Here's the file as per request.
Thanks so far
Cirrus
OTL logfile created on: 6/26/2012 2:29:16 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\blogger\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
4.00 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 49.19% Memory free
8.00 Gb Paging File | 4.97 Gb Available in Paging File | 62.14% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 456.92 Gb Total Space | 313.44 Gb Free Space | 68.60% Space Free | Partition Type: NTFS
Drive D: | 456.92 Gb Total Space | 456.81 Gb Free Space | 99.98% Space Free | Partition Type: NTFS
Computer Name: MSHOME | User Name: blogger | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Users\blogger\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\blogger\Desktop\aswMBR.exe (AVAST Software)
PRC - C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe (
http://www.express-files.com/)
PRC - C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe (PC Utilities Pro)
PRC - C:\Program Files (x86)\FlashGet Network\FlashGet 3\Flashget3.exe (Trend Media Corporation Limited)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
PRC - C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\FlashGet Network\FlashGet 3\zlib.dll ()
MOD - C:\Program Files (x86)\FlashGet Network\FlashGet 3\ckcore.dll ()
MOD - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BugReport.dll ()
MOD - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
MOD - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll ()
========== Win32 Services (SafeList) ========== SRV:
64bit: - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:
64bit: - (mfevtp) -- C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:
64bit: - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:
64bit: - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:
64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:
64bit: - (MSK80Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McMPFSvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McAfee SiteAdvisor Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:
64bit: - (Updater Service) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:
64bit: - (nSvcIp) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (NOBU) -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (MWLService) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (MOBKbackup) -- C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (GREGService) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV:
64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:
64bit: - (mfefirek) -- C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:
64bit: - (mfewfpk) -- C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:
64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:
64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:
64bit: - (mferkdet) -- C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:
64bit: - (mfenlfk) -- C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:
64bit: - (cfwids) -- C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:
64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:
64bit: - (NVNET) -- C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:
64bit: - (MOBKFilter) -- C:\Windows\SysNative\drivers\MOBK.sys (Mozy, Inc.)
DRV:
64bit: - (AVer7231_x64) -- C:\Windows\SysNative\drivers\AVer7231_x64.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (mwlPSDVDisk) -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:
64bit: - (mwlPSDFilter) -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:
64bit: - (mwlPSDNServ) -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:
64bit: - (mcdbus) -- C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (mcdbus) -- C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://acer.msn.comIE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBoxIE:
64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9848IE - HKLM\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBoxIE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9848&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://search.searchcompletion.com/?si=10197&home=1IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =
http://search.searchcompletion.com/?si=10197&home=1IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" =
http://start.facemoods.com/?a=audio&s={searchTerms}&f=4IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\..\SearchScopes\{4B34121C-8B20-4973-97EB-E349F855C4CF}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3176921IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enAU448IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" =
http://www.bigseekpro.com/search/browser/solidyoutube/{E02D20E8-FC2A-49FF-AB7C-AC6C417624C3}?q={searchTerms}IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9848&q={searchTerms}IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/02/28 08:07:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/06/18 16:15:26 | 000,000,000 | ---D | M]
[2012/02/09 07:56:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\blogger\AppData\Roaming\Mozilla\Extensions
[2011/10/05 11:32:05 | 000,003,195 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Complitly.xml
[2011/10/05 11:31:54 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchaudio.xml
O1 HOSTS File: ([2012/06/25 17:26:46 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found
O2:
64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120618111946.dll (McAfee, Inc.)
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:
64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120618111946.dll (McAfee, Inc.)
