Thanks, Agent ST.
here is my report regarding your latest instructions.
First, I'd like to tell you that I encountered a problem/scare.
It happened when I was removing the HijackThis (HJT).
I decided to do that right after removing Adobe Acrobat (before attempting to install IE).
I clicked on the HJT name in the Control Panel and got this message:
"This will remove HJT settings for the registry and exit. You will have to delete HijackThis.exe manually".
I clicked OK and it got removed from the Control Panel.
Next I looked for that HijackThis.exe file and found out that it was in this directory:
C:\Program Files\Trend Micro\HijackThis
I deleted the HijackThis folder and then this problem happened - I don't remember - right after deletion or I did reboot after that.
Anyway, what I had was basically empty screen, with no icons, so I wasn't able to do anything!!!!
I got scared, but came up with only solution I knew... I restarted in Safe Mode with networking and restored that stupid HijackThis folder. Then restarted normally and it worked! But it means that HJT is not removed completely.
The other issue I encountered was the Internet Explorer.
When Trying to install, I got this message: "IE did not finish installing".
I tried the Troubleshooting, but it is extremely (at least for me) complicated because there are so many possible causes.
For example, I was told that I have to install 11 security updates. I tried doing that, but they were not installed. Which of them (or lack of them) is causing he installation problem? I don't know, it's impossible for me to solve this (there maybe dozens of combinations with 11 updates...).
Because I use IE very rarely, I decided not to install it and maybe do it later when Microsoft solves this problem (apparently they know there is a big problem with this).
Still, sometimes it is necessary to use IE, so could you please help me to install IE?
And what about those 11 security updates - is there any easier way to solve it??? Please help with this too, if you can.
Finally, I had a small problem with OTL Fix.
When I was running it, I noticed writing: "Not Responding". But at the same time the hour-glass or rather small wheel was turning. Then "Not Responding" disappeared, but inn the background the icons on the screen were gone and nothing was going on for few minutes and only last 2 items in that Custom Scans/Fixes were showing.
At that time, I clicked on Run Fix again. It looked like it was running again and it showed "Not Responding" again, then "Not Responding" disappeared, but nothing was going on in the OTL window. After a few minutes, I clicked outside the OTL window and the green bar at the bottom of the OTL window started to move and soon I got the message to click OK to reboot. After that I got the OTL log (OTLFix #1).
But because I wasn't sure it was done properly, I ran OTL Fix again (OTLFix #2).
I will paste all the logs below, but first I will address your question re outstanding issues:
- the laptop runs quite well, I don't see any slowing down or refusing to perform any operations, although I must say that I use it now only to perform the tasks you're telling me to do;
- I don't have any anti-virus now; which one would you suggest? I don't want to go back to AVG...
- how would you suggest solve the issues from this stage:
- HJT
- IE
- Windows security updates
Thanks in advance for more help.
Here are the logs:
OTLFix #1:
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
========== REGISTRY ==========
========== FILES ==========
< echo,Y|cacls "%WinDir%\system32\drivers\etc\hosts" /G everyone:f /c >
Are you sure (Y/N)?processed file: C:\Windows\system32\drivers\etc\Hosts
C:\Users\karolinka\Desktop\cmd.bat deleted successfully.
C:\Users\karolinka\Desktop\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\karolinka\Desktop\cmd.bat deleted successfully.
C:\Users\karolinka\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: karolinka
->Temp folder emptied: 51986863 bytes
->Temporary Internet Files folder emptied: 18409131 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 52166145 bytes
->Flash cache emptied: 611 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 111424511 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 223.00 mb
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: karolinka
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 01162012_121437
Files\Folders moved on Reboot...
C:\Users\karolinka\AppData\Local\Temp\ehmsas.txt moved successfully.
Registry entries deleted on Reboot...
==
OTLFix #2:
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
========== REGISTRY ==========
========== FILES ==========
< echo,Y|cacls "%WinDir%\system32\drivers\etc\hosts" /G everyone:f /c >
Are you sure (Y/N)?processed file: C:\Windows\system32\drivers\etc\Hosts
C:\Users\karolinka\Desktop\cmd.bat deleted successfully.
