PDA

View Full Version : ilivid Toolbar



candy123
2014-05-12, 12:43
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by Roger at 13:15:19 on 2014-05-12
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1015.290 [GMT 3:00]
.
AV: Kaspersky PURE 3.0 *Enabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky PURE 3.0 *Enabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\CyberLink\YouCam\YouCamService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\klwtblfs.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HPZ12
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer, optimized for Bing and MSN
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
dURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - <orphaned>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky pure 3.0\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky pure 3.0\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky pure 3.0\ieext\onlinebanking\online_banking_bho.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\microsoft\bingbar\7.3.132.0\BingExt.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky pure 3.0\ieext\urladvisor\klwtbbho.dll
BHO: {f34c9277-6577-4dff-b2d7-7d58092f272f} - <orphaned>
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\microsoft\bingbar\7.3.132.0\BingExt.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [SpybotDeletingF5423] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\windows\SchedLgU.Txt"
mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRun: [YouCam Service] "c:\program files\cyberlink\youcam\YouCamService.exe" /s
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Driver Genius] <no file>
mRunOnce: [SpybotDeletingE9413] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\windows\SchedLgU.Txt"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky pure 3.0\ie_banner_deny.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky pure 3.0\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky pure 3.0\ieext\urladvisor\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1369313642218
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
TCP: NameServer = 192.168.10.254
TCP: Interfaces\{8DEA69D0-8FCC-4C91-8431-1493E397A41D} : DHCPNameServer = 192.168.10.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: igfxcui - igfxdev.dll
Notify: klogon - c:\windows\system32\klogon.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\roger\application data\mozilla\firefox\profiles\2ayiv71i.default-1398444096234\
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\astrology_4aei\installr\1.bin\NP4aEISb.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.24.7\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1202122.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1210150.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_13_0_0_206.dll
.
============= SERVICES / DRIVERS ===============
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\drivers\CSCrySec.sys [2012-2-10 88632]
R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2013-11-11 135776]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\drivers\CSVirtualDiskDrv.sys [2012-2-10 39736]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2012-2-10 593504]
R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2013-11-11 44000]
R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2013-11-11 145040]
R1 RapportCerberus_59849;RapportCerberus_59849;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\baseline\RapportCerberus32_59849.sys [2013-10-28 340432]
R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2014-4-14 156024]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2014-4-14 228888]
R2 avp;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky pure 3.0\avp.exe -r --> c:\program files\kaspersky lab\kaspersky pure 3.0\avp.exe -r [?]
R2 CSObjectsSrv;CryptoStorage control service;c:\program files\common files\infowatch\cryptostorage\ProtectedObjectsSrv.exe [2013-9-25 818888]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2014-4-14 1444120]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2013-5-20 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2013-5-20 1369624]
R3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.3.132.0\SeaPort.EXE [2014-3-11 247968]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\drivers\clwvd.sys [2012-2-9 27760]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 35672]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2013-11-11 24160]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 24672]
S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.3.132.0\BBSvc.EXE [2014-3-11 193696]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2013-5-20 168384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-2-28 161384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2012-2-9 1691480]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2012-2-9 23456]
S3 esgiguard;esgiguard;\??\c:\program files\enigma software group\spyhunter\esgiguard.sys --> c:\program files\enigma software group\spyhunter\esgiguard.sys [?]
S3 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2014-4-14 107256]
S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8192cu.sys --> c:\windows\system32\drivers\RTL8192cu.sys [?]
.
=============== Created Last 30 ================
.
2014-05-11 11:55:43 -------- d-----w- c:\program files\Enigma Software Group
2014-05-11 11:55:06 -------- d-----w- c:\windows\455F074C814E4520B69B5584BD90400C.TMP
2014-05-11 11:54:12 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2014-04-13 21:01:06 107256 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
.
==================== Find3M ====================
.
2014-04-29 12:09:50 692400 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-04-29 12:09:49 70832 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-02 08:27:51 135776 ----a-w- c:\windows\system32\drivers\kl1.sys
2014-04-01 12:59:23 21817 ----a-w- c:\documents and settings\roger\vvicons.tmp
2014-03-06 17:59:23 920064 ----a-w- c:\windows\system32\wininet.dll
2014-03-06 17:59:22 43520 ----a-w- c:\windows\system32\licmgr10.dll
2014-03-06 17:59:22 18944 ----a-w- c:\windows\system32\corpol.dll
2014-03-06 17:59:22 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-06 00:46:54 385024 ----a-w- c:\windows\system32\html.iec
2014-02-26 01:59:05 13312 ------w- c:\windows\system32\xp_eos.exe
.
============= FINISH: 13:16:46.64 ===============

ken545
2014-05-12, 15:58
:snwelcome:

Enigma Software Group <-- See if you can uninstall this via Add Remove Programs in the Control Panel, the programs it provides are borderline at most


-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/)
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

Do not click on any links in the top Advertisment.




Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.








http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

candy123
2014-05-12, 17:07
Hi here is the log, thanks for your help.

# AdwCleaner v3.208 - Report created 12/05/2014 at 17:55:41
# Updated 11/05/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Roger - TROJAN
# Running from : C:\Documents and Settings\Roger\My Documents\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\IBUpdaterService
Folder Deleted : C:\Documents and Settings\All Users\Application Data\ParetoLogic
Folder Deleted : C:\Documents and Settings\All Users\Application Data\wincert
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\driver-soft
Folder Deleted : C:\Program Files\Smiley Bar for Facebook
Folder Deleted : C:\Program Files\VideoPerformer
Folder Deleted : C:\Documents and Settings\Roger\Local Settings\Application Data\eSupport.com
Folder Deleted : C:\Documents and Settings\Roger\Local Settings\Application Data\iac
Folder Deleted : C:\Documents and Settings\Roger\Local Settings\Application Data\torch
Folder Deleted : C:\Documents and Settings\Roger\Local Settings\Application Data\visi_coupon
Folder Deleted : C:\Documents and Settings\Roger\Application Data\DriverCure
Folder Deleted : C:\Documents and Settings\Roger\Application Data\file scout
Folder Deleted : C:\Documents and Settings\Roger\Application Data\ilividtoolbarguid
Folder Deleted : C:\Documents and Settings\Roger\Application Data\ParetoLogic
Folder Deleted : C:\Documents and Settings\Roger\Application Data\StatusWinks
Folder Deleted : C:\Documents and Settings\Roger\Start Menu\Programs\VideoPerformer

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{DFEFBE51-CA52-484B-ADF0-6B158B05262D}]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\*\shell\filescout
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Key Deleted : HKLM\SOFTWARE\Classes\Applications\Torch.exe
Key Deleted : HKLM\SOFTWARE\Classes\iLividIEHelper.DNSGuard
Key Deleted : HKLM\SOFTWARE\Classes\iLividIEHelper.DNSGuard.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform [FunWebProducts]
Key Deleted : HKCU\Software\e2d6d0e53def12
Key Deleted : HKLM\SOFTWARE\e2d6d0e53def12
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3253185
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AFB130D4-7DD2-41EB-A9AD-4C90414657F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DB507187-9746-458C-97DA-C458131EEDE7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1FDC0B61-91AC-4157-9B27-CAD9A09AB67E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{65F1815B-26A0-4AA8-A973-1598F6D646F6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{75E8DA27-44AF-40AE-927C-F2EEC99D65B1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0B84B4B4-8AF8-4F1F-91FE-074A666F6425}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{14D02517-C8BE-4735-A344-3C8366C77AA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{631ACB68-57C3-48AF-9CC5-FCEC0837FFD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8040829D-1177-46E2-9157-8282438B79C7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF94B35C-3AC5-4030-9F9C-15FB4E3DC339}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B1DF253A-9E7A-480D-B6A5-7A435B520DBB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D5E9B421-C309-41DE-9014-800A2ADCDEB0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0B84B4B4-8AF8-4F1F-91FE-074A666F6425}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{14D02517-C8BE-4735-A344-3C8366C77AA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{631ACB68-57C3-48AF-9CC5-FCEC0837FFD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8040829D-1177-46E2-9157-8282438B79C7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AF94B35C-3AC5-4030-9F9C-15FB4E3DC339}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B1DF253A-9E7A-480D-B6A5-7A435B520DBB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D5E9B421-C309-41DE-9014-800A2ADCDEB0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{F34C9277-6577-4DFF-B2D7-7D58092F272F}]
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\filescout
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\ilividtoolbarguid
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\performersoft llc
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\torch
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\ParetoLogic
Key Deleted : HKLM\Software\torch
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilividtoolbarguid
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v29.0.1 (en-US)

[ File : C:\Documents and Settings\Roger\Application Data\Mozilla\Firefox\Profiles\2ayiv71i.default-1398444096234\prefs.js ]


-\\ Google Chrome v

[ File : C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
Deleted [Startup_urls] : hxxp://www.searchnu.com/406

*************************

AdwCleaner[R0].txt - [8555 octets] - [12/05/2014 17:53:22]
AdwCleaner[S0].txt - [8502 octets] - [12/05/2014 17:55:41]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8562 octets] ##########

candy123
2014-05-12, 18:05
Hi here is Junk cleaner log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Microsoft Windows XP x86
Ran by Roger on 12/05/2014 at 18:32:53.01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\WINDOWS\Tasks\rmschedule.job



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\boost_interprocess"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\drivergenius"





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12/05/2014 at 18:47:15.10
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ken545
2014-05-12, 18:43
Hi Candi,

Thanks for the logs. There is no reason to quote what I post, it just uses up valuable space on the server


http://i.imgur.com/GUZVCQN.jpg Please download Malwarebytes Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.



Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
Once installed, Malwarebytes will ask if you want to Launch Now. Please select to do so and then Malwarebytes will open and update on its own. Please allow this to complete.
If an update is found, it will download and install the latest version.
Let's be sure to run a Hyper Scan. Press the Scan tab and then select Hyper Scan.
Press Scan Now then Skip Update (since we just updated it)

http://www.bleepstatic.com/fhost/uploads/2/mbam2.0.1.jpg



When the scan is complete, click View Detailed Log, then Export to save the log to your Desktop (name the log MBAM Scan).
Copy and Paste all of the information in that file to your next reply.

candy123
2014-05-13, 07:29
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 12/05/2014
Scan Time: 20:26:10
Logfile: MBAM Scan.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.05.12.06
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: Roger

Scan Type: Hyper Scan
Result: Completed
Objects Scanned: 211354
Time Elapsed: 6 min, 52 sec

Memory: Enabled
Startup: Enabled
Filesystem: Disabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 1
PUP.Optional.BProtector.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, , [563088c8e59666d0c94a7f315fa4966a],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 7
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\css, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\js, , [5a2c242c196267cfed918bed2fd346ba],

Files: 52
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\UrlFolderExtension.uf1, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\UrlFolderExtension.ufm, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\anemone-1.2.7.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\background.html, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\Date.getWeek.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\hidden-window.html, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\ie7-fix.html, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\jquery-1.7.2.min.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\jquery-dropdown.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\jquery-inputfieldrestrict.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\jquery-modal.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\jquery-ui.min.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\json2.min.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\manifest.json, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\SignedExtension.cab, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\underscore-1.3.1.min.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\widget-api-1.2.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\window.html, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\css\dropdown.css, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\css\modal.css, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\css\widget.css, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\favicon.ico, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\FBwidget_sprite.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icon.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icon.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\loading.gif, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F0.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F0.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F1.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F1.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F10.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F10.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F2.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F2.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F3.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F3.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F4.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F4.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F5.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F5.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F6.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F6.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F7.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F7.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F8.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F8.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F9.bmp, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\images\icons\F9.png, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\js\background.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\js\hiddenwindow.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\js\settings.js, , [5a2c242c196267cfed918bed2fd346ba],
PUP.Optional.MindSpark.A, C:\Documents and Settings\NetworkService\Application Data\FilmFanatic\91fbdd335935d6fab2f0f46ec3451b3a18a24a23\1.1.2\js\widgetwindow.js, , [5a2c242c196267cfed918bed2fd346ba],

Physical Sectors: 0
(No malicious items detected)


(end)

ken545
2014-05-13, 11:56
Morning Candi,

Run Malwarebytes again and this time run the Threat Scan.

When the scan has completed, you will now be presented with a screen showing you the malware infections that Malwarebytes’ Anti-Malware has detected. To remove the malicious programs that Malwarebytes Anti-malware has found, click on the “Quarantine All” button, and then click on the “Apply Now” button.

Then post the log please

candy123
2014-05-13, 16:55
Hi Ken hare's the log. Interesting I ran spybot this am, before doing this task, ilivid Toolbar was not present! Thanks.



Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 13/05/2014
Scan Time: 17:46:13
Logfile: Threat scan.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.05.13.07
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: Roger

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 250904
Time Elapsed: 1 hr, 6 min, 33 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 7
PUP.Optional.Datamngr.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}, Quarantined, [00eb3e12e992a393610f36f87b875fa1],
PUP.Optional.Datamngr.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}, Quarantined, [00eb3e12e992a393610f36f87b875fa1],
PUP.Optional.Datamngr.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{F34C9277-6577-4DFF-B2D7-7D58092F272F}, Quarantined, [7c6f75dba9d248ee3140e14df1116b95],
PUP.Optional.Datamngr.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{F34C9277-6577-4DFF-B2D7-7D58092F272F}, Quarantined, [7c6f75dba9d248ee3140e14df1116b95],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{0B84B4B4-8AF8-4F1F-91FE-074A666F6425}, Quarantined, [b932c8880279c472d74441e316ec718f],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{631ACB68-57C3-48AF-9CC5-FCEC0837FFD3}, Quarantined, [7f6c93bdb6c546f0da3d2400768cee12],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D5E9B421-C309-41DE-9014-800A2ADCDEB0}, Quarantined, [618aada34437c07671a850d428daa759],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

ken545
2014-05-13, 17:25
Good

Run another Threat Scan with Malwarebytes and lets make sure there all gone

Then lets check for leftovers


OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

candy123
2014-05-14, 12:36
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.bbcnews.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: url_advisor%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: content_blocker%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: anti_banner%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: online_banking%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@ei.Astrology_4a.com/Plugin: C:\Program Files\Astrology_4aEI\Installr\1.bin\NP4aEISB.dll (Astrology.com)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/07 09:25:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\url_advisor@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\url_advisor@kaspersky.com [2014/04/02 11:28:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\virtual_keyboard@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\virtual_keyboard@kaspersky.com [2014/04/02 11:28:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\content_blocker@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\content_blocker@kaspersky.com [2014/04/02 11:28:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\anti_banner@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\anti_banner@kaspersky.com [2014/04/02 11:28:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\online_banking@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\online_banking@kaspersky.com [2014/04/02 11:28:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/05/10 11:16:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2013/01/08 17:40:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Roger\Application Data\Mozilla\Extensions
[2014/04/25 20:06:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Roger\Application Data\Mozilla\Firefox\Profiles\2ayiv71i.default-1398444096234\extensions
[2014/05/10 11:16:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/05/10 11:16:24 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/04/02 11:28:27 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\ANTI_BANNER@KASPERSKY.COM
[2014/04/02 11:28:27 | 000,000,000 | ---D | M] (Content Blocker) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\CONTENT_BLOCKER@KASPERSKY.COM
[2014/04/02 11:28:28 | 000,000,000 | ---D | M] (Safe Money) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\ONLINE_BANKING@KASPERSKY.COM
[2014/04/02 11:28:29 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\URL_ADVISOR@KASPERSKY.COM
[2013/10/18 11:27:07 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.msn.com/?pc=UP94&ocid=UP94DHP
CHR - plugin: Error reading preferences file
CHR - Extension: Kaspersky URL Advisor = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0\
CHR - Extension: Safe Money = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_1\
CHR - Extension: Content Blocker = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.2.614_0\
CHR - Extension: Virtual Keyboard = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.2.614_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Google Wallet = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Anti-Banner = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0\

O1 HOSTS File: ([2014/05/13 18:53:31 | 000,450,543 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15468 more lines...
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [YouCam Service] C:\Program Files\CyberLink\YouCam\YouCamService.exe (CyberLink Corp.)
O4 - Startup: C:\Documents and Settings\Roger\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1369313642218 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8DEA69D0-8FCC-4C91-8431-1493E397A41D}: DhcpNameServer = 192.168.10.254
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/02/09 12:54:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2014/05/14 13:07:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Roger\Desktop\OTL.exe
[2014/05/14 12:30:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2014/05/13 19:24:38 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\66764599.sys
[2014/05/13 18:34:54 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\14604B0C.sys
[2014/05/12 20:17:56 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014/05/12 20:16:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/05/12 20:16:31 | 000,050,648 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014/05/12 20:16:31 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2014/05/12 20:16:31 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014/05/12 18:30:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2014/05/12 17:54:06 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\WINDOWS\System32\sqlite3.dll
[2014/05/12 17:53:13 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/05/12 13:30:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2014/05/12 13:29:01 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2014/05/12 13:29:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2014/05/11 14:55:43 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014/05/11 14:54:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2014/05/11 14:51:46 | 000,728,960 | ---- | C] (Enigma Software Group USA, LLC.) -- C:\Documents and Settings\Roger\My Documents\SpyHunter-Installer.exe
[2014/05/10 13:19:51 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Roger\Recent
[2014/05/10 11:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014/04/27 11:44:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2014/04/25 19:41:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Roger\Desktop\Old Firefox Data
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Roger\*.tmp files -> C:\Documents and Settings\Roger\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014/05/14 13:11:02 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/05/14 13:10:03 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/05/14 13:09:38 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2014/05/14 13:09:38 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2014/05/14 13:07:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Roger\Desktop\OTL.exe
[2014/05/14 12:12:00 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014/05/14 07:37:44 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/05/14 07:37:36 | 000,000,222 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014/05/14 07:37:34 | 000,000,620 | ---- | M] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2014/05/14 07:37:34 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2000478354-1715567821-839522115-1004.job
[2014/05/14 07:36:49 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RMAutoUpdate.job
[2014/05/14 07:35:58 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/05/14 07:35:53 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/05/13 19:31:54 | 000,009,467 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2014/05/13 19:24:38 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\66764599.sys
[2014/05/13 18:53:31 | 000,450,543 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2014/05/13 18:34:55 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\14604B0C.sys
[2014/05/13 14:48:37 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F3D1F9B5-E016-47FB-8DD6-B47FAD44F026}.job
[2014/05/12 20:16:35 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/05/12 19:24:00 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2000478354-1715567821-839522115-1004.job
[2014/05/12 13:29:11 | 000,000,776 | ---- | M] () -- C:\Documents and Settings\Roger\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2014/05/12 13:29:02 | 000,000,620 | ---- | M] () -- C:\Documents and Settings\Roger\Desktop\NTREGOPT.lnk
[2014/05/12 13:29:02 | 000,000,601 | ---- | M] () -- C:\Documents and Settings\Roger\Desktop\ERUNT.lnk
[2014/05/11 21:46:01 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2014/05/11 14:51:56 | 000,728,960 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Documents and Settings\Roger\My Documents\SpyHunter-Installer.exe
[2014/05/11 11:17:58 | 000,268,600 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/05/09 10:44:30 | 000,000,216 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014/05/08 11:49:08 | 003,694,691 | ---- | M] () -- C:\Documents and Settings\Roger\My Documents\765210.zip
[2014/04/30 22:56:33 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2014/04/30 11:13:01 | 006,022,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2014/04/30 00:32:29 | 000,000,616 | ---- | M] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2014/04/29 23:45:15 | 000,000,000 | ---- | M] () -- C:\cookies.sqlite
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Roger\*.tmp files -> C:\Documents and Settings\Roger\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014/05/12 20:16:35 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/05/12 13:29:11 | 000,000,776 | ---- | C] () -- C:\Documents and Settings\Roger\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2014/05/12 13:29:02 | 000,000,620 | ---- | C] () -- C:\Documents and Settings\Roger\Desktop\NTREGOPT.lnk
[2014/05/12 13:29:02 | 000,000,601 | ---- | C] () -- C:\Documents and Settings\Roger\Desktop\ERUNT.lnk
[2014/05/11 11:17:58 | 000,268,600 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/05/08 11:47:55 | 003,694,691 | ---- | C] () -- C:\Documents and Settings\Roger\My Documents\765210.zip
[2014/04/29 23:45:15 | 000,000,000 | ---- | C] () -- C:\cookies.sqlite
[2013/02/02 13:20:38 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Roger\Local Settings\Application Data\WebpageIcons.db
[2012/03/01 11:34:00 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\Roger\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2013/10/17 11:02:11 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 06:42:06 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 15:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 06:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/02 13:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\6F638BC8005648376B1EAE987B07D329
[2012/02/09 15:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2012/02/09 16:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\install_clap
[2012/11/25 16:12:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2013/04/15 19:17:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2012/02/11 16:24:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2012/11/10 04:03:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\ilividtoolbarguid
[2012/02/12 17:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Ashampoo
[2012/11/13 17:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\FreeFixer
[2013/07/09 20:05:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Imperium Romanum
[2014/04/02 14:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Naturalsoft
[2013/10/18 13:23:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Oracle
[2012/11/25 16:07:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\PC Utility Kit

