thanx for your continuing support. here's your reward, lol. there's plenty here to get your teeth into...
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=b51c2381ed80464ab6d4d30df1e95751
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-11-13 09:29:58
# local_time=2012-11-13 09:29:58 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 424586 424586 0 0
# compatibility_mode=768 16777215 100 0 67807143 67807143 0 0
# compatibility_mode=5892 16776637 100 100 310758 190325508 0 0
# compatibility_mode=8192 67108863 100 0 3863 3863 0 0
# scanned=161957
# found=5
# cleaned=5
# scan_time=6263
C:\Program Files\FoxTabVideoConverter\VideoConverter.exe a variant of Win32/InstallCore.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Users\Steve\Desktop\Brothersoft_downloader_For_iOpener.exe a variant of Win32/BSDownloader application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Users\Steve\Desktop\Desktop Icons\YouTubeDownloaderSetup33.exe a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Users\Steve\Desktop\Desktop Icons\YouTubeDownloaderSetup34.exe a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Users\Steve\Downloads\regvissetup.exe a variant of Win32/Adware.ErrorRepairPro application (deleted - quarantined) 00000000000000000000000000000000 C
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=b51c2381ed80464ab6d4d30df1e95751
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-11-15 07:57:07
# local_time=2012-11-15 07:57:07 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 631330 631330 0 0
# compatibility_mode=768 16777215 100 0 68013887 68013887 0 0
# compatibility_mode=5892 16776638 100 100 517502 190532252 0 0
# compatibility_mode=8192 67108863 100 0 210607 210607 0 0
# scanned=160131
# found=4
# cleaned=0
# scan_time=9947
C:\Qoobox\Quarantine\C\Windows\System32\Process.exe.vir Win32/PrcView application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Steve\AppData\Roaming\Business Logic\UWC\Backup\J40223.4634724884.WCU Win32/Toolbar.AskSBar application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Steve\Desktop\Desktop Icons\Adaware_Installer.exe Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I
C:\Windows\Installer\b8837.msi probably a variant of Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I
-------------------------
Results of screen317's Security Check version 0.99.54
Windows Vista Service Pack 2 x86
(UAC is disabled!) Internet Explorer 9
``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled!
Windows Firewall Disabled!
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:````````` Out of date HijackThis installed! Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.65.1.1000
HijackThis 1.99.1
CCleaner
Java 7 Update 9
Adobe Flash Player 10
Flash Player out of Date! Adobe Reader 8
Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled! Malwarebytes' Anti-Malware mbamscheduler.exe
Alwil Software Avast5 AvastSvc.exe
Alwil Software Avast5 AvastUI.exe
`````````````````System Health check````````````````` Total Fragmentation on Drive C: 1 %
````````````````````End of Log`````````````````````` ---------------------------------
OTL logfile created on: 15/11/2012 20:23:00 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Steve\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
766.51 Mb Total Physical Memory | 102.65 Mb Available Physical Memory | 13.39% Memory free
1.76 Gb Paging File | 0.68 Gb Available in Paging File | 38.77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.05 Gb Total Space | 46.86 Gb Free Space | 34.44% Space Free | Partition Type: NTFS
Computer Name: STEVE-PC | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/11/14 11:14:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Steve\Desktop\OTL.exe
PRC - [2012/10/30 22:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/10/30 22:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/11 09:10:18 | 001,995,600 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
PRC - [2012/09/11 09:10:16 | 001,258,320 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe
PRC - [2012/07/29 19:52:22 | 000,976,728 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2012/07/29 19:52:20 | 001,673,048 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2012/07/05 05:58:58 | 000,332,488 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Common Files\Motive\pcControlHost.exe
PRC - [2012/03/02 21:34:26 | 000,361,472 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Common Files\Motive\pcCMService.exe
PRC - [2011/07/28 16:06:32 | 008,247,264 | ---- | M] () -- C:\Program Files\NETGEAR\WNA1100\WNA1100.exe
PRC - [2011/07/28 16:06:20 | 000,297,440 | ---- | M] () -- C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe
PRC - [2009/04/11 06:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/05/29 08:49:58 | 000,083,264 | ---- | M] (Packard Bell Services) -- C:\Windows\System32\HidService.exe