C:\Users\karolinka\Desktop\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\karolinka\Desktop\cmd.bat deleted successfully.
C:\Users\karolinka\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: karolinka
->Temp folder emptied: 32490 bytes
->Temporary Internet Files folder emptied: 37294 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 5670002 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 66016 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 6.00 mb
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: karolinka
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 01162012_122943
Files\Folders moved on Reboot...
C:\Users\karolinka\AppData\Local\Temp\ehmsas.txt moved successfully.
Registry entries deleted on Reboot...
==
OTLCustom Scan:
OTL logfile created on: 16/01/2012 12:36:38 PM - Run 5
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\karolinka\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
1.99 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 49.61% Memory free
4.21 Gb Paging File | 3.11 Gb Available in Paging File | 73.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 225.59 Gb Total Space | 120.84 Gb Free Space | 53.57% Space Free | Partition Type: NTFS
Drive D: | 7.29 Gb Total Space | 0.74 Gb Free Space | 10.22% Space Free | Partition Type: NTFS
Computer Name: KAROLINKA-PC | User Name: karolinka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/09 12:17:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\karolinka\Desktop\OTL.exe
PRC - [2012/01/03 05:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/12/20 23:24:51 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/12/12 23:20:56 | 003,305,760 | ---- | M] (Akamai Technologies, Inc) -- C:\Users\karolinka\AppData\Local\Akamai\netsession_win.exe
PRC - [2011/10/13 22:01:50 | 000,994,360 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe
PRC - [2011/10/13 22:01:48 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe
PRC - [2011/10/13 22:01:46 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psi_tray.exe
PRC - [2011/08/11 15:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2010/09/30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2009/10/19 22:54:01 | 000,638,976 | ---- | M] (FinePrint Software, LLC) -- C:\WINDOWS\System32\spool\drivers\w32x86\3\fpdisp6.exe
PRC - [2009/04/10 22:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/07/11 16:51:32 | 000,423,200 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
PRC - [2008/05/21 17:26:10 | 000,451,896 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Pure Networks\Network Magic\nmapp.exe
PRC - [2008/05/16 06:11:44 | 000,648,504 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
PRC - [2007/04/23 17:11:42 | 000,262,243 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
PRC - [2007/03/12 10:54:24 | 000,050,696 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
PRC - [2007/02/12 06:38:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/02/12 06:37:58 | 000,174,872 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/02/07 06:30:00 | 000,065,536 | R--- | M] (Cognizance Corporation) -- c:\Program Files\Bioscrypt\VeriSoft\Bin\asghost.exe
PRC - [2006/12/20 12:27:40 | 000,719,664 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2006/12/20 12:27:38 | 001,600,304 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
========== Modules (No Company Name) ==========
MOD - [2011/12/20 23:24:51 | 002,124,760 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/11/01 23:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/01 23:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/10/15 02:34:18 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll
MOD - [2011/10/15 02:33:58 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll
MOD - [2011/10/15 02:31:59 | 007,950,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll
MOD - [2011/10/15 02:31:31 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2009/08/16 16:06:02 | 000,141,312 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/04/23 17:11:44 | 000,339,968 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
MOD - [2007/04/23 17:11:34 | 000,237,673 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
MOD - [2007/04/23 17:11:34 | 000,114,787 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
MOD - [2007/04/23 17:11:34 | 000,032,768 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
MOD - [2007/04/23 17:10:44 | 000,061,440 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2007/03/30 03:04:48 | 000,249,856 | ---- | M] () -- C:\WINDOWS\System32\igfxTMM.dll
