\program files\AVG Secure Search

2011-12-11 02:43:05 -------- d--h--w- c:\documents and settings\all users\application data\Common Files

2011-12-11 02:41:56 -------- d-----w- c:\windows\system32\drivers\AVG

2011-12-11 02:41:56 -------- d-----w- c:\documents and settings\all users\application data\AVG2012

2011-12-11 02:41:14 -------- d-----w- c:\program files\AVG

2011-12-11 02:33:58 -------- d-----w- c:\documents and settings\all users\application data\MFAData

.

==================== Find3M ====================

.

2011-12-10 21:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-10-24 20:29:02 94208 ---ha-w- c:\windows\system32\QuickTimeVR.qtx

2011-10-24 20:29:02 69632 ---ha-w- c:\windows\system32\QuickTime.qts

2011-10-13 08:34:38 66616 ---ha-w- c:\windows\system32\drivers\avgntflt.sys

.

============= FINISH: 22:37:24.35 ===============

Link to post
Share on other sites

Welcome to the forum.

Please download Farbar Service Scanner and run it on the computer with the issue.

  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update

    [*]Press "Scan".

    [*]It will create a log (FSS.txt) in the same directory the tool is run.

    [*]Please copy and paste the log to your reply.

Please download and run RogueKiller.

Choose 1 to scan the system

Post back the report.

----------------------

Then.......

Please download OTL from one of the links below:

http://oldtimer.geekstogo.com/OTL.exe

http://oldtimer.geekstogo.com/OTL.com (<---renamed version)

Save it to your desktop.

Double click on the icon on your desktop.

Click the Scan All Users checkbox.

Push the Quick Scan button.

Two reports will open, copy and paste them in a reply here: (or attach them as .txt files)

OTL.txt <-- Will be opened

Extra.txt <-- Will be minimized

The scan will take about 10 minutes...depends on your hard drive size.

MrC

Link to post
Share on other sites

Farbar Service Scanner

Ran by Anna (administrator) on 14-01-2012 at 20:20:37

Microsoft Windows XP Professional Service Pack 3 (X86)

Boot Mode: Normal

****************************************************************

Internet Services:

============

Connection Status:

==============

Localhost is accessible.

LAN connected.

Attempt to access Google IP returned error: Google IP is offline

Yahoo IP is accessible.

Windows Firewall:

=============

Firewall Disabled Policy:

==================

System Restore:

============

System Restore Disabled Policy:

========================

Security Center:

============

Windows Update:

===========

File Check:

========

C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit

C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit

C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit

C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit

C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit

C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit

C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit

C:\WINDOWS\system32\netman.dll => MD5 is legit

C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit

C:\WINDOWS\system32\srsvc.dll => MD5 is legit

C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit

C:\WINDOWS\system32\wscsvc.dll => MD5 is legit

C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit

C:\WINDOWS\system32\wuauserv.dll => MD5 is legit

C:\WINDOWS\system32\qmgr.dll => MD5 is legit

C:\WINDOWS\system32\es.dll => MD5 is legit

C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit

C:\WINDOWS\system32\svchost.exe => MD5 is legit

C:\WINDOWS\system32\rpcss.dll => MD5 is legit

C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:

=======

AegisP(8) Avgtdix(11) Gpc(3) IPSec(5) NetBT(6) NwlnkIpx(9) NwlnkNb(10) PSched(7) Tcpip(4)

0x0B00000005000000010000000200000003000000040000000B000000060000000700000008000000090000000A000000

IpSec Tag value is correct.

**** End of log ****

RogueKiller V6.2.4 [01/12/2012] by Tigzy

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

Started in : Normal mode

User: Anna [Admin rights]

Mode: Scan -- Date : 01/14/2012 20:21:56

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 9 ¤¤¤

[] HKLM\[...]\Run : () -> ACCESS DENIED

[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (hxxp127.0.0.1:50370) -> FOUND

[PROXY FF] dxjt8jqw.default\ 127.0.0.1:50370 -> FOUND

[HJPOL] HKCU\[...]\System : DisableTaskMgr (1) -> FOUND

[HJPOL] HKCU\[...]\Explorer : NoDesktop (1) -> FOUND

[WallPP] HKCU\[...]\Desktop : Wallpaper () -> FOUND

[HJ] HKCU\[...]\Advanced : Start_ShowMyComputer (0) -> FOUND

[HJ] HKCU\[...]\Advanced : Start_ShowSearch (0) -> FOUND

[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++

--- User ---

[MBR] 009fe65faad70e66f8581745f3dbfc13

[bSP] 0b5ed4fd7bc3c27d1e483acc98bf82cf : Windows XP MBR Code

Partition table:

0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 63 | Size: 137427 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[1].txt >>

RKreport[1].txt

OTL logfile created on: 1/14/2012 8:24:57 PM - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Anna\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

494.86 Mb Total Physical Memory | 70.97 Mb Available Physical Memory | 14.34% Memory free

1.13 Gb Paging File | 0.35 Gb Available in Paging File | 30.67% Paging File free

Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 127.99 Gb Total Space | 109.50 Gb Free Space | 85.56% Space Free | Partition Type: NTFS

Unable to calculate disk information.

Computer Name: ANNA-Y4TNC2FAXB | User Name: Anna | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/14 20:23:45 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Anna\Desktop\OTL (1).com

PRC - [2012/01/05 03:48:46 | 001,047,024 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

PRC - [2011/12/18 15:50:58 | 000,869,216 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

PRC - [2011/12/18 15:50:51 | 000,892,768 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe

PRC - [2011/12/03 01:22:12 | 004,200,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgui.exe

PRC - [2011/12/03 01:22:12 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe

PRC - [2011/11/28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe

PRC - [2011/10/22 18:43:24 | 000,140,952 | -H-- | M] (Google Inc.) -- C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe

PRC - [2011/10/13 02:34:38 | 000,136,360 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe

PRC - [2011/10/13 02:34:34 | 000,269,480 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe

PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe

PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe

PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe

PRC - [2010/11/02 16:05:06 | 000,281,768 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

PRC - [2010/01/14 21:11:00 | 000,076,968 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

PRC - [2008/09/10 05:11:12 | 000,676,520 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe

PRC - [2008/09/10 05:11:09 | 000,025,256 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxdumsdmon.exe

PRC - [2008/05/23 06:58:34 | 000,594,600 | -H-- | M] ( ) -- C:\WINDOWS\system32\lxducoms.exe

PRC - [2008/04/13 18:12:19 | 001,033,728 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2004/12/29 23:32:20 | 000,065,536 | -H-- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe

PRC - [2004/12/17 15:47:12 | 000,548,864 | -H-- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe

PRC - [2004/12/16 14:09:40 | 000,827,392 | -H-- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe

PRC - [2004/12/14 10:50:26 | 000,340,032 | -H-- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe

PRC - [2004/11/10 10:14:08 | 000,036,864 | -H-- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

PRC - [2004/10/14 08:11:10 | 001,388,544 | -H-- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

PRC - [2003/09/26 14:43:16 | 000,184,320 | -H-- | M] (Agere Systems) -- C:\Program Files\ltmoh\ltmoh.exe

PRC - [2002/09/20 13:50:10 | 000,045,056 | -H-- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

========== Modules (No Company Name) ==========

MOD - [2012/01/05 03:48:44 | 000,411,120 | ---- | M] () -- C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppgooglenaclpluginchrome.dll

MOD - [2012/01/05 03:48:43 | 003,767,792 | ---- | M] () -- C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll

MOD - [2012/01/05 03:47:19 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\avutil-51.dll

MOD - [2012/01/05 03:47:18 | 000,222,208 | ---- | M] () -- C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\avformat-53.dll

MOD - [2012/01/05 03:47:17 | 001,746,432 | ---- | M] () -- C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\avcodec-53.dll

MOD - [2011/12/18 15:50:58 | 000,869,216 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

MOD - [2011/12/18 15:50:51 | 000,892,768 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe

MOD - [2011/10/12 02:14:47 | 000,971,264 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll

MOD - [2011/10/12 02:12:33 | 005,450,752 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll

MOD - [2011/10/12 02:12:26 | 012,430,848 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll

MOD - [2011/10/12 02:12:10 | 001,587,200 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll

MOD - [2011/10/12 02:10:08 | 007,950,848 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll

MOD - [2011/10/12 02:09:53 | 011,490,816 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll

MOD - [2010/01/28 12:57:58 | 000,355,688 | -H-- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll

MOD - [2008/09/10 05:11:12 | 000,676,520 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe

MOD - [2008/09/10 05:11:09 | 000,025,256 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxdumsdmon.exe

MOD - [2008/09/10 03:56:27 | 000,081,920 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxducaps.dll

MOD - [2008/09/10 03:56:14 | 000,380,928 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxduscw.dll

MOD - [2008/09/10 03:56:12 | 001,036,288 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxdudrs.dll

MOD - [2008/09/10 03:43:35 | 000,086,016 | -H-- | M] () -- C:\WINDOWS\system32\lxduoem.dll