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2012/11/25 15:04:06 | 000,000,251 | ---- | M] ()(C:\Documents and Settings\Roger\Desktop\ASHANTI F??G??? 1961-1988.url) -- C:\Documents and Settings\Roger\Desktop\ASHANTI ΦΡΕΓΆΤΑ 1961-1988.url
[2012/11/25 15:04:06 | 000,000,251 | ---- | C] ()(C:\Documents and Settings\Roger\Desktop\ASHANTI F??G??? 1961-1988.url) -- C:\Documents and Settings\Roger\Desktop\ASHANTI ΦΡΕΓΆΤΑ 1961-1988.url

========== Alternate Data Streams ==========

@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1
@Alternate Data Stream - 440 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:D1B5B4F1

< End of report >

candy123
2014-05-14, 12:41
Hi thanks again, have run Malware and no problems found.




OTL Extras logfile created on: 14/05/2014 13:09:26 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Roger\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1015.23 Mb Total Physical Memory | 285.23 Mb Available Physical Memory | 28.10% Memory free
3.39 Gb Paging File | 2.40 Gb Available in Paging File | 70.69% Paging File free
Paging file location(s): C:\pagefile.sys 2560 2560 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 214.71 Gb Free Space | 92.20% Space Free | Partition Type: NTFS

Computer Name: TROJAN | User Name: Roger | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htafile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Documents and Settings\Roger\Application Data\File Scout\filescout.exe" /open "%1"
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1542:TCP" = 1542:TCP:*:Enabled:Realtek WPS TCP Prot
"1542:UDP" = 1542:UDP:*:Enabled:Realtek WPS UDP Prot
"53:UDP" = 53:UDP:*:Enabled:Realtek AP UDP Prot

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe" = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Documents and Settings\Roger\Local Settings\Temp\7zS046E\HPDiagnosticCoreUI.exe" = C:\Documents and Settings\Roger\Local Settings\Temp\7zS046E\HPDiagnosticCoreUI.exe:*:Enabled:HPSAPS


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 5
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{262EFBD9-A907-490F-81F4-561FDD3A8C5C}" = NaturalReaderFree
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3365E735-48A6-4194-9988-CE59AC5AE503}" = Bing Bar
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{528145C0-462A-11E1-B8B4-B8AC6F97B88E}" = Google Earth
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9BF745FA-1118-44D2-9362-179DA4B27AC6}" = Webcam 2200
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.9)
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7FB6B99-C93C-4818-825B-37EF4B64C80C}" = PS_AIO_02_Software
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C14337B6-7777-4643-A0B0-B054EF10F59D}" = c5200_Help
"{C68BF996-C440-46f5-AFCF-A0CE584AB95C}" = C5200
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D25BDCF5-19F6-4d9e-B9C9-273FE81446C4}" = PS_AIO_02_ProductContext
"{D64BC2CF-0F12-47d7-B412-B4F3FD684253}" = HP Photosmart All-In-One Software 9.0
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E96DA799-C0DF-44d7-AE41-D8312824B898}" = C5200_doccd
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EF0D2E55-6FE2-4e35-BE22-A742E85D84E3}" = PS_AIO_02_Software_min
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.1
"Ashampoo Burning Studio 11_is1" = Ashampoo Burning Studio 11 v.11.0.3
"CCleaner" = CCleaner
"ERUNT_is1" = ERUNT 1.1j
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 5
"InstallWIX_{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"LHTTSENG" = L&H TTS3000 British English
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.1.1004
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 29.0.1 (x86 en-US)" = Mozilla Firefox 29.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Picasa 3" = Picasa 3
"PROPLUS" = Microsoft Office Professional Plus 2007
"Rapport_msi" = Trusteer Endpoint Protection
"RealPlayer 15.0" = RealPlayer
"Video Voice" = Video Voice 3.0
"VideoPerformer" = VideoPerformer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 02/05/2014 09:20:57 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 03/05/2014 03:49:42 | Computer Name = TROJAN | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module igfxpph.dll, version 6.14.10.4926, fault address 0x0000be0d.

Error - 07/05/2014 10:45:55 | Computer Name = TROJAN | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 28.0.0.5186, faulting
module mozalloc.dll, version 28.0.0.5186, fault address 0x0000119c.

Error - 11/05/2014 06:43:11 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 34.0.1847.131, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/05/2014 06:43:14 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 34.0.1847.131, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/05/2014 08:21:47 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/05/2014 08:45:36 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/05/2014 08:47:38 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 13/05/2014 09:37:51 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.0.0.500, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 14/05/2014 05:46:41 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 13/05/2014 02:26:18 | Computer Name = TROJAN | Source = HPZipr12 | ID = 262187
Description =

Error - 13/05/2014 10:46:07 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.

Error - 13/05/2014 10:46:31 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Pml Driver HPZ12 service
to connect.

Error - 13/05/2014 10:46:31 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7000
Description = The Pml Driver HPZ12 service failed to start due to the following
error: %%1053

Error - 14/05/2014 00:36:19 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security
Center Service service to connect.

Error - 14/05/2014 00:36:19 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7000
Description = The Spybot-S&D 2 Security Center Service service failed to start due
to the following error: %%1053

Error - 14/05/2014 00:36:53 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the MBAMService service.

Error - 14/05/2014 00:37:35 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the MBAMService service.

Error - 14/05/2014 05:10:53 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Pml Driver HPZ12 service
to connect.

Error - 14/05/2014 05:10:53 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7000
Description = The Pml Driver HPZ12 service failed to start due to the following
error: %%1053


< End of report >

ken545
2014-05-14, 12:57
Hi,

You missed posting the beginning of the log with all the Internet Explorer info, you can go to My Computer and click on your C: Drive and look for the OTL folder and the log will be in there, right now I am just interested in the main log, not the extras one. When you find it , open it and go to the top and click on Edit > Select All....................then Edit > Copy and paste it back into this thread please

candy123
2014-05-15, 10:32
OTL Extras logfile created on: 14/05/2014 13:09:26 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Roger\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1015.23 Mb Total Physical Memory | 285.23 Mb Available Physical Memory | 28.10% Memory free
3.39 Gb Paging File | 2.40 Gb Available in Paging File | 70.69% Paging File free
Paging file location(s): C:\pagefile.sys 2560 2560 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 214.71 Gb Free Space | 92.20% Space Free | Partition Type: NTFS

Computer Name: TROJAN | User Name: Roger | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htafile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Documents and Settings\Roger\Application Data\File Scout\filescout.exe" /open "%1"
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1542:TCP" = 1542:TCP:*:Enabled:Realtek WPS TCP Prot
"1542:UDP" = 1542:UDP:*:Enabled:Realtek WPS UDP Prot
"53:UDP" = 53:UDP:*:Enabled:Realtek AP UDP Prot

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe" = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Documents and Settings\Roger\Local Settings\Temp\7zS046E\HPDiagnosticCoreUI.exe" = C:\Documents and Settings\Roger\Local Settings\Temp\7zS046E\HPDiagnosticCoreUI.exe:*:Enabled:HPSAPS