MOD - [2006/12/20 12:18:56 | 000,126,976 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
MOD - [2006/12/20 12:00:12 | 000,389,120 | ---- | M] () -- C:\WINDOWS\System32\btwhidcs.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (stllssvr)
SRV - [2012/01/03 05:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/12/14 22:15:19 | 003,316,000 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_b427739.dll -- (Akamai)
SRV - [2011/10/13 22:01:50 | 000,994,360 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011/10/13 22:01:48 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011/08/11 15:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2010/09/30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0)
SRV - [2009/10/19 22:54:01 | 000,638,976 | ---- | M] (FinePrint Software, LLC) [Auto | Running] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe -- (FinePrint Dispatcher v6)
SRV - [2008/05/21 17:25:30 | 000,012,800 | ---- | M] (Pure Networks, Inc.) [On_Demand | Stopped] -- C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe -- (nmraapache)
SRV - [2008/05/16 06:11:44 | 000,648,504 | ---- | M] (Pure Networks, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2007/04/23 17:11:44 | 000,106,593 | ---- | M] () [Auto | Stopped] -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe -- (CLSched) CyberLink Task Scheduler (CTS)
SRV - [2007/04/23 17:11:42 | 000,262,243 | ---- | M] () [Auto | Running] -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) CyberLink Background Capture Service (CBCS)
SRV - [2007/02/12 06:38:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2007/02/07 06:30:00 | 000,074,240 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll -- (ASBroker)
SRV - [2006/06/21 23:14:00 | 000,131,584 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\Bioscrypt\VeriSoft\Bin\ASChnl.dll -- (ASChannel)
========== Driver Services (SafeList) ==========
DRV - [2011/07/22 08:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 13:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/09/01 00:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\psi_mf.sys -- (PSI)
DRV - [2010/07/21 16:52:14 | 000,044,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2009/10/11 18:29:35 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/09/01 14:29:50 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\kl1.sys -- (kl1)
DRV - [2008/11/17 14:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel®
DRV - [2008/05/16 06:10:32 | 000,024,888 | ---- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\pnarp.sys -- (pnarp)
DRV - [2008/05/16 06:10:30 | 000,026,424 | ---- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\purendis.sys -- (purendis)
DRV - [2007/03/28 08:44:22 | 000,140,424 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\atswpdrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2007/03/05 13:28:00 | 000,076,288 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007/03/01 04:49:58 | 002,216,448 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel®
DRV - [2007/02/24 06:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/23 09:03:28 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/01/23 08:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/30 09:24:58 | 000,008,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\eabfiltr.sys -- (eabfiltr)
DRV - [2006/11/01 23:41:49 | 001,010,560 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\smserial.sys -- (smserial)
DRV - [2006/06/28 08:54:00 | 000,009,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\CPQBttn.sys -- (HBtnKey)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: calendar-timezones@mozilla.org:0.1.2008d
FF - prefs.js..extensions.enabledItems: default-palette@celtx.com:1.0
FF - prefs.js..extensions.enabledItems: emoticons-msn-smileys@m513901.de:0.1
FF - prefs.js..extensions.enabledItems: inspector@mozilla.org:2.0.0
FF - prefs.js..extensions.enabledItems: messagestyle-blackened@addons.instantbird.org:0.9
FF - prefs.js..extensions.enabledItems: messagestyle-depth@addons.instantbird.org:1.1
FF - prefs.js..extensions.enabledItems: messagestyle-minimal20@addons.instantbird.org:1.5
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/07 20:38:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/16 11:20:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{96196123-4458-4274-9392-31555CDE029E}: C:\Users\karolinka\AppData\Local\{96196123-4458-4274-9392-31555CDE029E}\ [2011/06/07 18:03:12 | 000,000,000 | ---D | M]