PRC - [2008/05/07 08:19:26 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/01/21 02:32:50 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdSync.exe
PRC - [2003/08/27 09:29:46 | 000,065,536 | ---- | M] (America Online, Inc.) -- C:\Windows\wanmpsvc.exe
========== Modules (No Company Name) ========== MOD - [2012/05/28 20:44:02 | 000,520,464 | ---- | M] () -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\39624\RapportMS.dll
MOD - [2012/02/01 13:43:10 | 000,557,056 | ---- | M] () -- C:\Program Files\Trusteer\Rapport\bin\js32.dll
MOD - [2011/07/28 16:06:32 | 008,247,264 | ---- | M] () -- C:\Program Files\NETGEAR\WNA1100\WNA1100.exe
MOD - [2009/08/28 15:50:18 | 000,282,624 | ---- | M] () -- C:\Program Files\NETGEAR\WNA1100\WifiSvcLib.dll
MOD - [2009/08/16 16:06:02 | 000,141,312 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Services (SafeList) ========== SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Roxio Creator 2009 Ultimate\Digital Home 11\RoxioUPnPRenderer11.exe -- (Roxio UPnP Renderer 11)
SRV - File not found [Auto | Stopped] -- -- (AOL ACS)
SRV - [2012/10/30 22:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/10/18 18:51:24 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe -- (GoToAssist)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/07/29 19:52:22 | 000,976,728 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2012/03/02 21:34:26 | 000,361,472 | ---- | M] (Alcatel-Lucent) [Auto | Running] -- C:\Program Files\Common Files\Motive\pcCMService.exe -- (pcCMService)
SRV - [2011/07/28 16:06:20 | 000,297,440 | ---- | M] () [Auto | Running] -- C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe -- (WSWNA1100)
SRV - [2010/03/22 19:05:40 | 000,960,992 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\NETGEAR\WNA1100\jswpsapi.exe -- (jswpsapi)
SRV - [2008/05/29 08:49:58 | 000,083,264 | ---- | M] (Packard Bell Services) [Auto | Running] -- C:\Windows\System32\HidService.exe -- (GenericHidService)
SRV - [2008/02/03 11:00:00 | 000,129,992 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\Windows\System32\ezsvc7.dll -- (ezSharedSvc)
SRV - [2008/01/21 02:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/21 02:32:50 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2008/01/21 02:32:50 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2005/01/06 17:41:22 | 000,462,848 | ---- | M] (Lexmark International, Inc.) [On_Demand | Stopped] -- C:\Windows\System32\lxbycoms.exe -- (lxby_device)
SRV - [2003/08/27 09:29:46 | 000,065,536 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\Windows\wanmpsvc.exe -- (WANMiniportService)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\SBREdrv.sys -- (SBRE)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys -- (Lavasoft Kernexplorer)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Steve\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Steve\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | System | Stopped] -- C:\Users\Steve\Desktop\New Folder\Run\a2ddax86.sys -- (A2DDA)
DRV - [2012/10/30 22:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 22:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 22:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 22:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012/10/30 22:51:57 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012/10/30 22:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/10/23 15:02:46 | 000,272,216 | ---- | M] () [Kernel | System | Running] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus32_43926.sys -- (RapportCerberus_43926)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/07/29 19:52:38 | 000,166,840 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2012/07/29 19:52:38 | 000,071,480 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI)
DRV - [2012/07/29 19:52:38 | 000,065,848 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2012/07/05 05:58:02 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2012/07/05 05:57:44 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2012/05/28 20:42:48 | 000,021,520 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Running] -- c:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\39624\RapportIaso.sys -- (RapportIaso)
DRV - [2011/07/22 09:35:16 | 000,021,472 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SCMNdisP.sys -- (SCMNdisP)
DRV - [2010/10/10 18:48:00 | 001,439,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athur.sys -- (athur)
DRV - [2010/09/14 13:38:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2010/09/14 13:38:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2010/09/14 13:38:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2010/09/14 13:38:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2010/09/14 13:38:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2009/08/12 15:45:55 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2009/04/11 04:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb)