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 5
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{262EFBD9-A907-490F-81F4-561FDD3A8C5C}" = NaturalReaderFree
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3365E735-48A6-4194-9988-CE59AC5AE503}" = Bing Bar
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{528145C0-462A-11E1-B8B4-B8AC6F97B88E}" = Google Earth
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9BF745FA-1118-44D2-9362-179DA4B27AC6}" = Webcam 2200
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.9)
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7FB6B99-C93C-4818-825B-37EF4B64C80C}" = PS_AIO_02_Software
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C14337B6-7777-4643-A0B0-B054EF10F59D}" = c5200_Help
"{C68BF996-C440-46f5-AFCF-A0CE584AB95C}" = C5200
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D25BDCF5-19F6-4d9e-B9C9-273FE81446C4}" = PS_AIO_02_ProductContext
"{D64BC2CF-0F12-47d7-B412-B4F3FD684253}" = HP Photosmart All-In-One Software 9.0
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E96DA799-C0DF-44d7-AE41-D8312824B898}" = C5200_doccd
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EF0D2E55-6FE2-4e35-BE22-A742E85D84E3}" = PS_AIO_02_Software_min
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.1
"Ashampoo Burning Studio 11_is1" = Ashampoo Burning Studio 11 v.11.0.3
"CCleaner" = CCleaner
"ERUNT_is1" = ERUNT 1.1j
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 5
"InstallWIX_{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"LHTTSENG" = L&H TTS3000 British English
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.1.1004
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 29.0.1 (x86 en-US)" = Mozilla Firefox 29.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Picasa 3" = Picasa 3
"PROPLUS" = Microsoft Office Professional Plus 2007
"Rapport_msi" = Trusteer Endpoint Protection
"RealPlayer 15.0" = RealPlayer
"Video Voice" = Video Voice 3.0
"VideoPerformer" = VideoPerformer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 02/05/2014 09:20:57 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 03/05/2014 03:49:42 | Computer Name = TROJAN | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module igfxpph.dll, version 6.14.10.4926, fault address 0x0000be0d.

Error - 07/05/2014 10:45:55 | Computer Name = TROJAN | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 28.0.0.5186, faulting
module mozalloc.dll, version 28.0.0.5186, fault address 0x0000119c.

Error - 11/05/2014 06:43:11 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 34.0.1847.131, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/05/2014 06:43:14 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 34.0.1847.131, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/05/2014 08:21:47 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/05/2014 08:45:36 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/05/2014 08:47:38 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 13/05/2014 09:37:51 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.0.0.500, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 14/05/2014 05:46:41 | Computer Name = TROJAN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 13/05/2014 02:26:18 | Computer Name = TROJAN | Source = HPZipr12 | ID = 262187
Description =

Error - 13/05/2014 10:46:07 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.

Error - 13/05/2014 10:46:31 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Pml Driver HPZ12 service
to connect.

Error - 13/05/2014 10:46:31 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7000
Description = The Pml Driver HPZ12 service failed to start due to the following
error: %%1053

Error - 14/05/2014 00:36:19 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security
Center Service service to connect.

Error - 14/05/2014 00:36:19 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7000
Description = The Spybot-S&D 2 Security Center Service service failed to start due
to the following error: %%1053

Error - 14/05/2014 00:36:53 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the MBAMService service.

Error - 14/05/2014 00:37:35 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the MBAMService service.

Error - 14/05/2014 05:10:53 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Pml Driver HPZ12 service
to connect.

Error - 14/05/2014 05:10:53 | Computer Name = TROJAN | Source = Service Control Manager | ID = 7000
Description = The Pml Driver HPZ12 service failed to start due to the following
error: %%1053


< End of report >

candy123
2014-05-15, 10:42
OTL logfile created on: 14/05/2014 13:09:26 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Roger\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1015.23 Mb Total Physical Memory | 285.23 Mb Available Physical Memory | 28.10% Memory free
3.39 Gb Paging File | 2.40 Gb Available in Paging File | 70.69% Paging File free
Paging file location(s): C:\pagefile.sys 2560 2560 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 214.71 Gb Free Space | 92.20% Space Free | Partition Type: NTFS

Computer Name: TROJAN | User Name: Roger | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Roger\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\klwtblfs.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\CyberLink\YouCam\YouCamService.exe (CyberLink Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\PixArt\Pac7302\Monitor.exe (PixArt Imaging Incorporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportMS.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\kpcengine.2.2.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\dblite.dll ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()
MOD - C:\WINDOWS\system32\qcap.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Services (SafeList) ==========

SRV - (SDWSCService) -- C:\Program Files\Spybot File not found
SRV - (SDUpdateService) -- C:\Program Files\Spybot File not found
SRV - (SDScannerService) -- C:\Program Files\Spybot File not found
SRV - (AppMgmt) -- %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (RapportMgmtService) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (BBUpdate) -- C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) -- C:\Program Files\Microsoft\BingBar\7.3.132.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (avp) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
SRV - (CSObjectsSrv) -- C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)


========== Driver Services (SafeList) ==========

DRV - (WDICA) -- File not found
DRV - (RTL8192cu) -- system32\DRIVERS\RTL8192cu.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV - (Changer) -- File not found
DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys (Malwarebytes Corporation)
DRV - (RapportPG) -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportEI) -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) -- C:\WINDOWS\system32\drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (kl1) -- C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (KLIF) -- C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab ZAO)
DRV - (kneps) -- C:\WINDOWS\system32\drivers\kneps.sys (Kaspersky Lab ZAO)
DRV - (kltdi) -- C:\WINDOWS\system32\drivers\kltdi.sys (Kaspersky Lab ZAO)
DRV - (klmouflt) -- C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab ZAO)
DRV - (klkbdflt) -- C:\WINDOWS\system32\drivers\klkbdflt.sys (Kaspersky Lab ZAO)
DRV - (RapportCerberus_59849) -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys ()
DRV - (klim5) -- C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab ZAO)
DRV - (DrvAgent32) -- C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (IntcAzAudAddService) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (CSCrySec) -- C:\WINDOWS\system32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) -- C:\WINDOWS\system32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (clwvd) -- C:\WINDOWS\system32\drivers\clwvd.sys (CyberLink Corporation)
DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (PAC7302) -- C:\WINDOWS\system32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC=UP66
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?ocid=OIE8HP&PC=UP66
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\..\SearchScopes\{18FCFA92-EE6D-4594-984F-2F900D2EDE18}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADSA_enCY470
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\..\SearchScopes\{18FCFA92-EE6D-4594-984F-2F900D2EDE18}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADSA_enCY470
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC=UP66
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.bbcnews.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: url_advisor%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: content_blocker%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: anti_banner%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: online_banking%40kaspersky.com:13.0.2.653
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@ei.Astrology_4a.com/Plugin: C:\Program Files\Astrology_4aEI\Installr\1.bin\NP4aEISB.dll (Astrology.com)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/07 09:25:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\url_advisor@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\url_advisor@kaspersky.com [2014/04/02 11:28:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\virtual_keyboard@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\virtual_keyboard@kaspersky.com [2014/04/02 11:28:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\content_blocker@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\content_blocker@kaspersky.com [2014/04/02 11:28:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\anti_banner@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\anti_banner@kaspersky.com [2014/04/02 11:28:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\online_banking@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\online_banking@kaspersky.com [2014/04/02 11:28:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/05/10 11:16:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2013/01/08 17:40:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Roger\Application Data\Mozilla\Extensions
[2014/04/25 20:06:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Roger\Application Data\Mozilla\Firefox\Profiles\2ayiv71i.default-1398444096234\extensions
[2014/05/10 11:16:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/05/10 11:16:24 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/04/02 11:28:27 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\ANTI_BANNER@KASPERSKY.COM
[2014/04/02 11:28:27 | 000,000,000 | ---D | M] (Content Blocker) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\CONTENT_BLOCKER@KASPERSKY.COM
[2014/04/02 11:28:28 | 000,000,000 | ---D | M] (Safe Money) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\ONLINE_BANKING@KASPERSKY.COM
[2014/04/02 11:28:29 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\URL_ADVISOR@KASPERSKY.COM
[2013/10/18 11:27:07 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.msn.com/?pc=UP94&ocid=UP94DHP
CHR - plugin: Error reading preferences file
CHR - Extension: Kaspersky URL Advisor = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0\
CHR - Extension: Safe Money = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_1\
CHR - Extension: Content Blocker = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.2.614_0\
CHR - Extension: Virtual Keyboard = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.2.614_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Google Wallet = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Anti-Banner = C:\Documents and Settings\Roger\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0\