MOD - [2008/09/10 03:41:44 | 000,032,768 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\ipcmt.dll

MOD - [2008/09/10 03:40:31 | 000,069,632 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\lxducnv4.dll

MOD - [2008/05/26 21:36:57 | 000,036,864 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\app4r.monitor.core.dll

MOD - [2008/05/26 21:36:57 | 000,028,672 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\app4r.monitor.common.dll

MOD - [2008/05/26 21:35:58 | 000,065,536 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\app4r.devmons.mcmdevmon.dll

MOD - [2008/05/23 06:17:14 | 000,121,856 | -H-- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdudrpp.dll

MOD - [2008/05/23 06:02:14 | 000,188,416 | -H-- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdudatr.dll

MOD - [2008/05/23 06:02:05 | 000,073,728 | -H-- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\lxducats.dll

MOD - [2008/04/30 18:41:53 | 000,045,056 | -H-- | M] () -- C:\WINDOWS\system32\LXDUPMON.DLL

MOD - [2008/03/24 22:53:10 | 000,012,288 | -H-- | M] () -- C:\Program Files\Lexmark 5600-6600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll

========== Win32 Services (SafeList) ==========

SRV - [2011/12/18 15:50:58 | 000,869,216 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe -- (vToolbarUpdater)

SRV - [2011/10/13 02:34:38 | 000,136,360 | -H-- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)

SRV - [2011/10/13 02:34:34 | 000,269,480 | -H-- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)

SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)

SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)

SRV - [2008/05/23 06:58:34 | 000,594,600 | -H-- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxducoms.exe -- (lxdu_device)

SRV - [2008/05/23 06:58:22 | 000,098,984 | -H-- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe -- (lxduCATSCustConnectService)

SRV - [2004/11/10 10:14:08 | 000,036,864 | -H-- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (CFSvcs)

SRV - [2002/09/20 13:50:10 | 000,045,056 | -H-- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))

========== Driver Services (SafeList) ==========

DRV - [2011/10/13 02:34:38 | 000,138,192 | -H-- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)

DRV - [2011/10/13 02:34:38 | 000,066,616 | -H-- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)

DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)

DRV - [2011/10/04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)

DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)

DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)

DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)

DRV - [2011/07/11 01:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)

DRV - [2011/07/11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)

DRV - [2011/07/11 01:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)

DRV - [2009/05/11 11:49:19 | 000,011,608 | -H-- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)

DRV - [2009/05/11 09:12:49 | 000,028,520 | -H-- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)

DRV - [2008/04/13 12:56:06 | 000,088,320 | -H-- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)

DRV - [2007/12/26 09:47:30 | 000,272,128 | -H-- | M] (NETGEAR Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wg111v2.sys -- (RTLWUSB)

DRV - [2007/09/04 00:14:06 | 000,006,528 | -H-- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Thpevm.SYS -- (Thpevm)

DRV - [2004/11/30 15:04:16 | 000,409,984 | -H-- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TEchoCan.sys -- (TEchoCan)

DRV - [2004/10/29 17:48:10 | 003,222,784 | -H-- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®

DRV - [2004/07/22 13:50:16 | 001,268,234 | -H-- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2003/01/29 13:35:00 | 000,012,032 | -H-- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Netdevio.sys -- (Netdevio)

DRV - [2001/08/23 06:00:00 | 000,063,232 | -H-- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)

DRV - [2001/08/23 06:00:00 | 000,055,936 | -H-- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.stardoll.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"

FF - prefs.js..browser.search.selectedEngine: "Bing"

FF - prefs.js..browser.search.selectedengine: "Bing"

FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"

FF - prefs.js..extensions.enabledItems: textlinks@mmagoo.com:1.0.0

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..keyword.URL: "http://www.zstart.com/s/?site=Bing&src=FF-Address&q="

FF - prefs.js..network.proxy.http: "127.0.0.1"

FF - prefs.js..network.proxy.http_port: 50370

FF - prefs.js..network.proxy.type: 1

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Anna\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)

FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Anna\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/28 09:23:43 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\9.0.0.22\ [2011/12/18 15:51:09 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 01:51:50 | 000,000,000 | -H-D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/11 01:51:50 | 000,000,000 | -H-D | M]

[2010/08/28 17:16:56 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions

[2010/08/28 17:16:56 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions\mozswing@mozswing.org

[2011/12/23 00:56:42 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\dxjt8jqw.default\extensions

[2010/10/26 10:07:18 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\dxjt8jqw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2010/10/27 16:31:22 | 000,001,919 | -H-- | M] () -- C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\dxjt8jqw.default\searchplugins\bing-zugo.xml

[2011/10/10 03:22:20 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2010/12/12 11:38:26 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

[2011/08/04 18:46:44 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

[2011/10/10 03:22:20 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}

[2010/09/12 08:31:48 | 000,000,000 | -H-D | M] (Mighty Magoo TextLinks) -- C:\DOCUMENTS AND SETTINGS\ANNA\APPLICATION DATA\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\TEXTLINKS@MMAGOO.COM

[2010/08/28 17:08:10 | 000,000,000 | -H-D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

[2011/07/19 04:05:25 | 000,476,904 | -H-- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

[2011/12/18 15:50:49 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo! (Enabled)

CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEncoding}&fr=crmas&p={searchTerms}

CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}

CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll

CHR - plugin: Java Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll

CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll

CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll

CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Anna\Application Data\Mozilla\plugins\npgoogletalk.dll

CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Anna\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll

CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

CHR - plugin: Default Plug-in (Enabled) = default_plugin

CHR - Extension: Mighty Magoo = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ahndmghnjfikjccedhcgoilmgklebefp\

CHR - Extension: YouTube = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\

CHR - Extension: Google Search = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\

CHR - Extension: AVG Safe Search = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\

CHR - Extension: Gmail = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2001/08/23 06:00:00 | 000,000,734 | -H-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.22\AVG Secure Search_toolbar.dll ()

O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.22\AVG Secure Search_toolbar.dll ()

O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)

O4 - HKLM..\Run: [CFSServ.exe] CFSServ.exe -NoClient File not found

O4 - HKLM..\Run: [Lexmark 5600-6600 Series Fax Server] C:\Program Files\Lexmark 5600-6600 Series\fm3032.exe ()

O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)

O4 - HKLM..\Run: [lxduamon] C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe ()

O4 - HKLM..\Run: [lxdumon.exe] C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe ()

O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)

O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)

O4 - HKLM..\Run: [TAudEffect] C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe (TOSHIBA)

O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()

O4 - HKCU..\Run: [speedItUpEX] C:\Program Files\SpeedItup Free\SpeedItUp.exe -MINI File not found

O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 112442153 = C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\44c2f94c06b3bb3d.exe

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1

O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()

O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()

O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Anna\Start Menu\Programs\IMVU\Run IMVU.lnk ()

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)

O16 - DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} http://images.fotki.com/activex/FotkiUploader.cab (FotkiUploader Control)

O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B67BBD2-4DF6-42DA-AA1E-4FE16A76CFAD}: DhcpNameServer = 192.168.2.1 192.168.2.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8B4A023-86B9-46CA-853D-55C908791CF1}: DhcpNameServer = 207.69.188.186 207.69.188.187

O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)

O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKCU Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp

O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp

O30 - LSA: Authentication Packages - (nwprovau) -C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010/07/12 09:55:54 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/14 20:23:51 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Anna\Desktop\OTL (1).com

[2012/01/14 20:21:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Anna\Desktop\RK_Quarantine

[2012/01/14 20:05:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Anna\IETldCache

[2012/01/08 22:43:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates

[2012/01/08 22:38:16 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8

[2012/01/08 22:35:01 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Anna\Start Menu\Programs\Administrative Tools

[2011/12/31 14:45:03 | 062,844,064 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe

[2011/12/31 14:44:35 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2011/12/31 03:27:16 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC

[2011/12/30 19:41:52 | 000,000,000 | -HSD | C] -- C:\found.000

[2011/12/18 15:51:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache

[2011/12/18 15:51:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search

[2010/07/16 19:28:09 | 000,438,272 | -H-- | C] ( ) -- C:\WINDOWS\System32\LXDUhcp.dll

[2010/07/16 19:28:09 | 000,364,544 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxduinpa.dll

[2010/07/16 19:28:09 | 000,339,968 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxduiesc.dll

[2010/07/16 19:28:08 | 001,069,056 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxduserv.dll

[2010/07/16 19:28:08 | 000,851,968 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxduusb1.dll

[2010/07/16 19:28:08 | 000,651,264 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxdupmui.dll

[2010/07/16 19:28:07 | 000,577,536 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxdulmpm.dll

[2010/07/16 19:28:06 | 000,679,936 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxduhbn3.dll

[2010/07/16 19:28:06 | 000,328,360 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxduih.exe

[2010/07/16 19:28:05 | 000,765,952 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxducomc.dll

[2010/07/16 19:28:05 | 000,594,600 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxducoms.exe