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\blogger\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll (Trend Media Group)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:
64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:
64bit: - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ArcadeMovieService] C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [ExpressFiles] C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe (
http://www.express-files.com/)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000..\Run: [FlashGet 3] C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe (Trend Media Corporation Limited)
O4 - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro)
O4 - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\blogger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3615671016-1225033205-3068105798-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Download all links by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetallurl.htm ()
O8:
64bit: - Extra context menu item: Download by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgeturl.htm ()
O8:
64bit: - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html File not found
O8:
64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Download all links by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetallurl.htm ()
O8 - Extra context menu item: Download by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgeturl.htm ()
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office10\EXCEL.EXE/3000 File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9159A1E6-6CDA-4AF7-8BDC-B99596A40793}: DhcpNameServer = 192.168.2.1
O18:
64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ========== [2012/06/26 14:25:18 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\blogger\Desktop\OTL.exe
[2012/06/26 13:32:19 | 000,000,000 | ---D | C] -- C:\Users\blogger\Desktop\Data for malw
[2012/06/26 08:46:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/06/26 06:24:58 | 002,128,472 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\blogger\Desktop\tdsskiller(1).exe
[2012/06/26 06:24:54 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\blogger\Desktop\aswMBR(1).exe
[2012/06/26 06:21:44 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\blogger\Desktop\aswMBR.exe
[2012/06/26 06:17:38 | 002,128,472 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\blogger\Desktop\tdsskiller.exe
[2012/06/25 17:46:30 | 000,000,000 | ---D | C] -- C:\Users\blogger\Desktop\messgae_files
[2012/06/25 17:28:26 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/25 17:18:01 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/25 17:18:01 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/25 17:18:01 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/25 17:16:33 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/25 17:16:24 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/06/25 17:14:35 | 004,567,602 | R--- | C] (Swearware) -- C:\Users\blogger\Desktop\ComboFix.exe
[2012/06/25 07:54:24 | 000,000,000 | ---D | C] -- C:\Users\blogger\Desktop\New folder
[2012/06/25 07:35:52 | 000,000,000 | ---D | C] -- C:\Users\blogger\Desktop\attach1
[2012/06/25 07:25:12 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\blogger\Desktop\dds.scr
[2012/06/20 18:19:49 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\blogger\Desktop\HijackThis.exe
[2012/06/19 17:36:52 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/06/19 17:36:52 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/06/19 17:36:51 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/06/19 17:36:35 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/06/19 17:36:35 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/06/19 17:36:35 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/06/19 17:36:22 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/06/19 17:36:22 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012/06/14 03:00:40 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/06/14 03:00:40 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/06/14 03:00:40 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/06/14 03:00:40 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/06/14 03:00:38 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/06/14 03:00:38 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/06/14 03:00:38 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/06/14 03:00:38 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/06/14 03:00:36 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/06/14 03:00:36 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/06/14 03:00:36 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/06/14 03:00:36 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/06/14 03:00:35 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/06/13 20:22:29 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 20:22:29 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 20:22:28 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 20:22:15 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 20:22:14 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 20:22:13 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 20:22:04 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012/06/13 20:21:54 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012/06/13 20:21:53 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012/05/27 21:20:24 | 000,000,000 | ---D | C] -- C:\BounceBack
[2012/05/27 21:20:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BounceBack Express
[2012/05/27 21:20:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CMS Peripherals
========== Files - Modified Within 30 Days ========== [2012/06/26 14:24:14 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\blogger\Desktop\OTL.exe
[2012/06/26 14:01:02 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/26 13:45:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/26 13:41:09 | 000,038,366 | ---- | M] () -- C:\Users\blogger\Desktop\Data for malw.zip
[2012/06/26 08:46:33 | 000,001,832 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2012/06/26 06:43:14 | 000,006,943 | ---- | M] () -- C:\Users\blogger\Documents\Document.rtf
[2012/06/26 06:20:39 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\blogger\Desktop\aswMBR.exe
[2012/06/26 06:16:53 | 002,128,472 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\blogger\Desktop\tdsskiller.exe
[2012/06/25 23:01:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/25 18:23:47 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 18:23:47 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 17:46:30 | 000,109,890 | ---- | M] () -- C:\Users\blogger\Desktop\messgae.htm
[2012/06/25 17:45:38 | 000,715,679 | ---- | M] () -- C:\Users\blogger\Desktop\post to bleeping pc.mht
[2012/06/25 17:26:46 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/25 17:17:34 | 004,567,602 | R--- | M] (Swearware) -- C:\Users\blogger\Desktop\ComboFix.exe
[2012/06/25 07:37:11 | 000,002,574 | ---- | M] () -- C:\Users\blogger\Desktop\attach1.zip
[2012/06/25 07:24:04 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\blogger\Desktop\dds.scr
[2012/06/25 07:21:51 | 000,000,000 | ---- | M] () -- C:\Users\blogger\defogger_reenable
[2012/06/24 18:36:32 | 000,881,475 | ---- | M] () -- C:\Users\blogger\Desktop\SecurityCheck.exe
[2012/06/24 18:32:34 | 000,050,477 | ---- | M] () -- C:\Users\blogger\Desktop\Defogger.exe