[2011/01/17 10:32:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\karolinka\AppData\Roaming\Mozilla\Extensions
[2011/01/17 10:32:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\karolinka\AppData\Roaming\Mozilla\Extensions\celtx@celtx.com
[2012/01/09 11:59:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\karolinka\AppData\Roaming\Mozilla\Firefox\Profiles\l5gvipr0.default\extensions
[2009/09/02 07:21:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\karolinka\AppData\Roaming\Mozilla\Firefox\Profiles\l5gvipr0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/06 19:09:11 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\karolinka\AppData\Roaming\Mozilla\Firefox\Profiles\l5gvipr0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012/01/07 20:45:02 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\karolinka\AppData\Roaming\Mozilla\Firefox\Profiles\l5gvipr0.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2010/06/15 20:29:07 | 000,000,000 | ---D | M] (RadioBar Toolbar) -- C:\Users\karolinka\AppData\Roaming\Mozilla\Firefox\Profiles\l5gvipr0.default\extensions\radiobar@toolbar
[2012/01/07 20:38:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/01/17 10:29:52 | 000,000,000 | ---D | M] (Timezone Definitions for Mozilla Calendar) -- C:\PROGRAM FILES\CELTX\EXTENSIONS\CALENDAR-TIMEZONES@MOZILLA.ORG
[2011/01/17 10:29:51 | 000,000,000 | ---D | M] (Default Shot Palette) -- C:\PROGRAM FILES\CELTX\EXTENSIONS\DEFAULT-PALETTE@CELTX.COM
[2011/01/17 10:29:51 | 000,000,000 | ---D | M] (MSN-Smileys) -- C:\PROGRAM FILES\CELTX\EXTENSIONS\EMOTICONS-MSN-SMILEYS@M513901.DE
[2011/01/17 10:29:49 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\PROGRAM FILES\CELTX\EXTENSIONS\INSPECTOR@MOZILLA.ORG
[2011/01/17 10:29:49 | 000,000,000 | ---D | M] (Blackened) -- C:\PROGRAM FILES\CELTX\EXTENSIONS\MESSAGESTYLE-BLACKENED@ADDONS.INSTANTBIRD.ORG
[2011/01/17 10:29:48 | 000,000,000 | ---D | M] (Depth) -- C:\PROGRAM FILES\CELTX\EXTENSIONS\MESSAGESTYLE-DEPTH@ADDONS.INSTANTBIRD.ORG
[2011/01/17 10:29:48 | 000,000,000 | ---D | M] (Minimal) -- C:\PROGRAM FILES\CELTX\EXTENSIONS\MESSAGESTYLE-MINIMAL20@ADDONS.INSTANTBIRD.ORG
[2011/12/20 23:24:52 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/12/20 20:30:41 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/20 20:30:41 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/01/16 12:29:49 | 000,000,098 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (VeriSoft Access Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CognizanceTS] c:\Program Files\Bioscrypt\VeriSoft\Bin\ASTSVCC.dll (Cognizance Corporation)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File not found
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Pure Networks, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\karolinka\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [googletalk] C:\Users\karolinka\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.2.0)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.59.160.13 64.59.160.15 64.59.161.68
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4246B7FF-D8FF-47BD-8DE9-0D5CE6915CBB}: DhcpNameServer = 64.59.160.13 64.59.160.15 64.59.161.68
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\WINDOWS\System32\APSHook.dll) -C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\karolinka\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\karolinka\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/11 07:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2012/01/16 10:28:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/01/15 11:20:00 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/01/15 11:19:33 | 002,322,184 | ---- | C] (ESET) -- C:\Users\karolinka\Desktop\esetsmartinstaller_enu.exe
[2012/01/14 01:47:04 | 004,713,472 | ---- | C] (AVAST Software) -- C:\Users\karolinka\Desktop\aswMBR.exe
[2012/01/14 00:53:43 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012/01/13 00:03:09 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/01/12 23:27:21 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/01/11 23:12:12 | 000,000,000 | ---D | C] -- C:\Users\karolinka\Desktop\FOLDER
[2012/01/11 10:43:25 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/01/11 10:43:25 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/01/11 10:43:25 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/01/11 07:59:11 | 000,718,104 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Users\karolinka\Desktop\avgremover.exe
[2012/01/11 07:53:04 | 000,000,000 | ---D | C] -- C:\Users\karolinka\AppData\Local\Adobe