[2010/07/16 19:28:05 | 000,376,832 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxducomm.dll

[2010/07/16 19:28:04 | 000,369,320 | -H-- | C] ( ) -- C:\WINDOWS\System32\lxducfg.exe

[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[4 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

[1 C:\Documents and Settings\Anna\My Documents\*.tmp files -> C:\Documents and Settings\Anna\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/14 20:23:45 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Anna\Desktop\OTL (1).com

[2012/01/14 20:21:36 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys

[2012/01/14 20:11:10 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2012/01/14 20:05:41 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Anna\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2012/01/14 20:05:38 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012/01/14 19:48:00 | 000,000,974 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-507921405-1343024091-1003UA.job

[2012/01/14 19:48:00 | 000,000,922 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-507921405-1343024091-1003Core.job

[2012/01/14 02:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At2.job

[2012/01/14 01:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At5.job

[2012/01/14 00:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At1.job

[2012/01/13 23:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At24.job

[2012/01/13 22:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At22.job

[2012/01/13 21:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At23.job

[2012/01/13 20:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At21.job

[2012/01/13 19:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At18.job

[2012/01/13 18:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At20.job

[2012/01/13 17:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At19.job

[2012/01/13 16:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At17.job

[2012/01/13 15:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At16.job

[2012/01/13 14:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At15.job

[2012/01/13 13:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At14.job

[2012/01/13 12:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At13.job

[2012/01/13 11:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At11.job

[2012/01/13 10:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At12.job

[2012/01/13 09:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At10.job

[2012/01/13 08:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At9.job

[2012/01/13 07:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At8.job

[2012/01/13 06:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At7.job

[2012/01/13 05:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At6.job

[2012/01/13 04:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At3.job

[2012/01/13 03:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\At4.job

[2012/01/09 21:01:27 | 000,043,025 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm

[2012/01/09 14:18:01 | 000,000,284 | -H-- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2012/01/09 03:16:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012/01/08 22:44:07 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2012/01/07 13:55:35 | 086,178,471 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm

[2012/01/06 20:51:45 | 000,002,277 | -H-- | M] () -- C:\Documents and Settings\Anna\Desktop\Google Chrome.lnk

[2011/12/31 14:50:25 | 062,844,064 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe

[2011/12/28 09:23:48 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk

[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[4 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

[1 C:\Documents and Settings\Anna\My Documents\*.tmp files -> C:\Documents and Settings\Anna\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/14 20:21:36 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys

[2012/01/14 20:05:41 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\Anna\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2011/12/07 05:22:36 | 000,000,288 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~gvaLhMYJG5QNqb

[2011/12/07 05:22:36 | 000,000,200 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~gvaLhMYJG5QNqbr

[2011/12/07 05:22:31 | 000,000,440 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\gvaLhMYJG5QNqb

[2010/10/25 07:30:16 | 000,000,006 | -H-- | C] () -- C:\Documents and Settings\Anna\Application Data\start

[2010/10/25 07:28:56 | 000,000,006 | -H-- | C] () -- C:\Documents and Settings\Anna\Application Data\completescan

[2010/10/25 07:21:26 | 000,000,010 | -H-- | C] () -- C:\Documents and Settings\Anna\Application Data\install

[2010/09/16 18:25:39 | 000,000,134 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\launch.xml

[2010/09/16 18:25:35 | 000,000,329 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\launcherData.xml

[2010/08/15 13:38:03 | 018,280,000 | --S- | C] () -- C:\WINDOWS\System32\FotkiThumbDB.dat

[2010/08/15 13:38:03 | 000,428,400 | --S- | C] () -- C:\WINDOWS\System32\FotkiUploadThumbDB.dat

[2010/08/08 12:03:15 | 000,000,256 | -H-- | C] () -- C:\WINDOWS\System32\pool.bin

[2010/08/01 21:21:39 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SETUP32.INI

[2010/07/22 15:19:19 | 000,013,312 | -H-- | C] () -- C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/07/16 19:34:07 | 000,040,960 | -H-- | C] () -- C:\WINDOWS\System32\lxduvs.dll

[2010/07/16 19:34:04 | 000,360,448 | -H-- | C] () -- C:\WINDOWS\System32\lxducoin.dll

[2010/07/16 19:32:21 | 001,036,288 | -H-- | C] () -- C:\WINDOWS\System32\lxdudrs.dll

[2010/07/16 19:32:21 | 000,081,920 | -H-- | C] () -- C:\WINDOWS\System32\lxducaps.dll

[2010/07/16 19:32:20 | 000,069,632 | -H-- | C] () -- C:\WINDOWS\System32\lxducnv4.dll

[2010/07/16 19:31:36 | 000,045,056 | -H-- | C] () -- C:\WINDOWS\System32\LXDUPMON.DLL

[2010/07/16 19:31:36 | 000,032,768 | -H-- | C] () -- C:\WINDOWS\System32\LXDUFXPU.DLL

[2010/07/16 19:31:16 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\lxduoem.dll

[2010/07/16 19:29:03 | 000,000,044 | -H-- | C] () -- C:\WINDOWS\System32\lxdurwrd.ini

[2010/07/16 19:28:10 | 000,389,120 | -H-- | C] () -- C:\WINDOWS\System32\LXDUinst.dll

[2010/07/16 19:28:06 | 000,208,896 | -H-- | C] () -- C:\WINDOWS\System32\lxdugrd.dll

[2010/07/14 22:16:29 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2010/07/12 21:40:25 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\NDSTray.INI

[2010/07/12 21:38:17 | 000,000,138 | -H-- | C] () -- C:\WINDOWS\wininit.ini

[2010/07/12 21:23:45 | 000,010,165 | -H-- | C] () -- C:\WINDOWS\System32\tosmreg.ini

[2010/07/12 21:23:44 | 000,128,113 | -H-- | C] () -- C:\WINDOWS\System32\csellang.ini

[2010/07/12 21:23:44 | 000,045,056 | -H-- | C] () -- C:\WINDOWS\System32\csellang.dll

[2010/07/12 21:23:44 | 000,007,671 | -H-- | C] () -- C:\WINDOWS\System32\cseltbl.ini

[2010/07/12 11:57:15 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat

[2010/07/12 11:35:42 | 000,036,864 | -H-- | C] () -- C:\WINDOWS\System32\RtlGina2.dll

[2010/07/12 11:35:41 | 000,966,765 | -H-- | C] () -- C:\WINDOWS\System32\acAuth.dll

[2010/07/12 11:35:41 | 000,344,064 | -H-- | C] () -- C:\WINDOWS\System32\SCMLib.dll

[2010/07/12 10:20:36 | 000,001,769 | -H-- | C] () -- C:\WINDOWS\Language_trs.ini

[2010/07/12 09:57:51 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2010/07/12 09:53:12 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2010/07/12 04:47:33 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI

[2010/07/12 04:46:39 | 000,315,560 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009/08/03 14:07:42 | 000,403,816 | -H-- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2009/08/03 14:07:42 | 000,230,768 | -H-- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe

[2004/08/02 13:20:40 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat

[2001/08/23 06:00:00 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin

[2001/08/23 06:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat

[2001/08/23 06:00:00 | 000,436,276 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2001/08/23 06:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2001/08/23 06:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat

[2001/08/23 06:00:00 | 000,069,006 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2001/08/23 06:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin

[2001/08/23 06:00:00 | 000,037,344 | R-S- | C] () -- C:\Documents and Settings\Anna\Application Data\chkntfs.dat

[2001/08/23 06:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2001/08/23 06:00:00 | 000,004,463 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat

[2001/08/23 06:00:00 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin

[2001/08/23 06:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2010/07/16 19:31:10 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\5600-6600 Series

[2011/12/18 15:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search

[2011/12/10 20:50:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012

[2011/12/10 20:43:05 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files

[2011/04/07 20:08:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Individual Software

[2010/07/21 19:00:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Lexmark 5600-6600 Series

[2012/01/07 13:57:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData

[2010/10/05 21:02:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Anna\Application Data\5600-6600 Series

[2011/12/10 20:43:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anna\Application Data\AVG Secure Search

[2011/12/10 20:46:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anna\Application Data\AVG2012

[2011/11/06 21:25:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Anna\Application Data\IMVU

[2011/10/16 13:52:38 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Anna\Application Data\IMVUClient

[2011/06/27 10:26:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Anna\Application Data\Individual Software

[2010/07/21 19:00:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Anna\Application Data\Lexmark Productivity Studio

[2010/08/08 12:02:53 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Anna\Application Data\Research In Motion

[2010/09/02 08:14:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Anna\Application Data\Toshiba