O1 HOSTS File: ([2014/05/13 18:53:31 | 000,450,543 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15468 more lines...
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [YouCam Service] C:\Program Files\CyberLink\YouCam\YouCamService.exe (CyberLink Corp.)
O4 - Startup: C:\Documents and Settings\Roger\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2000478354-1715567821-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1369313642218 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8DEA69D0-8FCC-4C91-8431-1493E397A41D}: DhcpNameServer = 192.168.10.254
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/02/09 12:54:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2014/05/14 13:07:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Roger\Desktop\OTL.exe
[2014/05/14 12:30:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2014/05/13 19:24:38 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\66764599.sys
[2014/05/13 18:34:54 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\14604B0C.sys
[2014/05/12 20:17:56 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014/05/12 20:16:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/05/12 20:16:31 | 000,050,648 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014/05/12 20:16:31 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2014/05/12 20:16:31 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014/05/12 18:30:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2014/05/12 17:54:06 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\WINDOWS\System32\sqlite3.dll
[2014/05/12 17:53:13 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/05/12 13:30:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2014/05/12 13:29:01 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2014/05/12 13:29:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2014/05/11 14:55:43 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014/05/11 14:54:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2014/05/11 14:51:46 | 000,728,960 | ---- | C] (Enigma Software Group USA, LLC.) -- C:\Documents and Settings\Roger\My Documents\SpyHunter-Installer.exe
[2014/05/10 13:19:51 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Roger\Recent
[2014/05/10 11:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014/04/27 11:44:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2014/04/25 19:41:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Roger\Desktop\Old Firefox Data
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Roger\*.tmp files -> C:\Documents and Settings\Roger\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014/05/14 13:11:02 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/05/14 13:10:03 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/05/14 13:09:38 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2014/05/14 13:09:38 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2014/05/14 13:07:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Roger\Desktop\OTL.exe
[2014/05/14 12:12:00 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014/05/14 07:37:44 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/05/14 07:37:36 | 000,000,222 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014/05/14 07:37:34 | 000,000,620 | ---- | M] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2014/05/14 07:37:34 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2000478354-1715567821-839522115-1004.job
[2014/05/14 07:36:49 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RMAutoUpdate.job
[2014/05/14 07:35:58 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/05/14 07:35:53 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/05/13 19:31:54 | 000,009,467 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2014/05/13 19:24:38 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\66764599.sys
[2014/05/13 18:53:31 | 000,450,543 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2014/05/13 18:34:55 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\14604B0C.sys
[2014/05/13 14:48:37 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F3D1F9B5-E016-47FB-8DD6-B47FAD44F026}.job
[2014/05/12 20:16:35 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/05/12 19:24:00 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2000478354-1715567821-839522115-1004.job
[2014/05/12 13:29:11 | 000,000,776 | ---- | M] () -- C:\Documents and Settings\Roger\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2014/05/12 13:29:02 | 000,000,620 | ---- | M] () -- C:\Documents and Settings\Roger\Desktop\NTREGOPT.lnk
[2014/05/12 13:29:02 | 000,000,601 | ---- | M] () -- C:\Documents and Settings\Roger\Desktop\ERUNT.lnk
[2014/05/11 21:46:01 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2014/05/11 14:51:56 | 000,728,960 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Documents and Settings\Roger\My Documents\SpyHunter-Installer.exe
[2014/05/11 11:17:58 | 000,268,600 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/05/09 10:44:30 | 000,000,216 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014/05/08 11:49:08 | 003,694,691 | ---- | M] () -- C:\Documents and Settings\Roger\My Documents\765210.zip
[2014/04/30 22:56:33 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2014/04/30 11:13:01 | 006,022,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2014/04/30 00:32:29 | 000,000,616 | ---- | M] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2014/04/29 23:45:15 | 000,000,000 | ---- | M] () -- C:\cookies.sqlite
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Roger\*.tmp files -> C:\Documents and Settings\Roger\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014/05/12 20:16:35 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/05/12 13:29:11 | 000,000,776 | ---- | C] () -- C:\Documents and Settings\Roger\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2014/05/12 13:29:02 | 000,000,620 | ---- | C] () -- C:\Documents and Settings\Roger\Desktop\NTREGOPT.lnk
[2014/05/12 13:29:02 | 000,000,601 | ---- | C] () -- C:\Documents and Settings\Roger\Desktop\ERUNT.lnk
[2014/05/11 11:17:58 | 000,268,600 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/05/08 11:47:55 | 003,694,691 | ---- | C] () -- C:\Documents and Settings\Roger\My Documents\765210.zip
[2014/04/29 23:45:15 | 000,000,000 | ---- | C] () -- C:\cookies.sqlite
[2013/02/02 13:20:38 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Roger\Local Settings\Application Data\WebpageIcons.db
[2012/03/01 11:34:00 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\Roger\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2013/10/17 11:02:11 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 06:42:06 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 15:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 06:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/02 13:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\6F638BC8005648376B1EAE987B07D329
[2012/02/09 15:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2012/02/09 16:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\install_clap
[2012/11/25 16:12:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2013/04/15 19:17:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2012/02/11 16:24:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2012/11/10 04:03:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\ilividtoolbarguid
[2012/02/12 17:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Ashampoo
[2012/11/13 17:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\FreeFixer
[2013/07/09 20:05:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Imperium Romanum
[2014/04/02 14:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Naturalsoft
[2013/10/18 13:23:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\Oracle
[2012/11/25 16:07:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Roger\Application Data\PC Utility Kit

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2012/11/25 15:04:06 | 000,000,251 | ---- | M] ()(C:\Documents and Settings\Roger\Desktop\ASHANTI F??G??? 1961-1988.url) -- C:\Documents and Settings\Roger\Desktop\ASHANTI ΦΡΕΓΆΤΑ 1961-1988.url
[2012/11/25 15:04:06 | 000,000,251 | ---- | C] ()(C:\Documents and Settings\Roger\Desktop\ASHANTI F??G??? 1961-1988.url) -- C:\Documents and Settings\Roger\Desktop\ASHANTI ΦΡΕΓΆΤΑ 1961-1988.url

========== Alternate Data Streams ==========

@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1
@Alternate Data Stream - 440 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:D1B5B4F1

< End of report >

ken545
2014-05-15, 13:35
Sometimes the forum gets ahead of itself, glad you found my post

Just post the log from this fix and then tell me how you feel your system is behaving now, is ilivid still present


Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL Make sure it starts with :OTL and ends with [reboot]




:OTL
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1
@Alternate Data Stream - 440 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1


:Services

:Reg

:Files
C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1
C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1
C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1
C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1
C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1
ipconfig /flushdns /c


:Commands
[purity]
[resethosts]
[EMPTYJAVA]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces

candy123
2014-05-15, 14:58
Hi Ken just checked in and noticed you had written a reply, however I can't see your post?

ken545
2014-05-15, 15:07
Sometimes the forum gets ahead of itself, glad you found my post

Just post the log from this fix and then tell me how you feel your system is behaving now, is ilivid still present


Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL Make sure it starts with :OTL and ends with [reboot]




:OTL
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {07FF25BA-8946-4A35-8B81-C841149C1FCE} - No CLSID value found.
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1
@Alternate Data Stream - 440 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1


:Services

:Reg

:Files
C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1
C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1
C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1
C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1
C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1
ipconfig /flushdns /c


:Commands
[purity]
[resethosts]
[EMPTYJAVA]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces

candy123
2014-05-15, 15:18
All processes killed
========== OTL ==========
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07FF25BA-8946-4A35-8B81-C841149C1FCE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07FF25BA-8946-4A35-8B81-C841149C1FCE}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07FF25BA-8946-4A35-8B81-C841149C1FCE} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07FF25BA-8946-4A35-8B81-C841149C1FCE}\ not found.
ADS C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1 deleted successfully.
ADS C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1 deleted successfully.
ADS C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1 deleted successfully.
ADS C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1 deleted successfully.
ADS C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1 deleted successfully.
ADS C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1 deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File\Folder C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZZ..Z.ZZ..Z:1 not found.
File\Folder C:\3590F75ABA9E485486C100C1A9D4FF06ZZ.ZZ.Z...ZZZ.ZZ:1 not found.
File\Folder C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.ZZ.ZZZZZZ..Z:1 not found.
File\Folder C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z.Z.ZZZZ.ZZ.ZZ:1 not found.
File\Folder C:\3590F75ABA9E485486C100C1A9D4FF06Z...Z..ZZ.Z...ZZ:1 not found.
File\Folder C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZ.Z.Z.ZZ.ZZZZ:1 not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Roger\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Roger\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYJAVA]

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Roger
->Java cache emptied: 0 bytes

User: Roр

Total Java Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 65938 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1598904 bytes
->Flash cache emptied: 598 bytes

User: Roger
->Temp folder emptied: 1042683 bytes
->Temporary Internet Files folder emptied: 53462790 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 17574759 bytes
->Google Chrome cache emptied: 23919240 bytes
->Flash cache emptied: 4606 bytes

User: Roр

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 3662790 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 46325 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 9379334 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 779931 bytes

Total Files Cleaned = 106.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 05152014_160707

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

candy123
2014-05-15, 15:52
11462

Hi Ken, am using XP, start search ilivid.Toolbar, this log still comes up! The latest entry was, I think 12 May.

were there other issues with the machine? thanks

ken545
2014-05-15, 16:21
Not to much else going on except for ilivid



Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.




C:\Documents and Settings\Roger\Application Data\ilivid <-- Go here and delete anything related to ilivid ( but nothing else )




Then lets do a deeper search, you will need the 32 bit version

Download and Run SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1 (http://jpshortstuff.247fixes.com/SystemLook.exe)
Download Mirror #2 (http://images.malwareremoval.com/jpshortstuff/SystemLook.exe)
64 Bit Version (http://jpshortstuff.247Fixes.com/SystemLook_x64.exe)


Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield:


:folderfind
ilivid
:filefind
ilivid
:regfind
ilivid

Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

candy123
2014-05-15, 19:57
SystemLook 30.07.11 by jpshortstuff
Log created at 20:52 on 15/05/2014 by Roger
Administrator - Elevation successful

========== folderfind ==========

Searching for "ilivid"
C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid d------ [14:09 24/02/2014]

========== filefind ==========

Searching for "ilivid"
No files found.

========== regfind ==========

Searching for "ilivid"
[HKEY_CURRENT_USER\Software\Google\Picasa\Picasa2\Preferences]
"LastImport0"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid\"
[HKEY_CURRENT_USER\Software\Google\Picasa\Picasa2\Preferences]
"SaveFile"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid\"
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"000"="ilivid"
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"001"="ilivid.toolbar"
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"002"="ilivid.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"003"="ilivid toolbar"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"e"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid1.jpg"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg]
"a"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid1.jpg"
[HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Documents and Settings\Roger\Local Settings\Application Data\iLivid]
[HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Documents and Settings\Roger\Local Settings\Application Data\iLivid]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetup[1].exe]
[HKEY_USERS\.DEFAULT\Software\ilividtoolbarguid]
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Google\Picasa\Picasa2\Preferences]
"LastImport0"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid\"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Google\Picasa\Picasa2\Preferences]
"SaveFile"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid\"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"000"="ilivid"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"001"="ilivid.toolbar"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"002"="ilivid.exe"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"003"="ilivid toolbar"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"e"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid1.jpg"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg]
"a"="C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid1.jpg"
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Documents and Settings\Roger\Local Settings\Application Data\iLivid]
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Documents and Settings\Roger\Local Settings\Application Data\iLivid]
[HKEY_USERS\S-1-5-18\Software\ilividtoolbarguid]

-= EOF =-

ken545
2014-05-15, 20:37
Were going to make some changes to your registry so you need to back it up first

Backup the Registry:

Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.