[2012/01/10 10:45:30 | 008,821,856 | ---- | C] (OPSWAT, Inc.) -- C:\Users\karolinka\Desktop\AppRemover.exe
[2012/01/10 10:09:48 | 001,692,968 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Users\karolinka\Desktop\avg_remover_stf_x86_2012_1796.exe
[2012/01/10 10:00:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/10 09:14:27 | 004,383,253 | R--- | C] (Swearware) -- C:\Users\karolinka\Desktop\ComboFix.exe
[2012/01/09 12:17:06 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\karolinka\Desktop\OTL.exe
[2012/01/09 12:01:00 | 001,972,528 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\karolinka\Desktop\tdsskiller.exe
[2012/01/07 02:05:08 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\karolinka\Desktop\dds.scr
[2012/01/07 01:31:02 | 000,000,000 | R--D | C] -- C:\Users\karolinka\Documents
[2012/01/06 22:51:52 | 000,000,000 | ---D | C] -- C:\Users\karolinka\Desktop\New Folder
[2012/01/06 19:35:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/01/06 19:14:37 | 013,913,696 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\karolinka\Desktop\SUPERAntiSpyware.exe
[2012/01/06 16:37:30 | 000,000,000 | ---D | C] -- C:\Users\karolinka\AppData\Roaming\Tific
[2012/01/06 16:37:30 | 000,000,000 | ---D | C] -- C:\Users\karolinka\AppData\Local\tific
[2012/01/06 12:08:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/06 12:05:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/01/06 12:05:26 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/01/06 11:58:13 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2012/01/06 11:51:38 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/01/06 02:27:58 | 001,754,456 | ---- | C] (Secunia) -- C:\Users\karolinka\Desktop\PSISetup.exe
[2012/01/06 02:26:50 | 000,000,000 | ---D | C] -- C:\Users\karolinka\AppData\Local\Secunia PSI
[2012/01/06 02:26:35 | 000,000,000 | ---D | C] -- C:\Program Files\Secunia
[1 C:\Users\karolinka\Desktop\FOLDER\Documents\Documents\*.tmp files -> C:\Users\karolinka\Desktop\FOLDER\Documents\Documents\*.tmp -> ]
[1 C:\Users\karolinka\Desktop\*.tmp files -> C:\Users\karolinka\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/16 12:35:02 | 000,000,149 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2012/01/16 12:32:44 | 000,000,126 | ---- | M] () -- C:\Windows\System32\FpLicense6.ini
[2012/01/16 12:32:17 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 12:32:17 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 12:32:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/16 12:32:05 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/16 12:30:48 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/01/16 12:29:49 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2012/01/16 12:12:34 | 000,000,134 | ---- | M] () -- C:\Users\karolinka\Desktop\Internet Explorer Troubleshooting.url
[2012/01/16 11:20:24 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/01/16 11:15:18 | 000,609,196 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/01/16 11:15:18 | 000,108,672 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/01/15 16:07:25 | 000,879,683 | ---- | M] () -- C:\Users\karolinka\Desktop\SecurityCheck.exe
[2012/01/15 15:23:01 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6ED3C11A-7FAA-4F5A-A57C-FE5C34FB4763}.job
[2012/01/15 14:52:04 | 000,000,820 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012/01/15 11:19:37 | 002,322,184 | ---- | M] (ESET) -- C:\Users\karolinka\Desktop\esetsmartinstaller_enu.exe
[2012/01/14 11:08:04 | 001,972,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\karolinka\Desktop\tdsskiller.exe
[2012/01/14 02:11:59 | 000,000,512 | ---- | M] () -- C:\Users\karolinka\Desktop\MBR.dat
[2012/01/14 01:47:20 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\karolinka\Desktop\aswMBR.exe
[2012/01/14 00:52:27 | 004,383,253 | R--- | M] (Swearware) -- C:\Users\karolinka\Desktop\ComboFix.exe
[2012/01/14 00:30:59 | 373,070,884 | ---- | M] () -- C:\registrybackup.reg
[2012/01/13 05:59:18 | 372,312,857 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/01/11 07:59:51 | 000,718,104 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Users\karolinka\Desktop\avgremover.exe
[2012/01/10 10:46:02 | 008,821,856 | ---- | M] (OPSWAT, Inc.) -- C:\Users\karolinka\Desktop\AppRemover.exe
[2012/01/09 20:00:00 | 000,000,554 | ---- | M] () -- C:\Windows\tasks\Norton Internet Security - Run Full System Scan - karolinka.job
[2012/01/09 12:17:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\karolinka\Desktop\OTL.exe