[2012/01/14 00:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At1.job

[2012/01/13 09:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At10.job

[2012/01/13 11:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At11.job

[2012/01/13 10:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At12.job

[2012/01/13 12:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At13.job

[2012/01/13 13:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At14.job

[2012/01/13 14:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At15.job

[2012/01/13 15:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At16.job

[2012/01/13 16:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At17.job

[2012/01/13 19:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At18.job

[2012/01/13 17:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At19.job

[2012/01/14 02:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At2.job

[2012/01/13 18:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At20.job

[2012/01/13 20:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At21.job

[2012/01/13 22:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At22.job

[2012/01/13 21:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At23.job

[2012/01/13 23:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At24.job

[2012/01/13 04:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At3.job

[2012/01/13 03:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At4.job

[2012/01/14 01:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At5.job

[2012/01/13 05:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At6.job

[2012/01/13 06:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At7.job

[2012/01/13 07:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At8.job

[2012/01/13 08:27:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\Tasks\At9.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00061.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00060.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00059.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00058.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00057.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00056.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00055.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00054.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00053.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00052.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00051.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00050.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00049.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00048.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00047.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00046.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00045.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00044.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00043.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00042.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00041.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00040.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00039.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00038.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00037.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00036.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00035.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00034.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00033.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00032.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00031.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00030.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00029.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00028.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00027.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00026.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00025.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00024.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00023.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00022.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00021.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00020.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00019.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00018.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00017.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00016.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00015.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00014.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00013.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00012.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00011.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00010.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00009.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00008.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00007.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00006.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00005.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00004.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00003.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00002.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00001.jpg:Roxio EMC Stream

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Anna\My Documents\Imported Photos 00000.jpg:Roxio EMC Stream

< End of report >

OTL Extras logfile created on: 1/14/2012 8:24:57 PM - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Anna\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

494.86 Mb Total Physical Memory | 70.97 Mb Available Physical Memory | 14.34% Memory free

1.13 Gb Paging File | 0.35 Gb Available in Paging File | 30.67% Paging File free

Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 127.99 Gb Total Space | 109.50 Gb Free Space | 85.56% Space Free | Partition Type: NTFS

Unable to calculate disk information.

Computer Name: ANNA-Y4TNC2FAXB | User Name: Anna | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 1

"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe" = C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe:*:Enabled:Lexmark Device Monitor -- ()

"C:\Program Files\Lexmark 5600-6600 Series\frun.exe" = C:\Program Files\Lexmark 5600-6600 Series\frun.exe:*:Enabled:Lexmark Productivity Studio -- ()

"C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe" = C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:*:Enabled:ABBYY FineReader -- (ABBYY (BIT Software))

"C:\Program Files\Lexmark 5600-6600 Series\lxdufax.exe" = C:\Program Files\Lexmark 5600-6600 Series\lxdufax.exe:*:Enabled:Fax software -- ()

"C:\WINDOWS\system32\lxducoms.exe" = C:\WINDOWS\system32\lxducoms.exe:*:Enabled:Lexmark Communications System -- ( )

"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire

"C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe" = C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe:*:Enabled:ConfigFree SUMMIT Engine -- (TOSHIBA CORPORATION)

"C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome -- (Google Inc.)

"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox -- (Mozilla Corporation)

"C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Anna\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)

"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)

"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0

"{0577A2AA-DEA0-4D40-8372-4211102D43E4}" = TOSHIBA Mic Effect

"{10812DE7-2E57-4740-B226-6B3BE34AF9D7}" = Lexmark Tools for Office

"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java 6 Update 27

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0

"{4102037D-E8E0-48E0-B203-E521D194FB71}" = NETGEAR WG111v2 wireless USB 2.0 adapter

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4E74D41C-5864-4561-9F6B-069372513A0B}" = AVG 2012

"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin

"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime

"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012

"{8398852A-7B61-4808-8F58-D0A40D1B2CB6}" = AVG 2012

"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12

"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007

"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007

"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007

"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)

"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007

"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007

"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007

"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007

"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007

"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support

"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0

"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint

"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0

"{B28759B8-5FC6-4F56-9C6C-6EDAD36455A9}" = Roxio Media Manager

"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5

"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark Printable Web

"{DDD076BF-C5C3-468C-AA1B-F9A7E47446FE}" = Intel® Network Connections 13.1.33.0

"{E171F5DA-6F17-472D-A223-92468142C5E8}" = AVG 2012

"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications

"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Adobe Shockwave Player" = Adobe Shockwave Player 11.5

"All ATI Software" = ATI - Software Uninstall Utility

"AVG" = AVG 2012

"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus

"BlackBerry_{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5

"ENTERPRISE" = Microsoft Office Enterprise 2007

"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs

"ie7" = Windows Internet Explorer 7

"ie8" = Windows Internet Explorer 8

"ieSpell" = ieSpell

"Lexmark 5600-6600 Series" = Lexmark 5600-6600 Series

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Mavis Beacon Teaches Typing Deluxe 16" = Mavis Beacon Teaches Typing Deluxe 16

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Mozilla Firefox (3.6.7)" = Mozilla Firefox (3.6.7)

"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"Professor Answers" = Professor Answers

"Professor Teaches Excel 2003" = Professor Teaches Excel 2003

"Professor Teaches PowerPoint 2003" = Professor Teaches PowerPoint 2003

"Professor Teaches Word 2003" = Professor Teaches Word 2003

"TOSHIBA Software Modem" = TOSHIBA Software Modem

"WIC" = Windows Imaging Component

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Windows Media Player 11

"Windows XP Service Pack" = Windows XP Service Pack 3

"WMFDist11" = Windows Media Format 11 runtime

"wmp11" = Windows Media Player 11

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Google Chrome" = Google Chrome

"IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 485

Description = svchost (1560) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

failed with system error 1392 (0x00000570): "The file or directory is corrupted

and unreadable. ". The delete file operation will fail with error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 485

Description = svchost (1560) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

failed with system error 1392 (0x00000570): "The file or directory is corrupted

and unreadable. ". The delete file operation will fail with error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 485

Description = svchost (1560) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

failed with system error 1392 (0x00000570): "The file or directory is corrupted

and unreadable. ". The delete file operation will fail with error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 485

Description = svchost (1560) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

failed with system error 1392 (0x00000570): "The file or directory is corrupted

and unreadable. ". The delete file operation will fail with error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 485

Description = svchost (1560) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

failed with system error 1392 (0x00000570): "The file or directory is corrupted

and unreadable. ". The delete file operation will fail with error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 485

Description = svchost (1560) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

failed with system error 1392 (0x00000570): "The file or directory is corrupted

and unreadable. ". The delete file operation will fail with error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 485

Description = svchost (1560) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

failed with system error 1392 (0x00000570): "The file or directory is corrupted

and unreadable. ". The delete file operation will fail with error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 490

Description = svchost (1560) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"

for read / write access failed with system error 1392 (0x00000570): "The file or

directory is corrupted and unreadable. ". The open file operation will fail with

error -1022 (0xfffffc02).

Error - 12/30/2011 9:35:22 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = ESENT | ID = 439

Description = Catalog Database (1560) Unable to write a shadowed header for file

C:\WINDOWS\system32\CatRoot2\tmp.edb. Error -1022.

Error - 12/30/2011 10:20:42 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = MSDTC | ID = 4404

Description = MS DTC Tracing infrastructure : the initialization of the tracing

infrastructure failed. Internal Information : msdtc_trace : File: d:\comxp_sp3\com\com1x\dtc\dtc\trace\src\tracelib.cpp,

Line: 1115, StartTrace Failed, hr=0x800700a1

[ System Events ]

Error - 1/8/2012 9:59:03 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7009

Description = Timeout (30000 milliseconds) waiting for the lxduCATSCustConnectService

service to connect.

Error - 1/8/2012 9:59:03 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7000

Description = The lxduCATSCustConnectService service failed to start due to the

following error: %%1053

Error - 1/8/2012 9:59:03 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7009

Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher

9 service to connect.

Error - 1/8/2012 10:14:09 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7022

Description = The Server service hung on starting.

Error - 1/8/2012 10:14:09 PM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1070

Error - 1/9/2012 5:17:55 AM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7009

Description = Timeout (30000 milliseconds) waiting for the lxduCATSCustConnectService

service to connect.

Error - 1/9/2012 5:17:55 AM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7000

Description = The lxduCATSCustConnectService service failed to start due to the

following error: %%1053

Error - 1/9/2012 5:17:55 AM | Computer Name = ANNA-Y4TNC2FAXB | Source = Service Control Manager | ID = 7009

Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher

9 service to connect.

Error - 1/11/2012 4:25:46 AM | Computer Name = ANNA-Y4TNC2FAXB | Source = Windows Update Agent | ID = 16

Description = Unable to Connect: Windows is unable to connect to the automatic updates

service and therefore cannot download and install updates according to the set

schedule. Windows will continue to try to establish a connection.

Error - 1/13/2012 4:25:47 AM | Computer Name = ANNA-Y4TNC2FAXB | Source = Windows Update Agent | ID = 16

Description = Unable to Connect: Windows is unable to connect to the automatic updates

service and therefore cannot download and install updates according to the set

schedule. Windows will continue to try to establish a connection.