Please download the installer for Registry Backup from here (http://www.bleepingcomputer.com/download/registry-backup/) or here (http://www.tweaking.com/files/setups/tweaking.com_registry_backup_setup.exe) and save to your desktop.
Right-click on tweaking.com_registry_backup_setup.exe and select Run as Administrator >> Follow the prompts for a default installation
Ensure the option Open "Tweaking.com - Registry Backup" When Install Completes is selected >> Next > >> Finish
Once the GUI(graphical user interface) has appeared/loaded:-

http://i280.photobucket.com/albums/kk173/Dakeyras_album2/TCRB-1.jpg


Click on Backup Now >> once the process is complete the below will be displayed in the GUI:-

http://i280.photobucket.com/albums/kk173/Dakeyras_album2/TBRB-2.jpg


Close Tweaking.com - Registry Backup

Note: There will now be a folder at the root of the Hard-Drive named C:\RegBackup, do not delete this as it is the actual backup just created.







Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL




:OTL


:Services

:Reg
[HKEY_CURRENT_USER\Software\Google\Picasa\Picasa2\Preferences]
"LastImport0"=""
[HKEY_CURRENT_USER\Software\Google\Picasa\Picasa2\Preferences]
"SaveFile"=""
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"000"=""
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"001"=""
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"002"=""
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
"003"=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"e"=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg]
"a"=""
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetup[1].exe]
[-HKEY_USERS\.DEFAULT\Software\ilividtoolbarguid]
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Google\Picasa\Picasa2\Preferences]
"LastImport0"=""
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Google\Picasa\Picasa2\Preferences]
"SaveFile"=""
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"000"=""
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"001"=""
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"002"=""
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603]
"003"=""
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"e"=""
[HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg]
"a"=""
[-HKEY_USERS\S-1-5-18\Software\ilividtoolbarguid]
[-HKEY_CURRENT_USER\Software\ilivid]
[-HKEY_LOCAL_MACHINE\Software\ilivid]

:Files
C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid
C:\Documents and Settings\Roger\Local Settings\Application Data\iLivid


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces

candy123
2014-05-16, 11:12
All processes killed
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
HKEY_CURRENT_USER\Software\Google\Picasa\Picasa2\Preferences\\"LastImport0"|"" /E : value set successfully!
HKEY_CURRENT_USER\Software\Google\Picasa\Picasa2\Preferences\\"SaveFile"|"" /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603\\"000"|"" /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603\\"001"|"" /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603\\"002"|"" /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603\\"003"|"" /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\\"e"|"" /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg\\"a"|"" /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetup[1].exe\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\ilividtoolbarguid\ deleted successfully.
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Google\Picasa\Picasa2\Preferences\\"LastImport0"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Google\Picasa\Picasa2\Preferences\\"SaveFile"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603\\"000"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603\\"001"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603\\"002"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Search Assistant\ACMru\5603\\"003"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\\"e"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-2000478354-1715567821-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg\\"a"|"" /E : value set successfully!
Registry key HKEY_USERS\S-1-5-18\Software\ilividtoolbarguid\ not found.
Registry key HKEY_CURRENT_USER\Software\ilivid\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\ilivid\ not found.
========== FILES ==========
C:\Documents and Settings\Roger\My Documents\My Pictures\ilivid folder moved successfully.
File\Folder C:\Documents and Settings\Roger\Local Settings\Application Data\iLivid not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 66067 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Roger
->Temp folder emptied: 1233955 bytes
->Temporary Internet Files folder emptied: 42104909 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 387662650 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 3026 bytes

User: Roр

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 29975 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 3329630 bytes

Total Files Cleaned = 414.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 05162014_115322

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

ken545
2014-05-16, 13:07
Good,

When you use any of your browsers , IE, Firefox or Chrome to you see any trace of ilivid ?

candy123
2014-05-16, 16:42
Hi Ken, no I don't see any ilivid in the browser. I checked spy bot today and it appears that it has been puttying ilivid in quarantine.

Do you think I'm OK now? Regards.

ken545
2014-05-16, 17:25
Is Spybot still finding it, if so run a scan and post the entry it finds for ilivid

candy123
2014-05-18, 10:59
Hi Ken, yes 1 item dated 20, May 2013, which is in quarantine, but am unable to purge it, the system comes up saying can't delete it.

ken545
2014-05-18, 12:14
Can you take a snapshot of the quarantine folder so I can see what it is, as a side note if its in quarantine it cant hurt you, not sure why it wont delete

candy123
2014-05-19, 16:36
11477


Hi Ken here it is.

ken545
2014-05-19, 17:52
Hi,

Thats not what i was really looking for, I was looking for a path to the files that it wont let you delete so we could try removing them manually

Can you open up the Quarantine folder that shows the files in Quarantine and take a snapshot of that