[2012/01/07 20:38:16 | 000,000,870 | ---- | M] () -- C:\Users\karolinka\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/07 20:38:16 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/07 02:05:13 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\karolinka\Desktop\dds.scr
[2012/01/07 02:01:58 | 000,050,477 | ---- | M] () -- C:\Users\karolinka\Desktop\Defogger.exe
[2012/01/06 19:35:51 | 000,001,800 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/06 19:15:49 | 000,294,216 | ---- | M] () -- C:\Users\karolinka\Desktop\gmer.zip
[2012/01/06 19:15:04 | 013,913,696 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\karolinka\Desktop\SUPERAntiSpyware.exe
[2012/01/06 19:13:11 | 000,396,071 | ---- | M] () -- C:\Users\karolinka\Desktop\MiniToolBox.exe
[2012/01/06 12:08:56 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/06 02:29:13 | 000,000,899 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/01/06 02:25:21 | 000,005,648 | ---- | M] () -- C:\Users\karolinka\AppData\Local\d3d9caps.dat
[2012/01/06 02:08:30 | 001,754,456 | ---- | M] (Secunia) -- C:\Users\karolinka\Desktop\PSISetup.exe
[2011/12/20 12:45:27 | 000,073,728 | ---- | M] () -- C:\Users\karolinka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[1 C:\Users\karolinka\Desktop\FOLDER\Documents\Documents\*.tmp files -> C:\Users\karolinka\Desktop\FOLDER\Documents\Documents\*.tmp -> ]
[1 C:\Users\karolinka\Desktop\*.tmp files -> C:\Users\karolinka\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/16 11:23:08 | 000,000,134 | ---- | C] () -- C:\Users\karolinka\Desktop\Internet Explorer Troubleshooting.url
[2012/01/16 11:20:23 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/01/16 11:20:23 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/16 11:07:53 | 2137,448,448 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/14 02:11:59 | 000,000,512 | ---- | C] () -- C:\Users\karolinka\Desktop\MBR.dat
[2012/01/14 00:24:42 | 373,070,884 | ---- | C] () -- C:\registrybackup.reg
[2012/01/11 10:43:25 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/01/11 10:43:25 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/01/11 10:43:25 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/01/11 10:43:25 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/01/11 10:43:25 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/01/11 08:26:41 | 372,312,857 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/01/07 20:38:16 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/07 20:38:15 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/01/07 02:01:55 | 000,050,477 | ---- | C] () -- C:\Users\karolinka\Desktop\Defogger.exe
[2012/01/06 22:29:30 | 000,302,592 | ---- | C] () -- C:\Users\karolinka\Desktop\gmer.exe
[2012/01/06 19:35:51 | 000,001,800 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/06 19:15:48 | 000,294,216 | ---- | C] () -- C:\Users\karolinka\Desktop\gmer.zip
[2012/01/06 19:13:05 | 000,396,071 | ---- | C] () -- C:\Users\karolinka\Desktop\MiniToolBox.exe
[2012/01/06 19:11:31 | 000,879,683 | ---- | C] () -- C:\Users\karolinka\Desktop\SecurityCheck.exe
[2012/01/06 12:08:56 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/06 02:29:13 | 000,000,899 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/01/06 02:29:13 | 000,000,862 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2011/07/15 20:06:41 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011/04/18 14:43:17 | 000,000,552 | ---- | C] () -- C:\Users\karolinka\AppData\Local\d3d8caps.dat
[2009/10/24 12:37:49 | 000,000,126 | ---- | C] () -- C:\Windows\System32\FpLicense6.ini
[2009/10/24 12:37:29 | 000,040,960 | ---- | C] () -- C:\Windows\System32\fpent6a.dll
[2009/09/23 21:02:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/23 21:02:42 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/04 18:27:44 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2009/09/04 18:27:44 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2009/09/04 18:11:56 | 000,000,000 | RHS- | C] () -- C:\Windows\FFSSET.BIN
[2009/09/04 18:00:02 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf08b.dat
[2009/09/04 17:58:00 | 000,106,496 | ---- | C] () -- C:\Windows\System32\BrMuSNMP.dll
[2009/09/04 17:54:40 | 000,031,567 | ---- | C] () -- C:\Windows\maxlink.ini
[2009/08/03 14:40:59 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/06/22 11:58:33 | 000,005,648 | ---- | C] () -- C:\Users\karolinka\AppData\Local\d3d9caps.dat