< End of report >

Link to post
Share on other sites

You have two anti-virus programs installed, this doesn't work!

I would uninstall AVG and keep AntiVir.

AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}

-----------------------------------------

Please do this:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370
    FF - prefs.js..network.proxy.http: "127.0.0.1"
    FF - prefs.js..network.proxy.http_port: 50370
    FF - prefs.js..network.proxy.type: 1
    O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [CFSServ.exe] CFSServ.exe -NoClient File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 112442153 = C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\44c2f94c06b3bb3d.exe
    [2011/12/07 05:22:36 | 000,000,288 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~gvaLhMYJG5QNqb
    [2011/12/07 05:22:36 | 000,000,200 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~gvaLhMYJG5QNqbr
    [2011/12/07 05:22:31 | 000,000,440 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\gvaLhMYJG5QNqb

    :files
    C:\WINDOWS\tasks\*.job
    :Commands
    [emptytemp]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
  • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

MrC

Link to post
Share on other sites

All processes killed

========== OTL ==========

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!

Prefs.js: "127.0.0.1" removed from network.proxy.http

Prefs.js: 50370 removed from network.proxy.http_port

Prefs.js: 1 removed from network.proxy.type

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{9D425283-D487-4337-BAB6-AB8354A81457} not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9D425283-D487-4337-BAB6-AB8354A81457} not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CFSServ.exe not found.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\112442153 not found.

File C:\Documents and Settings\All Users\Application Data\~gvaLhMYJG5QNqb not found.

File C:\Documents and Settings\All Users\Application Data\~gvaLhMYJG5QNqbr not found.

File C:\Documents and Settings\All Users\Application Data\gvaLhMYJG5QNqb not found.

========== FILES ==========

File\Folder C:\WINDOWS\tasks\*.job not found.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

->Temp folder emptied: 0 bytes

User: Anna

->Temp folder emptied: 2641851 bytes

->Temporary Internet Files folder emptied: 1003906 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Google Chrome cache emptied: 9125165 bytes

->Flash cache emptied: 0 bytes

Link to post
Share on other sites

Please download and run TDSSKiller as outlined in the post below:

http://forums.malwarebytes.org/index.php?showtopic=100665&view=findpost&p=499595

If a suspicious object is detected, the default action will be Skip, click on Continue

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

---------------------------------------------------

Then..............

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Make sure you run ComboFix from your desktop.

Please include the C:\ComboFix.txt in your next reply for further review.

MrC

Link to post
Share on other sites

ComboFix 12-01-15.01 - Anna 01/15/2012 20:06:39.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.495.275 [GMT -6:00]

Running from: c:\documents and settings\Anna\My Documents\Downloads\ComboFix.exe

AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\All Users\SPL1F.tmp

c:\documents and settings\All Users\SPL43.tmp

c:\documents and settings\All Users\SPL53.tmp

c:\documents and settings\All Users\SPLDA.tmp

c:\documents and settings\Anna\Application Data\chkntfs.dat

c:\documents and settings\Anna\Application Data\completescan

c:\documents and settings\Anna\Application Data\install

c:\documents and settings\Anna\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk

c:\documents and settings\Anna\Application Data\Mozilla\Firefox\Profiles\dxjt8jqw.default\searchplugins\bing-zugo.xml

c:\documents and settings\Anna\Desktop\System Fix.lnk

c:\documents and settings\Anna\My Documents\~WRL1036.tmp

c:\documents and settings\Anna\Start Menu\Programs\System Fix

c:\documents and settings\Anna\Start Menu\Programs\System Fix\System Fix.lnk

c:\documents and settings\Anna\Start Menu\Programs\System Fix\Uninstall System Fix.lnk

c:\program files\Mighty Magoo

c:\program files\Mighty Magoo\ars.cfg

c:\program files\Mighty Magoo\icon.ico

c:\windows\system32\Cache

c:\windows\system32\Cache\272512937d9e61a4.fb

c:\windows\system32\Cache\287204568329e189.fb

c:\windows\system32\Cache\28bc8f716fd76a47.fb

c:\windows\system32\Cache\2c53092c95605355.fb

c:\windows\system32\Cache\3917078cb68ec657.fb

c:\windows\system32\Cache\590ba23ce359fd0c.fb

c:\windows\system32\Cache\610289e025a3ee9a.fb

c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb

c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb

c:\windows\system32\Cache\ad10a52aff5e038d.fb

c:\windows\system32\Cache\c4d28dca2e7648be.fb

c:\windows\system32\Cache\d201ef9910cd39de.fb

c:\windows\system32\Cache\d2e94710a5708128.fb

c:\windows\system32\Cache\d79b9dfe81484ec4.fb

c:\windows\system32\Cache\e0de16f883bea794.fb

c:\windows\system32\Cache\faf5fa885b2f3de8.fb

c:\windows\system32\drivers\etc\hosts.ics

.

.

((((((((((((((((((((((((( Files Created from 2011-12-16 to 2012-01-16 )))))))))))))))))))))))))))))))

.

.

2012-01-15 19:45 . 2012-01-15 19:45 -------- d-sh--w- c:\documents and settings\Anna\PrivacIE

2012-01-15 18:13 . 2012-01-15 18:13 -------- d-----w- c:\documents and settings\Anna\Application Data\AVG2012

2012-01-15 17:56 . 2012-01-15 17:56 -------- d-----w- C:\_OTL

2012-01-15 02:21 . 2012-01-15 02:21 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys

2012-01-15 02:05 . 2012-01-15 02:05 -------- d-sh--w- c:\documents and settings\Anna\IETldCache

2012-01-10 01:17 . 2012-01-10 01:17 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2012-01-09 04:43 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll

2012-01-09 04:42 . 2011-11-04 19:20 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2012-01-09 04:42 . 2011-11-04 19:20 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2012-01-09 04:42 . 2011-11-04 19:20 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll

2012-01-09 04:38 . 2012-01-09 04:41 -------- dc-h--w- c:\windows\ie8

2011-12-31 20:44 . 2011-12-31 20:50 -------- d-----w- c:\program files\Trend Micro

2011-12-31 01:41 . 2011-12-31 01:41 -------- d-----w- C:\found.000

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-10 21:24 . 2010-07-12 21:10 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-11-04 19:20 . 2001-08-23 12:00 916992 ----a-w- c:\windows\system32\wininet.dll

2011-11-04 19:20 . 2001-08-23 12:00 43520 ------w- c:\windows\system32\licmgr10.dll

2011-11-04 19:20 . 2001-08-23 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-11-04 11:23 . 2010-07-12 17:18 385024 ------w- c:\windows\system32\html.iec

2011-10-24 20:29 . 2011-10-24 20:29 94208 ---ha-w- c:\windows\system32\QuickTimeVR.qtx

2011-10-24 20:29 . 2011-10-24 20:29 69632 ---ha-w- c:\windows\system32\QuickTime.qts

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-09-26 184320]

"AGRSMMSG"="AGRSMMSG.exe" [2004-07-22 88361]

"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]

"TAudEffect"="c:\program files\TOSHIBA\TAudEffect\TAudEff.exe" [2004-12-14 340032]

"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-01-14 122939]

"lxdumon.exe"="c:\program files\Lexmark 5600-6600 Series\lxdumon.exe" [2008-09-10 676520]

"lxduamon"="c:\program files\Lexmark 5600-6600 Series\lxduamon.exe" [2008-09-10 16040]

"Lexmark 5600-6600 Series Fax Server"="c:\program files\Lexmark 5600-6600 Series\fm3032.exe" [2008-09-10 311976]

"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-11-11 421888]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk

backup=c:\windows\pss\NETGEAR WG111v2 Smart Wizard.lnkCommon Startup

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\Lexmark 5600-6600 Series\\lxduamon.exe"=

"c:\\Program Files\\Lexmark 5600-6600 Series\\frun.exe"=

"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=

"c:\\Program Files\\Lexmark 5600-6600 Series\\lxdufax.exe"=

"c:\\WINDOWS\\system32\\lxducoms.exe"=

"c:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=

"c:\\Documents and Settings\\Anna\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Documents and Settings\\Anna\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=

"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=

.

R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [9/4/2007 12:14 AM 6528]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/12/2010 3:12 PM 136360]

R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]

R3 TEchoCan;Toshiba Audio Effect;c:\windows\system32\drivers\TEchoCan.sys [7/12/2010 9:35 PM 409984]

R3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys [7/12/2010 11:18 AM 14208]

S2 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxduserv.exe [7/16/2010 7:34 PM 98984]

S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe --> c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe [?]