DRV - [2008/09/17 23:55:00 | 007,379,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/08/11 10:03:24 | 000,254,320 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\Windows\System32\drivers\C2SCSI.SYS -- (c2scsi)
DRV - [2008/05/15 01:28:00 | 000,020,384 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2007/10/31 03:23:20 | 000,115,744 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2006/11/02 07:30:56 | 000,044,544 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2003/01/10 15:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wanatw4.sys -- (wanatw)
DRV - [2002/02/22 23:08:02 | 000,214,656 | ---- | M] (Roxio) [File_System | System | Running] -- C:\Windows\System32\drivers\udfreadr.sys -- (UdfReadr)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://home.bt.yahoo.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
[2010/05/13 16:09:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Steve\AppData\Roaming\Mozilla\Extensions
[2010/05/13 16:09:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Steve\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2012/02/11 12:02:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\extensions
[2012/02/11 12:02:21 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
O1 HOSTS File: ([2012/11/15 09:03:41 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Steve\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.9.2)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9}
http://support.microsoft.com/mats/DiagWebControl.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6E3AE754-E200-4375-97D4-BCBA6EB8FBE1}: DhcpNameServer = 192.168.1.254
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\570\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Steve\Pictures\orion nebula.jpg
O24 - Desktop BackupWallPaper: C:\Users\Steve\Pictures\orion nebula.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/11/15 09:09:19 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/11/15 09:09:10 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/11/15 09:09:10 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\temp
[2012/11/15 08:43:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/11/15 08:43:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/11/15 08:43:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/11/15 08:42:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/11/15 08:41:37 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/11/15 08:25:32 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{AE12BC92-F2AB-445F-AAF3-9708FB1D6638}
[2012/11/15 08:04:27 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{1B60015C-B5B2-4937-9055-54735AA3175E}
[2012/11/14 17:43:48 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{A00E735F-AC93-4EB9-A05E-E10D1716CFE0}
[2012/11/14 17:25:51 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/11/14 11:14:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Steve\Desktop\OTL.exe
[2012/11/14 09:49:09 | 000,688,901 | R--- | C] (Swearware) -- C:\Users\Steve\Desktop\dds.com
[2012/11/14 09:35:55 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\Ahead
[2012/11/13 21:28:45 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Florence_And_The_Machine
[2012/11/13 20:53:53 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Marillion-Sounds_That_Cant_Be_Made-2012
[2012/11/13 10:56:20 | 000,752,145 | ---- | C] (Farbar) -- C:\Users\Steve\Desktop\MiniToolBox.exe
[2012/11/13 10:51:50 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{4E80485D-4E7D-4758-85AF-03CE5F74EBA5}
[2012/11/13 09:50:06 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Steve\Desktop\tdsskiller.exe
[2012/11/13 09:42:02 | 001,754,528 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\Steve\Desktop\rkill.com
[2012/11/13 07:41:13 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/11/12 19:42:43 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{B2862B03-8D92-4F31-85E8-24F9EFBC7BEE}
[2012/11/12 18:25:45 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\Malwarebytes
[2012/11/12 18:24:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/12 18:24:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/11/12 18:24:39 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/11/12 18:24:39 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/12 07:25:52 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{72D0A7E3-08DF-4452-AD72-61CECD17331B}
[2012/11/11 21:17:03 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2012/11/11 18:08:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2012/11/11 17:42:13 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/11/11 08:47:16 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{E94AD84C-5EAC-42E9-8622-56E1F79CB96D}