Run another scan with Spybot and post the log and lets see if we can see them

candy123
2014-05-20, 10:57
[i] 2014-05-18 11:51:59 Quarantine: Start purge selected items...
[i] 2014-05-18 11:52:02 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-05-12 12:29:52
[i] 2014-05-18 11:52:05 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-05-12 12:29:11
[i] 2014-05-18 11:52:08 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-04-26 19:46:37
[i] 2014-05-18 11:52:08 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-04-26 19:43:59
[i] 2014-05-18 11:52:09 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-04-21 18:15:54
[i] 2014-05-18 11:52:10 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-04-21 18:15:36
[i] 2014-05-18 11:52:10 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-04-21 18:14:19
[i] 2014-05-18 11:52:11 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-03-15 14:39:20
[i] 2014-05-18 11:52:12 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-03-15 14:39:04
[i] 2014-05-18 11:52:12 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-03-06 15:24:53
[i] 2014-05-18 11:52:18 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-25 12:12:34
[i] 2014-05-18 11:52:19 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-25 12:12:28
[i] 2014-05-18 11:52:19 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-25 12:10:21
[i] 2014-05-18 11:52:20 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-25 12:09:23
[i] 2014-05-18 11:52:20 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-25 12:08:27
[i] 2014-05-18 11:52:21 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-24 16:30:06
[i] 2014-05-18 11:52:22 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-24 15:11:01
[i] 2014-05-18 11:52:22 Quarantine: Purged ilivid.Toolbar: All detected items of product - 2014-02-24 15:10:24
[-] 2014-05-18 11:52:23 Quarantine: Error purging! ilivid.Toolbar: All detected items of product - 2013-05-20 14:55:47
[i] 2014-05-18 11:52:26 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:52:44 Quarantine: Start purge selected items...
[-] 2014-05-18 11:52:46 Quarantine: Error purging! ilivid.Toolbar: All detected items of product - 2013-05-20 14:55:47
[i] 2014-05-18 11:52:48 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:52:56 Quarantine: Start purge selected items...
[i] 2014-05-18 11:52:56 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:52:57 Quarantine: Start purge selected items...
[i] 2014-05-18 11:52:57 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:52:58 Quarantine: Start purge selected items...
[i] 2014-05-18 11:52:58 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:52:59 Quarantine: Start purge selected items...
[i] 2014-05-18 11:52:59 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:52:59 Quarantine: Start purge selected items...
[i] 2014-05-18 11:52:59 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:53:00 Quarantine: Start purge selected items...
[i] 2014-05-18 11:53:00 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:53:00 Quarantine: Start purge selected items...
[i] 2014-05-18 11:53:00 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:53:01 Quarantine: Start purge selected items...
[i] 2014-05-18 11:53:01 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:53:05 Quarantine: Start purge selected items...
[i] 2014-05-18 11:53:07 Quarantine: Purged Cache: All detected items of product - 2014-05-13 19:31:56
[i] 2014-05-18 11:53:07 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:55:37 Quarantine: Start purge selected items...
[i] 2014-05-18 11:55:40 Quarantine: Purged Zedo: All detected items of product - 2014-04-26 19:45:40
[i] 2014-05-18 11:55:42 Quarantine: Purged Zedo: All detected items of product - 2014-04-26 19:44:12
[i] 2014-05-18 11:55:42 Quarantine: Purged Windows: All detected items of product - 2014-05-13 19:31:55
[i] 2014-05-18 11:55:43 Quarantine: Purged Windows: All detected items of product - 2014-05-13 14:45:18
[i] 2014-05-18 11:55:44 Quarantine: Purged Windows: All detected items of product - 2014-05-12 12:29:18
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-04-26 19:45:52
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-04-26 19:44:38
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-04-21 18:14:55
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-03-15 14:40:35
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-03-15 14:39:15
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-03-06 15:25:53
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-02-25 12:08:36
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-02-24 15:10:36
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows: All detected items of product - 2014-05-17 19:36:05
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows.OpenWith: All detected items of product - 2014-05-17 19:36:05
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows Explorer: All detected items of product - 2014-05-13 19:31:55
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows Explorer: All detected items of product - 2014-05-13 14:45:20
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows Explorer: All detected items of product - 2014-05-12 12:29:19
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows Explorer: All detected items of product - 2014-04-26 19:45:52
[i] 2014-05-18 11:55:45 Quarantine: Purged Windows Explorer: All detected items of product - 2014-04-26 19:44:39
[i] 2014-05-18 11:55:46 Quarantine: Purged Windows Explorer: All detected items of product - 2014-04-21 18:14:55
[i] 2014-05-18 11:55:46 Quarantine: Purged Windows Explorer: All detected items of product - 2014-03-15 14:40:35
[i] 2014-05-18 11:55:46 Quarantine: Purged Windows Explorer: All detected items of product - 2014-03-15 14:39:15
[i] 2014-05-18 11:55:46 Quarantine: Purged Windows Explorer: All detected items of product - 2014-03-06 15:25:55
[i] 2014-05-18 11:55:46 Quarantine: Purged Windows Explorer: All detected items of product - 2014-02-25 12:08:36
[i] 2014-05-18 11:55:46 Quarantine: Purged Windows Explorer: All detected items of product - 2014-02-24 15:10:36
[i] 2014-05-18 11:55:46 Quarantine: Purged Windows Explorer: All detected items of product - 2014-05-17 19:36:05
[i] 2014-05-18 11:55:46 Quarantine: Purged Statcounter: All detected items of product - 2014-05-17 19:35:59
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-05-13 14:45:17
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-05-12 12:29:18
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-04-26 19:45:52
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-04-26 19:44:36
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-04-21 18:14:54
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-03-15 14:40:35
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-03-15 14:39:15
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-03-06 15:25:52
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-02-25 12:08:35
[i] 2014-05-18 11:55:46 Quarantine: Purged MS Office 12.0 (Word): All detected items of product - 2014-02-24 15:10:36
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectInput: All detected items of product - 2014-05-13 19:31:55
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectInput: All detected items of product - 2014-05-13 14:45:15
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectInput: All detected items of product - 2014-05-12 12:29:18
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-05-13 14:45:15
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-05-12 12:29:18
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-04-26 19:45:52
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-04-26 19:44:34
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-04-21 18:14:54
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-03-15 14:40:35
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-03-15 14:39:15
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-03-06 15:25:50
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-02-25 12:08:35
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-02-24 15:10:36
[i] 2014-05-18 11:55:46 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-05-17 19:36:05
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-05-13 19:31:54
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-05-13 14:45:11
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-05-12 12:29:18
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-04-26 19:45:52
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-04-26 19:44:30
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-04-21 18:14:54
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-03-15 14:40:34
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-03-15 14:39:14
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-03-06 15:25:48
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-02-25 12:08:35
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-02-24 15:10:35
[i] 2014-05-18 11:55:47 Quarantine: Purged MS Direct3D: All detected items of product - 2014-05-17 19:36:05
[i] 2014-05-18 11:55:47 Quarantine: Purged MediaPlex: All detected items of product - 2014-04-26 19:45:39
[i] 2014-05-18 11:55:47 Quarantine: Purged MediaPlex: All detected items of product - 2014-04-26 19:44:07
[i] 2014-05-18 11:55:47 Quarantine: Purged Macromedia.FlashPlayer.Cookies: All detected items of product - 2014-05-13 19:31:48
[i] 2014-05-18 11:55:47 Quarantine: Purged Macromedia.FlashPlayer.Cookies: All detected items of product - 2014-05-13 14:43:57
[i] 2014-05-18 11:55:47 Quarantine: Purged Macromedia.FlashPlayer.Cookies: All detected items of product - 2014-05-12 12:29:12
[i] 2014-05-18 11:55:47 Quarantine: Purged Macromedia.FlashPlayer.Cookies: All detected items of product - 2014-04-26 19:45:26
[i] 2014-05-18 11:55:47 Quarantine: Purged Macromedia.FlashPlayer.Cookies: All detected items of product - 2014-04-26 19:44:00
[i] 2014-05-18 11:55:47 Quarantine: Purged Macromedia.FlashPlayer.Cookies: All detected items of product - 2014-05-17 19:35:50
[i] 2014-05-18 11:55:47 Quarantine: Purged Internet Explorer: All detected items of product - 2014-05-13 14:45:07
[i] 2014-05-18 11:55:47 Quarantine: Purged Internet Explorer: All detected items of product - 2014-05-12 12:29:18
[i] 2014-05-18 11:55:47 Quarantine: Purged Internet Explorer: All detected items of product - 2014-03-15 14:40:34
[i] 2014-05-18 11:55:47 Quarantine: Purged Internet Explorer: All detected items of product - 2014-03-15 14:39:14
[i] 2014-05-18 11:55:47 Quarantine: Purged History: All detected items of product - 2014-05-13 19:31:57
[i] 2014-05-18 11:55:47 Quarantine: Purged History: All detected items of product - 2014-05-13 14:45:53
[i] 2014-05-18 11:55:47 Quarantine: Purged History: All detected items of product - 2014-04-26 19:45:53
[i] 2014-05-18 11:55:47 Quarantine: Purged History: All detected items of product - 2014-04-26 19:45:18
[i] 2014-05-18 11:55:47 Quarantine: Purged History: All detected items of product - 2014-03-15 14:40:36
[i] 2014-05-18 11:55:47 Quarantine: Purged History: All detected items of product - 2014-03-06 15:26:09
[i] 2014-05-18 11:55:47 Quarantine: Purged History: All detected items of product - 2014-02-25 12:08:38
[i] 2014-05-18 11:55:48 Quarantine: Purged History: All detected items of product - 2014-05-17 19:36:06
[i] 2014-05-18 11:55:48 Quarantine: Purged FastClick: All detected items of product - 2014-05-17 19:35:59
[i] 2014-05-18 11:55:48 Quarantine: Purged DoubleClick: All detected items of product - 2014-05-13 14:44:01
[i] 2014-05-18 11:55:48 Quarantine: Purged DoubleClick: All detected items of product - 2014-05-12 12:29:12
[i] 2014-05-18 11:55:48 Quarantine: Purged DoubleClick: All detected items of product - 2014-04-26 19:45:39
[i] 2014-05-18 11:55:48 Quarantine: Purged DoubleClick: All detected items of product - 2014-04-26 19:44:01
[i] 2014-05-18 11:55:48 Quarantine: Purged DoubleClick: All detected items of product - 2014-05-17 19:35:52
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-05-13 19:31:57
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-05-13 14:45:22
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-05-12 12:29:19
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-04-26 19:45:53
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-04-26 19:44:42
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-04-21 18:14:56
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-03-15 14:40:36
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-03-15 14:39:16
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-03-06 15:25:58
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-02-25 12:08:36
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-02-24 15:10:37
[i] 2014-05-18 11:55:48 Quarantine: Purged Cookie: All detected items of product - 2014-05-17 19:36:05
[i] 2014-05-18 11:55:48 Quarantine: Purged Common Dialogs: All detected items of product - 2014-05-13 19:31:48
[i] 2014-05-18 11:55:48 Quarantine: Purged Common Dialogs: All detected items of product - 2014-05-13 14:44:44
[i] 2014-05-18 11:55:49 Quarantine: Purged Common Dialogs: All detected items of product - 2014-05-12 12:29:13
[i] 2014-05-18 11:55:49 Quarantine: Purged Common Dialogs: All detected items of product - 2014-04-21 18:14:22
[i] 2014-05-18 11:55:49 Quarantine: Purged Common Dialogs: All detected items of product - 2014-03-06 15:25:02
[i] 2014-05-18 11:55:49 Quarantine: Purged Common Dialogs: All detected items of product - 2014-02-25 12:08:27
[i] 2014-05-18 11:55:49 Quarantine: Purged Common Dialogs: All detected items of product - 2014-02-24 15:10:25
[i] 2014-05-18 11:55:49 Quarantine: Purged Common Dialogs: All detected items of product - 2014-05-17 19:36:00
[i] 2014-05-18 11:55:49 Quarantine: Purged CasaleMedia: All detected items of product - 2014-04-26 19:45:39
[i] 2014-05-18 11:55:49 Quarantine: Purged CasaleMedia: All detected items of product - 2014-04-26 19:44:10
[i] 2014-05-18 11:55:49 Quarantine: Purged CasaleMedia: All detected items of product - 2014-05-17 19:35:57
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-05-13 14:45:27
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-05-12 12:29:20
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-04-26 19:45:53
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-04-26 19:44:48
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-04-21 18:14:58
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-03-15 14:40:36
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-03-15 14:39:17
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-03-06 15:26:05
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-02-25 12:08:37
[i] 2014-05-18 11:55:49 Quarantine: Purged Cache: All detected items of product - 2014-02-24 15:10:43
[i] 2014-05-18 11:55:49 Quarantine: Purged BurstMedia: All detected items of product - 2014-04-26 19:45:39
[i] 2014-05-18 11:55:49 Quarantine: Purged BurstMedia: All detected items of product - 2014-04-26 19:44:08
[i] 2014-05-18 11:55:49 Quarantine: Purged BurstMedia: All detected items of product - 2014-05-17 19:35:57
[i] 2014-05-18 11:55:49 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:56:00 Quarantine: Start purge selected items...
[i] 2014-05-18 11:56:01 Quarantine: Purged Windows Media SDK: All detected items of product - 2014-05-12 12:29:19
[i] 2014-05-18 11:56:01 Quarantine: Purged MS Regedit: All detected items of product - 2014-05-12 12:29:18
[i] 2014-05-18 11:56:01 Quarantine: Finished purge selected items.
[i] 2014-05-18 11:56:05 Quarantine: Start purge selected items...
[-] 2014-05-18 11:56:08 Quarantine: Error purging! ilivid.Toolbar: All detected items of product - 2013-05-20 14:55:47
[i] 2014-05-18 11:56:44 Quarantine: Finished purge selected items.
[i] 2014-05-18 17:11:11 Quarantine: Start purge selected items...
[i] 2014-05-18 17:11:13 Quarantine: Purged Log: All detected items of product - 2014-05-18 17:08:50
[i] 2014-05-18 17:11:14 Quarantine: Purged Log: All detected items of product - 2014-05-13 19:31:49
[i] 2014-05-18 17:11:15 Quarantine: Purged Log: All detected items of product - 2014-05-13 14:44:51
[i] 2014-05-18 17:11:16 Quarantine: Purged Log: All detected items of product - 2014-05-12 12:29:14
[i] 2014-05-18 17:11:16 Quarantine: Purged Log: All detected items of product - 2014-04-26 19:45:40
[i] 2014-05-18 17:11:17 Quarantine: Purged Log: All detected items of product - 2014-04-26 19:44:18
[i] 2014-05-18 17:11:18 Quarantine: Purged Log: All detected items of product - 2014-04-21 18:14:26
[i] 2014-05-18 17:11:18 Quarantine: Purged Log: All detected items of product - 2014-03-15 14:39:20
[i] 2014-05-18 17:11:19 Quarantine: Purged Log: All detected items of product - 2014-03-15 14:39:06
[i] 2014-05-18 17:11:19 Quarantine: Purged Log: All detected items of product - 2014-03-06 15:25:15
[i] 2014-05-18 17:11:20 Quarantine: Purged Log: All detected items of product - 2014-02-25 12:08:28
[i] 2014-05-18 17:11:21 Quarantine: Purged Log: All detected items of product - 2014-02-24 15:10:26
[i] 2014-05-18 17:11:22 Quarantine: Purged Log: All detected items of product - 2014-05-17 19:36:00
[-] 2014-05-18 17:11:23 Quarantine: Error purging! ilivid.Toolbar: All detected items of product - 2013-05-20 14:55:47
[i] 2014-05-18 17:11:25 Quarantine: Finished purge selected items.
[i] 2014-05-18 17:13:13 Quarantine: Start purge selected items...
[i] 2014-05-18 17:13:21 Quarantine: Purged Windows: All detected items of product - 2014-05-18 17:08:56
[i] 2014-05-18 17:13:21 Quarantine: Purged Windows Explorer: All detected items of product - 2014-05-18 17:08:56
[i] 2014-05-18 17:13:21 Quarantine: Purged MS DirectDraw: All detected items of product - 2014-05-18 17:08:56
[i] 2014-05-18 17:13:21 Quarantine: Purged MS Direct3D: All detected items of product - 2014-05-18 17:08:56
[i] 2014-05-18 17:13:21 Quarantine: Purged Macromedia.FlashPlayer.Cookies: All detected items of product - 2014-05-18 17:08:50
[i] 2014-05-18 17:13:21 Quarantine: Purged Internet Explorer: All detected items of product - 2014-05-18 17:08:55
[-] 2014-05-18 17:13:21 Quarantine: Error purging! ilivid.Toolbar: All detected items of product - 2013-05-20 14:55:47
[i] 2014-05-18 17:13:21 Quarantine: Purged History: All detected items of product - 2014-05-18 17:09:31
[i] 2014-05-18 17:13:21 Quarantine: Purged Cookie: All detected items of product - 2014-05-18 17:08:56
[i] 2014-05-18 17:13:21 Quarantine: Purged Cache: All detected items of product - 2014-05-18 17:09:02
[i] 2014-05-18 17:13:23 Quarantine: Finished purge selected items.
[i] 2014-05-19 17:22:18 Quarantine: Start purge selected items...
[-] 2014-05-19 17:22:21 Quarantine: Error purging! ilivid.Toolbar: All detected items of product - 2013-05-20 14:55:47
[i] 2014-05-19 17:23:54 Quarantine: Finished purge selected items.
[i] 2014-05-19 17:24:11 Quarantine: Start purge selected items...
[-] 2014-05-19 17:24:13 Quarantine: Error purging! ilivid.Toolbar: All detected items of product - 2013-05-20 14:55:47
[i] 2014-05-19 17:24:16 Quarantine: Finished purge selected items.