S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [7/12/2010 11:35 AM 272128]

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - 64301065

*Deregistered* - 64301065

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

uInternet Connection Wizard,ShellNext = iexplore

IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM

IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM

IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM

IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM

IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Anna\Start Menu\Programs\IMVU\Run IMVU.lnk

TCP: DhcpNameServer = 192.168.2.1 192.168.2.1

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll

DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} - hxxp://images.fotki.com/activex/FotkiUploader.cab

FF - ProfilePath - c:\documents and settings\Anna\Application Data\Mozilla\Firefox\Profiles\dxjt8jqw.default\

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: browser.search.selectedengine - Bing

FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/

FF - prefs.js: keyword.URL - hxxp://www.zstart.com/s/?site=Bing&src=FF-Address&q=

FF - prefs.js: network.proxy.http -

FF - prefs.js: network.proxy.http_port -

FF - prefs.js: network.proxy.type -

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

.

- - - - ORPHANS REMOVED - - - -

.

HKCU-Run-SpeedItUpEX - c:\program files\SpeedItup Free\SpeedItUp.exe

HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-01-15 20:15

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

Completion time: 2012-01-15 20:22:32

ComboFix-quarantined-files.txt 2012-01-16 02:22

.

Pre-Run: 119,640,346,624 bytes free

Post-Run: 119,578,963,968 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

.

- - End Of File - - 620C88728C6C0D8208234F1929926DC9

I think this cleared it...my icons etc are all back

Link to post
Share on other sites

That's Good News :)

Just run TDSSKiller as I asked............

Please download and run TDSSKiller as outlined in the post below:

http://forums.malwar...ndpost&p=499595

If a suspicious object is detected, the default action will be Skip, click on Continue

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

Post back the log, MrC

Link to post
Share on other sites

18:02:37.0656 3804 TDSS rootkit removing tool 2.7.5.0 Jan 18 2012 09:26:24

18:02:37.0976 3804 ============================================================

18:02:37.0976 3804 Current date / time: 2012/01/18 18:02:37.0976

18:02:37.0976 3804 SystemInfo:

18:02:37.0976 3804

18:02:37.0976 3804 OS Version: 5.1.2600 ServicePack: 3.0

18:02:37.0976 3804 Product type: Workstation

18:02:37.0976 3804 ComputerName: ANNA-Y4TNC2FAXB

18:02:37.0976 3804 UserName: Anna

18:02:37.0976 3804 Windows directory: C:\WINDOWS

18:02:37.0976 3804 System windows directory: C:\WINDOWS

18:02:37.0976 3804 Processor architecture: Intel x86

18:02:37.0976 3804 Number of processors: 1

18:02:37.0976 3804 Page size: 0x1000

18:02:37.0976 3804 Boot type: Normal boot

18:02:37.0976 3804 ============================================================

18:02:39.0979 3804 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054

18:02:40.0009 3804 Initialize success

18:03:00.0338 2848 ============================================================

18:03:00.0338 2848 Scan started

18:03:00.0338 2848 Mode: Manual; SigCheck; TDLFS;

18:03:00.0338 2848 ============================================================

18:03:00.0719 2848 Abiosdsk - ok

18:03:00.0799 2848 abp480n5 - ok

18:03:00.0859 2848 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys

18:03:02.0732 2848 ACPI - ok

18:03:02.0882 2848 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys

18:03:03.0042 2848 ACPIEC - ok

18:03:03.0062 2848 adpu160m - ok

18:03:03.0112 2848 aeaudio (f13d8e7e1faa31019c25eb17b5fb2662) C:\WINDOWS\system32\drivers\aeaudio.sys

18:03:03.0142 2848 aeaudio - ok

18:03:03.0182 2848 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

18:03:03.0353 2848 aec - ok

18:03:03.0453 2848 AegisP (30bb1bde595ca65fd5549462080d94e5) C:\WINDOWS\system32\DRIVERS\AegisP.sys

18:03:03.0483 2848 AegisP ( UnsignedFile.Multi.Generic ) - warning

18:03:03.0483 2848 AegisP - detected UnsignedFile.Multi.Generic (1)

18:03:03.0533 2848 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys

18:03:03.0573 2848 AFD - ok

18:03:03.0653 2848 AgereSoftModem (b894a08f2a01e27c1989c31c96fdde83) C:\WINDOWS\system32\DRIVERS\AGRSM.sys

18:03:03.0833 2848 AgereSoftModem - ok

18:03:03.0943 2848 Aha154x - ok

18:03:03.0963 2848 aic78u2 - ok

18:03:03.0993 2848 aic78xx - ok

18:03:04.0013 2848 AliIde - ok

18:03:04.0023 2848 amsint - ok

18:03:04.0074 2848 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys

18:03:04.0254 2848 Arp1394 - ok

18:03:04.0274 2848 asc - ok

18:03:04.0284 2848 asc3350p - ok

18:03:04.0304 2848 asc3550 - ok

18:03:04.0344 2848 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

18:03:04.0514 2848 AsyncMac - ok

18:03:04.0534 2848 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

18:03:04.0674 2848 atapi - ok

18:03:04.0704 2848 Atdisk - ok

18:03:04.0735 2848 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

18:03:04.0905 2848 Atmarpc - ok

18:03:04.0955 2848 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

18:03:05.0135 2848 audstub - ok

18:03:05.0235 2848 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys

18:03:05.0295 2848 avgio - ok

18:03:05.0415 2848 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys

18:03:15.0790 2848 avgntflt - ok

18:03:16.0001 2848 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys

18:03:16.0051 2848 avipbb - ok

18:03:16.0131 2848 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

18:03:16.0291 2848 Beep - ok

18:03:16.0461 2848 catchme - ok

18:03:16.0531 2848 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

18:03:16.0702 2848 cbidf2k - ok

18:03:16.0742 2848 cd20xrnt - ok

18:03:16.0802 2848 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

18:03:16.0992 2848 Cdaudio - ok

18:03:17.0062 2848 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

18:03:17.0212 2848 Cdfs - ok

18:03:17.0263 2848 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

18:03:17.0443 2848 Cdrom - ok

18:03:17.0473 2848 Changer - ok

18:03:17.0563 2848 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys

18:03:17.0743 2848 CmBatt - ok

18:03:17.0783 2848 CmdIde - ok

18:03:17.0833 2848 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys

18:03:17.0994 2848 Compbatt - ok

18:03:18.0054 2848 Cpqarray - ok

18:03:18.0094 2848 dac2w2k - ok

18:03:18.0124 2848 dac960nt - ok

18:03:18.0214 2848 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

18:03:18.0354 2848 Disk - ok

18:03:18.0424 2848 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys

18:03:18.0685 2848 dmboot - ok

18:03:18.0745 2848 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys

18:03:18.0875 2848 dmio - ok

18:03:18.0925 2848 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

18:03:19.0075 2848 dmload - ok

18:03:19.0135 2848 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

18:03:19.0315 2848 DMusic - ok

18:03:19.0396 2848 dpti2o - ok

18:03:19.0446 2848 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

18:03:19.0626 2848 drmkaud - ok

18:03:19.0686 2848 drvmcdb (f41619ae216b51d68dda163805eefaa9) C:\WINDOWS\system32\drivers\drvmcdb.sys

18:03:19.0696 2848 drvmcdb ( UnsignedFile.Multi.Generic ) - warning

18:03:19.0696 2848 drvmcdb - detected UnsignedFile.Multi.Generic (1)

18:03:19.0736 2848 drvnddm (2ff629c1c443e25d0149b9dfb77e43a8) C:\WINDOWS\system32\drivers\drvnddm.sys

18:03:19.0746 2848 drvnddm ( UnsignedFile.Multi.Generic ) - warning

18:03:19.0746 2848 drvnddm - detected UnsignedFile.Multi.Generic (1)

18:03:19.0806 2848 E100B (ac9cf17ee2ae003c98eb4f5336c38058) C:\WINDOWS\system32\DRIVERS\e100b325.sys