[2012/11/10 18:23:53 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\{9B86B04E-754A-4F50-B434-564DC3775EE6}
[2012/11/10 16:27:10 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\Downloaded Installations
[2012/11/10 16:24:48 | 000,000,000 | ---D | C] -- C:\Program Files\adawaretb
[2012/11/10 16:24:40 | 000,000,000 | ---D | C] -- C:\Program Files\Toolbar Cleaner
[2012/11/10 16:23:19 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\LavasoftStatistics
[2012/11/10 13:59:10 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2012/11/10 13:48:52 | 005,001,537 | R--- | C] (Swearware) -- C:\Users\Steve\Desktop\ComboFix.exe
[2012/11/10 13:25:14 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Steve_Hackett_-_Genesis_Revisited_II (2012)
[2012/11/09 18:04:53 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\Avg2013
[2012/11/09 16:57:59 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/11/08 17:12:50 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\TuneUp Software
[2012/11/08 17:02:48 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\MFAData
[2012/11/08 10:49:18 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/11/08 10:49:10 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012/10/30 17:39:35 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Bat For Lashes - The Haunted Man (2012)
[2012/10/28 08:54:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Desktop Help
[2012/10/24 10:37:25 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Jadis - See Right Through You (2012)#
[2012/10/23 10:22:58 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012/10/22 12:38:16 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Lucy Rose - Like I Used To 2012
[2012/10/22 11:42:25 | 001,439,744 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athur.sys
[2012/10/22 11:42:24 | 000,021,472 | ---- | C] (Windows ® Win 7 DDK provider) -- C:\Windows\System32\drivers\SCMNdisP.sys
[2012/10/22 11:42:24 | 000,020,384 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\System32\drivers\jswpslwf.sys
[2012/10/22 11:42:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNA1100 Genie
[2012/10/22 11:41:56 | 000,000,000 | ---D | C] -- C:\Program Files\NETGEAR
[2012/10/20 07:17:12 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Ellie Goulding - Halcyon 2012
[2012/10/19 08:17:50 | 000,000,000 | ---D | C] -- C:\Users\Steve\Desktop\Muse - The 2nd Law#
[2012/10/18 18:56:46 | 000,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\Motive
[2012/10/18 18:52:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Motive
[2012/10/18 18:52:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Motive
[2012/10/18 18:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\BT Broadband Desktop Help
[2012/10/18 18:50:49 | 000,000,000 | ---D | C] -- C:\Program Files\Citrix
[2012/10/18 18:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BTHomeHub
[2012/10/18 18:47:32 | 000,000,000 | ---D | C] -- C:\Program Files\BTHomeHub
========== Files - Modified Within 30 Days ========== [2012/11/15 20:10:14 | 000,881,833 | ---- | M] () -- C:\Users\Steve\Desktop\SecurityCheck.exe
[2012/11/15 19:59:08 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/15 19:59:08 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/15 18:57:07 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/15 18:57:06 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/15 18:00:03 | 000,000,444 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Registration3.job
[2012/11/15 18:00:03 | 000,000,442 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Registration.job
[2012/11/15 16:56:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/15 09:03:41 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/11/15 08:41:24 | 005,001,537 | R--- | M] (Swearware) -- C:\Users\Steve\Desktop\ComboFix.exe
[2012/11/14 11:14:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Steve\Desktop\OTL.exe
[2012/11/14 10:00:36 | 000,302,592 | ---- | M] () -- C:\Users\Steve\Desktop\0m1wjh70.exe
[2012/11/14 09:49:13 | 000,688,901 | R--- | M] (Swearware) -- C:\Users\Steve\Desktop\dds.com
[2012/11/14 09:46:51 | 000,050,477 | ---- | M] () -- C:\Users\Steve\Desktop\Defogger.exe
[2012/11/14 08:00:46 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012/11/13 10:56:21 | 000,752,145 | ---- | M] (Farbar) -- C:\Users\Steve\Desktop\MiniToolBox.exe
[2012/11/13 09:52:34 | 000,541,569 | ---- | M] () -- C:\Users\Steve\Desktop\AdwCleaner.exe
[2012/11/13 09:50:07 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Steve\Desktop\tdsskiller.exe
[2012/11/13 09:42:03 | 001,754,528 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\Steve\Desktop\rkill.com
[2012/11/13 08:33:10 | 000,001,441 | ---- | M] () -- C:\scu.dat
[2012/11/12 18:24:52 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/11 20:26:43 | 000,007,288 | ---- | M] () -- C:\Users\Steve\Documents\cc_20121111_202418.reg