ken545
2014-05-20, 12:57
See if you can empty the Quarantined items in Safemode, it looks like most of them where purged except for one ilivid, is that one ilivid entry the only one in the Quarantined folder ? if this doesn't work than I am going to ask a spybot helper as there more in tune to the inner workings of spybot than I am


Dont let this scare you , it wont do any damage, its just loads basic windows without all the drivers and what not, its a diagnostic mode , when your done just restart windows normally and you will be right back into regular windows



To Enter Safemode

Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Safemode
Then press the Enter Key on your Keyboard

Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)

candy123
2014-05-20, 19:17
Hi Ken, F8 does nothing. I have tried 4 times now, restart, turn off, and tap like no tomorrow on F8, all I get is a bit of an attempt to go into another window! If that makes sense? Ok the key board is about 13 years old, however, I have no problems with this keyboard, I use my machine quite alot. F8 never!! BTW, I ran spybot rootkit, and it came up with a long list, I went into my computer c drive and found zzz.zz.z when I open the file it is empty, ( there are many files, so I have not opened all)spybot came up with zzz.zz.z ?? It was much easier with the Telegram! Gasp. I hate computers.

Thanks for your time R

ken545
2014-05-20, 19:39
No problem, thats why where here

Not sure what Spybot found, lets double check, still waiting to hear back about purging your Spybot quarantine files


Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

Download Malwarebytes Anti-Rootkit from Here (http://downloads.malwarebytes.org/file/mbar)

Unzip the contents to a folder in a convenient location.
Open the folder where the contents were unzipped and run mbar.exe
Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
Click on the Cleanup button to remove any threats and reboot if prompted to do so.
Wait while the system shuts down and the cleanup process is performed.
Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt

candy123
2014-05-20, 20:18
Sorry it comes up with one file but will not allow me to delete.

ken545
2014-05-20, 21:00
Hi,

You have to understand that I am not sitting in front of your computer with you, I am most likely 1000s of miles away, your my eyes and ears and I can only go by what you tell me, some of your replies are a bit vague.

1. What found one file and wont allow you to delete it....Malwarebytes Anti Rootkit ??????????

2. How is your system behaving now ? Any unwanted pop up windows, any browser redirects to sites that you do not want to go to, if so what browser is the culprit.

ken545
2014-05-21, 02:33
The people at Spybot want to know what version of Spybot do you have installed ?

This is the latest version if you need it
http://www.safer-networking.org/

candy123
2014-05-21, 12:15
Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2013.10.02.12

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Roger :: NOBODY [administrator]

21/05/2014 12:46:07
mbar-log-2014-05-21 (12-46-07).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 209708
Time elapsed: 11 minute(s), 17 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009

(c) Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.658000 GHz
Memory total: 1064550400, free: 267317248

Downloaded database version: v2014.05.20.09
Downloaded database version: v2014.03.27.01
=======================================
Initializing...
Done!
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 2A885AF5

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 488375937
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 250059350016 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-488377168-488397168)...
Done!
Scan finished
=======================================


Removal queue found; removal started
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\VBR-0-0-63-i.mbam...
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009

(c) Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.658000 GHz
Memory total: 1064550400, free: 405786624

=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009

(c) Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.658000 GHz
Memory total: 1064550400, free: 403099648

=======================================
Initializing...
Done!
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 2A885AF5

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 488375937
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 250059350016 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-488377168-488397168)...
Done!
Scan finished
=======================================


Removal queue found; removal started
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\VBR-0-0-63-i.mbam...
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009

(c) Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.658000 GHz
Memory total: 1064550400, free: 162308096

=======================================

ken545
2014-05-21, 15:03
Please read my post # 36 and 37

candy123
2014-05-21, 18:20
Hi Ken, your 36/37 posts were not there when I posted earlier. Ok spybot only picks up ilivid in quarentine one file. It would appear that I'm using spybot 2, I am still unable to go into safe mode, however, have found this. (see below) Is spybot for some reason stopping me from going into safe mode?? Today I got a blue screen with this message. MULTIPLE_IRP_COMPLETE_REQUESTS.

My appoligies if I am vague, but am no expert with computers, I know the basics. Thanks again.

[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

[spybotsd]
timeout.old=30

ken545
2014-05-21, 18:37
Sometimes there is a glitch in the forum, sorry you where having problems reading my post

Right now all we are dealing with is one entry in Spybots Quarantine folder, lets not worry about it, it cant hurt you, what I am more concerned about is that your using a outdated Windows Operating System (WIN XP). Microsoft has discontinued support for XP, it has gone the way of Win 95 and Win 98, you can still use XP but without the support and without Windows Updates to patch security holes in your system its leaving you very vulnerable to infections . If you continue to use XP and go online, I would refrain from doing any online banking or purchases from sites using a credit card.



Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.


Malwarebytes is the free version and yours to keep and will not be removed



How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/index.php?showtopic=57817)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)



Safe Surfn
Ken

candy123
2014-05-21, 22:00
Hi Ken.I know XP is no longer supported, but am reluctant to buy a new machine, this cost's money which I don't have to spend.

I used too use Internet Explorer, but changed to Mozella, today I tried Internet Explorer but it is non responsive, also I have 3 Hotmail accounts, 2, are ok but one is well I can't get my emails, in so far the buttons are missing, like send, like read, and I can't sign out!! Never had this before!

Regards R

ken545
2014-05-21, 23:37
This forum is for Malware Removal only, as far as Internet Explorer or your hotmail accounts, why dont you do this

Your not answering any questions that i ask you and it makes helping you almost impossible

Open an account at

whatthetech.com


Then post in the Browsers Internet forum

http://forums.whatthetech.com/index.php?showforum=123


Hope you find the help you need there

Ken :)