[2009/02/23 19:18:34 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/02/13 19:53:10 | 000,073,728 | ---- | C] () -- C:\Users\karolinka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/10 18:39:42 | 000,000,132 | ---- | C] () -- C:\Users\karolinka\AppData\Roaming\wklnhst.dat
[2009/02/03 21:03:49 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/02/02 18:21:27 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2007/05/18 07:12:16 | 000,000,176 | ---- | C] () -- C:\Windows\System32\drivers\RTHDAEQ1.dat
[2007/05/18 07:12:16 | 000,000,176 | ---- | C] () -- C:\Windows\System32\drivers\RTHDAEQ0.dat
[2007/05/18 06:56:47 | 000,103,437 | ---- | C] () -- C:\Windows\hpqins13.dat
[2007/05/18 01:09:11 | 000,910,304 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2007/05/18 01:09:11 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2007/05/18 01:09:11 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1244.dll
[2007/02/27 12:43:02 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2006/12/20 12:00:12 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006/12/13 22:01:36 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/12/13 22:01:36 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/11/02 04:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 04:47:37 | 002,238,816 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 04:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:33:01 | 000,609,196 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 02:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 02:33:01 | 000,108,672 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 02:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 02:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 00:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 00:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/01 23:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/01 23:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/03/09 16:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/05/07 04:06:00 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2005/04/03 12:30:00 | 000,110,592 | R--- | C] () -- C:\Windows\System32\scardsyn.dll
[2001/11/14 12:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
[1998/05/06 17:10:00 | 000,069,632 | R--- | C] () -- C:\Windows\System32\ODMA32.dll
========== LOP Check ==========
[2011/01/17 10:32:05 | 000,000,000 | ---D | M] -- C:\Users\karolinka\AppData\Roaming\Greyfirst
[2009/09/04 18:57:30 | 000,000,000 | ---D | M] -- C:\Users\karolinka\AppData\Roaming\ScanSoft
[2009/09/02 09:17:59 | 000,000,000 | ---D | M] -- C:\Users\karolinka\AppData\Roaming\SystemRequirementsLab
[2009/02/10 18:39:48 | 000,000,000 | ---D | M] -- C:\Users\karolinka\AppData\Roaming\Template
[2012/01/06 16:37:31 | 000,000,000 | ---D | M] -- C:\Users\karolinka\AppData\Roaming\Tific
[2011/03/20 11:51:07 | 000,000,000 | ---D | M] -- C:\Users\karolinka\AppData\Roaming\uTorrent
[2012/01/16 12:30:48 | 000,032,756 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/01/15 15:23:01 | 000,000,426 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{6ED3C11A-7FAA-4F5A-A57C-FE5C34FB4763}.job
========== Purity Check ==========
========== Custom Scans ==========
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/12/20 23:24:52 | 000,715,216 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/12/20 23:24:52 | 000,715,216 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/12/20 23:24:52 | 000,715,216 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/12/20 23:24:51 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/12/20 23:24:51 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/12/20 23:24:51 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\system32\ie4uinit.exe" -hide [2011/11/02 20:45:23 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\system32\ie4uinit.exe" -show [2011/11/02 20:45:23 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\system32\ie4uinit.exe" -reinstall [2011/11/02 20:45:23 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/11/02 22:23:19 | 000,638,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: iexplore.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2009/11/05 21:14:44 | 001,794,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2009/11/05 21:14:44 | 001,794,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2009/11/05 21:14:44 | 001,794,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2009/11/05 21:14:44 | 001,794,848 | ---- | M] (Apple Inc.)
< %USERPROFILE%\AppData\Local\Google\Chrome\User Data\*.* /s >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-12 06:38:46
< End of report >
==
pumex