[2012/11/11 18:17:23 | 000,001,057 | ---- | M] () -- C:\Users\Steve\Desktop\Spybot - Search & Destroy.lnk
[2012/11/11 17:19:29 | 000,002,523 | ---- | M] () -- C:\Users\Steve\Desktop\HiJackThis.lnk
[2012/11/11 16:22:01 | 000,381,984 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/11/11 09:11:47 | 000,012,720 | ---- | M] () -- C:\Users\Steve\Documents\cc_20121111_091119.reg
[2012/11/10 16:20:37 | 000,000,318 | -H-- | M] () -- C:\aaw7boot.cmd
[2012/11/10 11:43:15 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012/11/10 07:45:53 | 000,000,945 | ---- | M] () -- C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/11/10 07:44:51 | 000,602,846 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/11/10 07:44:51 | 000,106,292 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/11/09 21:25:22 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2012/11/09 21:25:21 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2012/11/09 21:23:51 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012/11/09 17:33:59 | 000,438,982 | ---- | M] () -- C:\Users\Steve\Documents\ccleaner_20121109_173144.reg
[2012/11/09 16:58:16 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/11/08 07:47:11 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/11/07 12:40:37 | 000,000,691 | ---- | M] () -- C:\Users\Steve\AppData\Roaming\GetValue.vbs
[2012/11/07 12:40:37 | 000,000,035 | ---- | M] () -- C:\Users\Steve\AppData\Roaming\SetValue.bat
[2012/11/06 19:41:50 | 000,443,692 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.20121107-121832.backup
[2012/11/02 11:50:39 | 747,323,320 | ---- | M] () -- C:\Users\Steve\Desktop\Prometheus.2012.DVDRip.XviD-PTpOWeR.avi
[2012/10/30 22:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012/10/30 22:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012/10/30 22:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012/10/30 22:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012/10/30 22:51:57 | 000,058,680 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012/10/30 22:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012/10/30 22:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012/10/30 22:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012/10/29 16:08:30 | 734,212,096 | ---- | M] () -- C:\Users\Steve\Desktop\the raven.avi
[2012/10/28 08:54:28 | 000,001,135 | ---- | M] () -- C:\Users\Public\Desktop\BT Desktop Help.lnk
[2012/10/23 11:02:20 | 000,000,680 | ---- | M] () -- C:\Users\Steve\AppData\Local\d3d9caps.dat
[2012/10/22 11:42:00 | 000,000,701 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA1100 Genie.lnk
[2012/10/22 11:42:00 | 000,000,683 | ---- | M] () -- C:\Users\Public\Desktop\NETGEAR WNA1100 Genie.lnk
[2012/10/18 18:49:53 | 000,001,818 | ---- | M] () -- C:\Users\Public\Desktop\My BT.LNK
[2012/10/18 18:49:52 | 000,001,844 | ---- | M] () -- C:\Users\Public\Desktop\BT email & search.LNK
========== Files Created - No Company Name ========== [2012/11/15 20:09:46 | 000,881,833 | ---- | C] () -- C:\Users\Steve\Desktop\SecurityCheck.exe
[2012/11/15 08:43:00 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/11/15 08:43:00 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/11/15 08:43:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/11/15 08:43:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/11/15 08:43:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/11/14 10:00:36 | 000,302,592 | ---- | C] () -- C:\Users\Steve\Desktop\0m1wjh70.exe
[2012/11/14 09:46:49 | 000,050,477 | ---- | C] () -- C:\Users\Steve\Desktop\Defogger.exe
[2012/11/13 09:52:31 | 000,541,569 | ---- | C] () -- C:\Users\Steve\Desktop\AdwCleaner.exe
[2012/11/13 08:00:33 | 000,001,441 | ---- | C] () -- C:\scu.dat
[2012/11/12 18:24:52 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/11 20:26:39 | 000,007,288 | ---- | C] () -- C:\Users\Steve\Documents\cc_20121111_202418.reg
[2012/11/11 18:17:23 | 000,001,057 | ---- | C] () -- C:\Users\Steve\Desktop\Spybot - Search & Destroy.lnk
[2012/11/11 10:00:08 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
[2012/11/11 10:00:07 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
[2012/11/11 10:00:06 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
[2012/11/11 09:11:33 | 000,012,720 | ---- | C] () -- C:\Users\Steve\Documents\cc_20121111_091119.reg
[2012/11/10 16:20:37 | 000,000,318 | -H-- | C] () -- C:\aaw7boot.cmd
[2012/11/10 07:45:52 | 000,000,951 | ---- | C] () -- C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/11/09 21:23:51 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012/11/09 17:32:22 | 000,438,982 | ---- | C] () -- C:\Users\Steve\Documents\ccleaner_20121109_173144.reg
[2012/11/09 16:58:16 | 000,000,806 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/11/08 10:49:18 | 000,002,523 | ---- | C] () -- C:\Users\Steve\Desktop\HiJackThis.lnk