[2012/06/24 11:20:28 | 000,726,444 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/24 11:20:28 | 000,628,414 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/24 11:20:28 | 000,110,598 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/24 11:13:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/24 11:13:34 | 3220,623,360 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/23 20:45:29 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 20:45:29 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/21 18:10:22 | 002,128,472 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\blogger\Desktop\tdsskiller(1).exe
[2012/06/20 18:19:57 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\blogger\Desktop\HijackThis.exe
[2012/06/18 16:13:55 | 000,004,544 | ---- | M] () -- C:\Users\blogger\Documents\writing tips.rtf
[2012/06/18 14:16:35 | 000,881,475 | ---- | M] () -- C:\Users\blogger\Desktop\SecurityCheck(1).exe
[2012/06/14 03:27:35 | 004,853,376 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/03 08:19:46 | 000,038,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/06/03 08:19:42 | 000,057,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/06/03 08:19:42 | 000,044,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/06/03 08:19:23 | 000,701,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/06/03 08:15:31 | 002,622,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/06/03 08:15:08 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012/05/27 21:20:12 | 000,001,062 | ---- | M] () -- C:\Users\Public\Desktop\BounceBack Setup.lnk
[2012/05/27 21:20:12 | 000,001,062 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BounceBack Launcher.lnk
[2012/05/27 21:20:12 | 000,001,038 | ---- | M] () -- C:\Users\Public\Desktop\BounceBack QuickRestore.lnk
========== Files Created - No Company Name ========== [2012/06/26 13:41:09 | 000,038,366 | ---- | C] () -- C:\Users\blogger\Desktop\Data for malw.zip
[2012/06/26 06:43:14 | 000,006,943 | ---- | C] () -- C:\Users\blogger\Documents\Document.rtf
[2012/06/25 17:46:28 | 000,109,890 | ---- | C] () -- C:\Users\blogger\Desktop\messgae.htm
[2012/06/25 17:45:35 | 000,715,679 | ---- | C] () -- C:\Users\blogger\Desktop\post to bleeping pc.mht
[2012/06/25 17:18:01 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/25 17:18:01 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/25 17:18:01 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/25 17:18:01 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/25 17:18:01 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/25 07:37:11 | 000,002,574 | ---- | C] () -- C:\Users\blogger\Desktop\attach1.zip
[2012/06/25 07:29:10 | 000,881,475 | ---- | C] () -- C:\Users\blogger\Desktop\SecurityCheck(1).exe
[2012/06/25 07:21:51 | 000,000,000 | ---- | C] () -- C:\Users\blogger\defogger_reenable
[2012/06/25 07:20:12 | 000,881,475 | ---- | C] () -- C:\Users\blogger\Desktop\SecurityCheck.exe
[2012/06/24 18:33:30 | 000,050,477 | ---- | C] () -- C:\Users\blogger\Desktop\Defogger.exe
[2012/06/18 16:13:55 | 000,004,544 | ---- | C] () -- C:\Users\blogger\Documents\writing tips.rtf
[2012/05/27 21:20:18 | 000,032,768 | ---- | C] () -- C:\Windows\BBUninstall.exe
[2012/05/27 21:20:12 | 000,001,062 | ---- | C] () -- C:\Users\Public\Desktop\BounceBack Setup.lnk
[2012/05/27 21:20:12 | 000,001,062 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BounceBack Launcher.lnk
[2012/05/27 21:20:12 | 000,001,038 | ---- | C] () -- C:\Users\Public\Desktop\BounceBack QuickRestore.lnk
[2012/04/27 11:31:53 | 000,000,306 | ---- | C] () -- C:\Windows\PowerReg.dat
[2012/04/09 18:54:19 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2012/01/22 17:40:24 | 000,004,993 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat
[2012/01/22 17:35:15 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2011/12/19 19:22:37 | 000,098,344 | ---- | C] () -- C:\Windows\unTMV.exe
[2011/12/12 15:29:06 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/12/11 21:27:45 | 000,007,597 | ---- | C] () -- C:\Users\blogger\AppData\Local\resmon.resmoncfg
[2011/11/19 20:53:33 | 000,000,000 | ---- | C] () -- C:\Windows\OpPrintServer.INI
[2011/11/10 06:21:33 | 000,000,000 | ---- | C] () -- C:\Users\blogger\AppData\Local\{5DCBAF05-333C-4459-B6F6-3856DBFFCE67}
[2011/10/23 12:00:45 | 000,000,000 | ---- | C] () -- C:\Users\blogger\AppData\Local\{C12456D2-3A8C-4FAE-93A2-37E01103AB20}
[2011/10/23 11:58:53 | 000,000,000 | ---- | C] () -- C:\Users\blogger\AppData\Local\{9BD86E4B-F124-4A8B-81C8-9B20C6D9EF47}
[2011/02/10 16:57:24 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_89001461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_49001461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_33011461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A0F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_14001461_61.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_13011461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_8a.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_8a.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A0F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_8a.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_09001461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_08071461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_060F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_8a.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_8a.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_8a.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_8a.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_aa.bin
[2010/08/27 11:07:55 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_8a.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_ca.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_aa.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_8a.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_ca.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_aa.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_8a.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_07031461_aa.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_ca.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_aa.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_8a.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03131461_8a.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03031461_aa.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_ca.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_aa.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_8a.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_aa.bin
[2010/08/27 11:07:55 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_8a.bin
[2010/08/27 11:07:55 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_890F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_29001461_ca.bin
[2010/08/27 11:07:55 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_090F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_180F1461_ca.bin
[2010/08/27 11:07:55 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_18071461_aa.bin
[2010/08/27 11:07:55 | 000,000,376 | ---- | C] () -- C:\Windows\11317231_03131461_aa.bin
========== Files - Unicode (All) ==========[2011/11/03 07:48:11 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?Ë) -- C:\Windows\SysNative\꓀Ë
[2011/11/03 07:48:11 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?Ë) -- C:\Windows\SysNative\꓀Ë
========== Alternate Data Streams ========== @Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:E1F04E8D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:798A3728