18:03:19.0816 2848 E100B - ok

18:03:19.0926 2848 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

18:03:20.0117 2848 Fastfat - ok

18:03:20.0187 2848 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys

18:03:20.0367 2848 Fdc - ok

18:03:20.0417 2848 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys

18:03:20.0597 2848 Fips - ok

18:03:20.0647 2848 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys

18:03:20.0798 2848 Flpydisk - ok

18:03:20.0868 2848 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys

18:03:20.0988 2848 FltMgr - ok

18:03:21.0048 2848 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

18:03:21.0228 2848 Fs_Rec - ok

18:03:21.0278 2848 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

18:03:21.0449 2848 Ftdisk - ok

18:03:21.0509 2848 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

18:03:21.0679 2848 Gpc - ok

18:03:21.0799 2848 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys

18:03:21.0979 2848 HidUsb - ok

18:03:22.0049 2848 hpn - ok

18:03:22.0089 2848 hpt3xx - ok

18:03:22.0200 2848 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

18:03:22.0270 2848 HTTP - ok

18:03:22.0300 2848 i2omgmt - ok

18:03:22.0340 2848 i2omp - ok

18:03:22.0390 2848 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

18:03:22.0570 2848 i8042prt - ok

18:03:22.0610 2848 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys

18:03:22.0861 2848 Imapi - ok

18:03:22.0951 2848 ini910u - ok

18:03:23.0011 2848 IntelIde - ok

18:03:23.0061 2848 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys

18:03:23.0201 2848 intelppm - ok

18:03:23.0261 2848 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys

18:03:23.0411 2848 ip6fw - ok

18:03:23.0471 2848 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

18:03:23.0632 2848 IpFilterDriver - ok

18:03:23.0672 2848 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

18:03:23.0852 2848 IpInIp - ok

18:03:23.0912 2848 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

18:03:24.0072 2848 IpNat - ok

18:03:24.0122 2848 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys

18:03:24.0303 2848 IPSec - ok

18:03:24.0363 2848 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

18:03:24.0433 2848 IRENUM - ok

18:03:24.0493 2848 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys

18:03:24.0643 2848 isapnp - ok

18:03:24.0723 2848 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

18:03:24.0873 2848 Kbdclass - ok

18:03:24.0934 2848 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

18:03:25.0104 2848 kbdhid - ok

18:03:25.0174 2848 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

18:03:25.0354 2848 kmixer - ok

18:03:25.0404 2848 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

18:03:25.0504 2848 KSecDD - ok

18:03:25.0574 2848 lbrtfdc - ok

18:03:25.0795 2848 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

18:03:25.0975 2848 mnmdd - ok

18:03:26.0055 2848 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys

18:03:26.0205 2848 Modem - ok

18:03:26.0255 2848 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys

18:03:26.0446 2848 Mouclass - ok

18:03:26.0506 2848 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys

18:03:26.0676 2848 mouhid - ok

18:03:26.0726 2848 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

18:03:26.0866 2848 MountMgr - ok

18:03:26.0906 2848 mraid35x - ok

18:03:26.0966 2848 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

18:03:27.0087 2848 MRxDAV - ok

18:03:27.0167 2848 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

18:03:27.0277 2848 MRxSmb - ok

18:03:27.0367 2848 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

18:03:27.0507 2848 Msfs - ok

18:03:27.0557 2848 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

18:03:27.0748 2848 MSKSSRV - ok

18:03:27.0778 2848 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

18:03:27.0958 2848 MSPCLOCK - ok

18:03:28.0028 2848 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

18:03:28.0188 2848 MSPQM - ok

18:03:28.0258 2848 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

18:03:28.0389 2848 mssmbios - ok

18:03:28.0459 2848 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys

18:03:28.0539 2848 Mup - ok

18:03:28.0629 2848 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys

18:03:28.0769 2848 NDIS - ok

18:03:28.0839 2848 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

18:03:28.0889 2848 NdisTapi - ok

18:03:28.0969 2848 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

18:03:29.0140 2848 Ndisuio - ok

18:03:29.0180 2848 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

18:03:29.0360 2848 NdisWan - ok

18:03:29.0420 2848 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys

18:03:29.0490 2848 NDProxy - ok

18:03:29.0560 2848 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

18:03:29.0700 2848 NetBIOS - ok

18:03:29.0761 2848 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

18:03:29.0941 2848 NetBT - ok

18:03:30.0021 2848 Netdevio (1265eb253ed4ebe4acb3bd5f548ff796) C:\WINDOWS\system32\DRIVERS\netdevio.sys

18:03:30.0081 2848 Netdevio ( UnsignedFile.Multi.Generic ) - warning

18:03:30.0081 2848 Netdevio - detected UnsignedFile.Multi.Generic (1)

18:03:30.0181 2848 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys

18:03:30.0331 2848 NIC1394 - ok

18:03:30.0391 2848 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

18:03:30.0532 2848 Npfs - ok

18:03:30.0602 2848 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

18:03:30.0752 2848 Ntfs - ok

18:03:30.0842 2848 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

18:03:31.0012 2848 Null - ok

18:03:31.0082 2848 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

18:03:31.0243 2848 NwlnkFlt - ok

18:03:31.0283 2848 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

18:03:31.0463 2848 NwlnkFwd - ok

18:03:31.0533 2848 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys

18:03:31.0713 2848 NwlnkIpx - ok

18:03:31.0763 2848 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys

18:03:31.0944 2848 NwlnkNb - ok

18:03:32.0004 2848 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys

18:03:32.0174 2848 NwlnkSpx - ok

18:03:32.0244 2848 NWRDR (36b9b950e3d2e100970a48d8bad86740) C:\WINDOWS\system32\DRIVERS\nwrdr.sys

18:03:32.0304 2848 NWRDR - ok

18:03:32.0374 2848 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys

18:03:32.0504 2848 ohci1394 - ok

18:03:32.0595 2848 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys

18:03:32.0775 2848 Parport - ok

18:03:32.0825 2848 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

18:03:32.0985 2848 PartMgr - ok

18:03:33.0035 2848 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys

18:03:33.0205 2848 ParVdm - ok

18:03:33.0246 2848 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys

18:03:33.0386 2848 PCI - ok

18:03:33.0426 2848 PCIDump - ok

18:03:33.0486 2848 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys

18:03:33.0626 2848 PCIIde - ok

18:03:33.0666 2848 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys

18:03:33.0816 2848 Pcmcia - ok

18:03:33.0836 2848 PDCOMP - ok

18:03:33.0896 2848 PDFRAME - ok

18:03:33.0947 2848 PDRELI - ok

18:03:33.0997 2848 PDRFRAME - ok

18:03:34.0037 2848 perc2 - ok

18:03:34.0077 2848 perc2hib - ok

18:03:34.0227 2848 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

18:03:34.0407 2848 PptpMiniport - ok

18:03:34.0447 2848 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys

18:03:34.0607 2848 Processor - ok

18:03:34.0658 2848 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

18:03:34.0828 2848 PSched - ok

18:03:34.0888 2848 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

18:03:35.0058 2848 Ptilink - ok

18:03:35.0118 2848 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys

18:03:35.0128 2848 PxHelp20 - ok

18:03:35.0168 2848 ql1080 - ok

18:03:35.0208 2848 Ql10wnt - ok

18:03:35.0268 2848 ql12160 - ok

18:03:35.0308 2848 ql1240 - ok

18:03:35.0349 2848 ql1280 - ok

18:03:35.0389 2848 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

18:03:35.0559 2848 RasAcd - ok

18:03:35.0649 2848 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

18:03:35.0819 2848 Rasl2tp - ok

18:03:35.0859 2848 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

18:03:36.0040 2848 RasPppoe - ok

18:03:36.0110 2848 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

18:03:36.0260 2848 Raspti - ok

18:03:36.0320 2848 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

18:03:36.0470 2848 Rdbss - ok

18:03:36.0520 2848 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

18:03:36.0680 2848 RDPCDD - ok

18:03:36.0761 2848 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

18:03:36.0951 2848 rdpdr - ok

18:03:37.0031 2848 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys

18:03:37.0111 2848 RDPWD - ok

18:03:37.0171 2848 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys

18:03:37.0351 2848 redbook - ok

18:03:37.0432 2848 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\WINDOWS\system32\Drivers\RimUsb.sys

18:03:37.0512 2848 RimUsb - ok

18:03:37.0562 2848 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys

18:03:37.0632 2848 RimVSerPort - ok

18:03:37.0712 2848 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys

18:03:37.0892 2848 ROOTMODEM - ok

18:03:38.0062 2848 RTLWUSB (c3880bf1bad0b8eb69efb07a9c3fa7d9) C:\WINDOWS\system32\DRIVERS\wg111v2.sys

18:03:38.0163 2848 RTLWUSB - ok

18:03:38.0273 2848 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys

18:03:38.0453 2848 sdbus - ok

18:03:38.0513 2848 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

18:03:38.0623 2848 Secdrv - ok

18:03:38.0673 2848 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys

18:03:38.0824 2848 Serial - ok

18:03:38.0894 2848 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys

18:03:39.0074 2848 Sfloppy - ok

18:03:39.0154 2848 Simbad - ok

18:03:39.0244 2848 smwdm (014ab093e6452ea88031bb6e22919bb5) C:\WINDOWS\system32\drivers\smwdm.sys

18:03:39.0264 2848 smwdm - ok

18:03:39.0304 2848 Sparrow - ok

18:03:39.0354 2848 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

18:03:39.0525 2848 splitter - ok

18:03:39.0585 2848 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys

18:03:39.0655 2848 sr - ok

18:03:39.0735 2848 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys

18:03:39.0825 2848 Srv - ok

18:03:39.0875 2848 sscdbhk5 (1cbd1b58a32de97899f5290b05f856db) C:\WINDOWS\system32\drivers\sscdbhk5.sys

18:03:39.0895 2848 sscdbhk5 ( UnsignedFile.Multi.Generic ) - warning

18:03:39.0895 2848 sscdbhk5 - detected UnsignedFile.Multi.Generic (1)

18:03:39.0965 2848 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys

18:03:39.0985 2848 ssmdrv - ok

18:03:40.0045 2848 ssrtln (7fb07ac152d7a87e66204860002bd9a4) C:\WINDOWS\system32\drivers\ssrtln.sys