[2012/11/08 07:47:11 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/11/06 19:41:55 | 000,000,691 | ---- | C] () -- C:\Users\Steve\AppData\Roaming\GetValue.vbs
[2012/11/06 19:41:55 | 000,000,035 | ---- | C] () -- C:\Users\Steve\AppData\Roaming\SetValue.bat
[2012/11/02 11:38:21 | 747,323,320 | ---- | C] () -- C:\Users\Steve\Desktop\Prometheus.2012.DVDRip.XviD-PTpOWeR.avi
[2012/10/28 18:28:29 | 734,212,096 | ---- | C] () -- C:\Users\Steve\Desktop\the raven.avi
[2012/10/28 08:54:28 | 000,001,135 | ---- | C] () -- C:\Users\Public\Desktop\BT Desktop Help.lnk
[2012/10/23 11:02:20 | 000,000,680 | ---- | C] () -- C:\Users\Steve\AppData\Local\d3d9caps.dat
[2012/10/22 11:42:00 | 000,000,701 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA1100 Genie.lnk
[2012/10/22 11:42:00 | 000,000,683 | ---- | C] () -- C:\Users\Public\Desktop\NETGEAR WNA1100 Genie.lnk
[2012/10/18 18:49:53 | 000,001,818 | ---- | C] () -- C:\Users\Public\Desktop\My BT.LNK
[2012/10/18 18:49:52 | 000,001,844 | ---- | C] () -- C:\Users\Public\Desktop\BT email & search.LNK
[2012/03/11 07:44:42 | 000,000,231 | ---- | C] () -- C:\Windows\cdplayer.ini
[2012/03/11 07:34:25 | 000,001,534 | ---- | C] () -- C:\ProgramData\ss.ini
[2012/03/09 18:24:39 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2012/01/04 06:53:19 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2012/01/04 06:53:19 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/04/17 08:01:48 | 000,069,632 | ---- | C] () -- C:\Windows\realbap1.dll
[2011/04/17 08:01:48 | 000,045,568 | ---- | C] () -- C:\Windows\realbsf1.dll
[2011/04/17 08:01:43 | 000,069,632 | ---- | C] () -- C:\Windows\System32\realbap1.dll
[2011/04/17 08:01:43 | 000,045,568 | ---- | C] () -- C:\Windows\System32\realbsf1.dll
[2011/04/02 09:56:34 | 000,000,073 | ---- | C] () -- C:\Windows\EurekaLog.ini
[2010/06/30 14:15:20 | 000,000,373 | ---- | C] () -- C:\Users\Steve\Documents - Shortcut.lnk
[2010/01/31 12:19:04 | 000,137,020 | ---- | C] () -- C:\Users\Steve\AppData\Local\rx_audio.Cache
[2009/12/10 13:59:09 | 000,001,024 | ---- | C] () -- C:\Users\Steve\.rnd
[2009/09/26 12:23:15 | 000,004,536 | ---- | C] () -- C:\Users\Steve\AppData\Local\rx_image32.Cache
[2009/08/15 14:51:03 | 000,000,104 | ---- | C] () -- C:\Users\Steve\AppData\Roaming\wklnhst.dat
[2009/08/14 14:36:58 | 000,014,336 | ---- | C] () -- C:\Users\Steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ========== [2006/11/02 12:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 17:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 06:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 06:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2009/11/13 16:43:49 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Amazon
[2011/06/12 08:02:37 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\avidemux
[2010/02/14 11:05:52 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Business Logic
[2010/09/05 09:31:22 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Canneverbe Limited
[2009/10/02 07:51:59 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\CDRoller
[2009/12/10 14:30:35 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\DeepBurner Pro
[2009/09/19 13:01:49 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\DriverCure
[2011/11/08 07:16:56 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\DVDVideoSoft
[2011/03/13 08:15:56 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/11/16 19:06:47 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\EPSON
[2010/09/05 10:12:22 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\FinalBurner Video DVD
[2009/12/10 13:11:32 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\FoxScribe
[2009/08/29 07:47:38 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Free Audio Editor
[2010/03/13 16:44:08 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\ImTOO Software Studio
[2010/01/16 08:26:54 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\InfraRecorder
[2009/09/12 15:01:02 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\NCH Swift Sound
[2009/08/12 15:36:51 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Packard Bell
[2010/08/22 14:57:04 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Softplicity
[2011/10/10 06:01:31 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Template
[2010/05/15 11:34:02 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Trusteer
[2012/11/08 17:12:50 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\TuneUp Software
[2012/11/14 08:21:22 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\uTorrent
[2012/08/04 10:27:12 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Xilisoft
[2010/06/06 12:08:56 | 000,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\Xilisoft Corporation
========== Purity Check ========== < End of report >