18:03:40.0055 2848 ssrtln ( UnsignedFile.Multi.Generic ) - warning

18:03:40.0055 2848 ssrtln - detected UnsignedFile.Multi.Generic (1)

18:03:40.0125 2848 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

18:03:40.0286 2848 swenum - ok

18:03:40.0326 2848 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

18:03:40.0506 2848 swmidi - ok

18:03:40.0556 2848 symc810 - ok

18:03:40.0586 2848 symc8xx - ok

18:03:40.0616 2848 sym_hi - ok

18:03:40.0646 2848 sym_u3 - ok

18:03:40.0716 2848 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

18:03:40.0876 2848 sysaudio - ok

18:03:40.0967 2848 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

18:03:41.0057 2848 Tcpip - ok

18:03:41.0107 2848 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

18:03:41.0287 2848 TDPIPE - ok

18:03:41.0347 2848 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

18:03:41.0507 2848 TDTCP - ok

18:03:41.0577 2848 TEchoCan (2109255e76ff3c24d3e9a2c452a258ea) C:\WINDOWS\system32\DRIVERS\TEchoCan.sys

18:03:41.0668 2848 TEchoCan ( UnsignedFile.Multi.Generic ) - warning

18:03:41.0668 2848 TEchoCan - detected UnsignedFile.Multi.Generic (1)

18:03:41.0728 2848 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

18:03:41.0898 2848 TermDD - ok

18:03:41.0978 2848 tfsnboio (2da3ca4022abb0802de7eeda574e78d6) C:\WINDOWS\system32\dla\tfsnboio.sys

18:03:42.0048 2848 tfsnboio ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0048 2848 tfsnboio - detected UnsignedFile.Multi.Generic (1)

18:03:42.0108 2848 tfsncofs (c8d6928759b77701c21dc90ad61197f2) C:\WINDOWS\system32\dla\tfsncofs.sys

18:03:42.0198 2848 tfsncofs ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0198 2848 tfsncofs - detected UnsignedFile.Multi.Generic (1)

18:03:42.0248 2848 tfsndrct (bacdef5510fa643683cddca418e49446) C:\WINDOWS\system32\dla\tfsndrct.sys

18:03:42.0258 2848 tfsndrct ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0258 2848 tfsndrct - detected UnsignedFile.Multi.Generic (1)

18:03:42.0309 2848 tfsndres (3fc9f390fac563c3d3910d540adbd408) C:\WINDOWS\system32\dla\tfsndres.sys

18:03:42.0349 2848 tfsndres ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0349 2848 tfsndres - detected UnsignedFile.Multi.Generic (1)

18:03:42.0389 2848 tfsnifs (6aef3ec0b64689536891a9b96e9d7b82) C:\WINDOWS\system32\dla\tfsnifs.sys

18:03:42.0449 2848 tfsnifs ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0449 2848 tfsnifs - detected UnsignedFile.Multi.Generic (1)

18:03:42.0489 2848 tfsnopio (7239873a72dd456f6e74e6987cdb9687) C:\WINDOWS\system32\dla\tfsnopio.sys

18:03:42.0539 2848 tfsnopio ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0539 2848 tfsnopio - detected UnsignedFile.Multi.Generic (1)

18:03:42.0589 2848 tfsnpool (b78631e3593ddd76a4a8ba7cb8e32302) C:\WINDOWS\system32\dla\tfsnpool.sys

18:03:42.0619 2848 tfsnpool ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0619 2848 tfsnpool - detected UnsignedFile.Multi.Generic (1)

18:03:42.0679 2848 tfsnudf (9e8b4abb93e5784fc4e5d3202566cc7a) C:\WINDOWS\system32\dla\tfsnudf.sys

18:03:42.0719 2848 tfsnudf ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0719 2848 tfsnudf - detected UnsignedFile.Multi.Generic (1)

18:03:42.0769 2848 tfsnudfa (056fa0a11ba4cd688e1e40e48ffee921) C:\WINDOWS\system32\dla\tfsnudfa.sys

18:03:42.0809 2848 tfsnudfa ( UnsignedFile.Multi.Generic ) - warning

18:03:42.0809 2848 tfsnudfa - detected UnsignedFile.Multi.Generic (1)

18:03:42.0889 2848 Thpevm (beeca51c9ef368a1038e455278e4715e) C:\WINDOWS\system32\DRIVERS\Thpevm.SYS

18:03:42.0939 2848 Thpevm - ok

18:03:43.0000 2848 TosIde - ok

18:03:43.0060 2848 TrueSight (f69641efdb19acb4753b0155f7fdeed5) c:\windows\system32\drivers\TrueSight.sys

18:03:43.0080 2848 TrueSight ( UnsignedFile.Multi.Generic ) - warning

18:03:43.0080 2848 TrueSight - detected UnsignedFile.Multi.Generic (1)

18:03:43.0160 2848 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

18:03:43.0330 2848 Udfs - ok

18:03:43.0370 2848 ultra - ok

18:03:43.0450 2848 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys

18:03:43.0660 2848 Update - ok

18:03:43.0761 2848 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

18:03:43.0931 2848 usbccgp - ok

18:03:44.0001 2848 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

18:03:44.0171 2848 usbehci - ok

18:03:44.0221 2848 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

18:03:44.0392 2848 usbhub - ok

18:03:44.0452 2848 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys

18:03:44.0632 2848 usbprint - ok

18:03:44.0672 2848 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys

18:03:44.0832 2848 usbscan - ok

18:03:44.0892 2848 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

18:03:45.0052 2848 USBSTOR - ok

18:03:45.0103 2848 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

18:03:45.0273 2848 usbuhci - ok

18:03:45.0313 2848 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

18:03:45.0483 2848 VgaSave - ok

18:03:45.0523 2848 ViaIde - ok

18:03:45.0583 2848 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys

18:03:45.0733 2848 VolSnap - ok

18:03:45.0904 2848 w29n51 (c89da341fcc883a3d79dc11727484fc2) C:\WINDOWS\system32\DRIVERS\w29n51.sys

18:03:46.0214 2848 w29n51 - ok

18:03:46.0404 2848 WacomPen (aced8c149b30f8496c237bcba3727b48) C:\WINDOWS\system32\DRIVERS\wacompen.sys

18:03:46.0565 2848 WacomPen - ok

18:03:46.0625 2848 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

18:03:46.0785 2848 Wanarp - ok

18:03:46.0825 2848 WDICA - ok

18:03:46.0885 2848 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

18:03:47.0035 2848 wdmaud - ok

18:03:47.0246 2848 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS\system32\Drivers\wpdusb.sys

18:03:47.0336 2848 WpdUsb - ok

18:03:47.0426 2848 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys

18:03:47.0576 2848 WS2IFSL - ok

18:03:47.0756 2848 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

18:03:47.0816 2848 WudfPf - ok

18:03:47.0867 2848 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

18:03:47.0937 2848 WudfRd - ok

18:03:48.0077 2848 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0

18:03:48.0307 2848 \Device\Harddisk0\DR0 - ok

18:03:48.0337 2848 Boot (0x1200) (76545e3e85c861d49706c673958bc73e) \Device\Harddisk0\DR0\Partition0

18:03:48.0337 2848 \Device\Harddisk0\DR0\Partition0 - ok

18:03:48.0347 2848 ============================================================

18:03:48.0347 2848 Scan finished

18:03:48.0347 2848 ============================================================

18:03:48.0487 2840 Detected object count: 17

18:03:48.0487 2840 Actual detected object count: 17

18:04:30.0007 2840 AegisP ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0007 2840 AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0007 2840 drvmcdb ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0007 2840 drvmcdb ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0017 2840 drvnddm ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0017 2840 drvnddm ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0027 2840 Netdevio ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0027 2840 Netdevio ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0047 2840 sscdbhk5 ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0047 2840 sscdbhk5 ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0057 2840 ssrtln ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0057 2840 ssrtln ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0067 2840 TEchoCan ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0067 2840 TEchoCan ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0077 2840 tfsnboio ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0077 2840 tfsnboio ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0097 2840 tfsncofs ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0097 2840 tfsncofs ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0107 2840 tfsndrct ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0107 2840 tfsndrct ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0117 2840 tfsndres ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0117 2840 tfsndres ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0127 2840 tfsnifs ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0127 2840 tfsnifs ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0147 2840 tfsnopio ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0147 2840 tfsnopio ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0157 2840 tfsnpool ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0157 2840 tfsnpool ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0167 2840 tfsnudf ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0167 2840 tfsnudf ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0187 2840 tfsnudfa ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0187 2840 tfsnudfa ( UnsignedFile.Multi.Generic ) - User select action: Skip

18:04:30.0197 2840 TrueSight ( UnsignedFile.Multi.Generic ) - skipped by user

18:04:30.0197 2840 TrueSight ( UnsignedFile.Multi.Generic ) - User select action: Skip

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.