blakloks Posted January 14, 2012 Posted January 14, 2012 I uninstalled firefox from my desktop pc as it was running poorly i then tried to re-install my bt internet software and when i did i could not connect to the internet even though the icons were there, i then tried to system restore but was unable to this either so i now cannot connect to the internet so im not sure if i have a malware problem or not.:confused: Quote
KenB Posted January 15, 2012 Posted January 15, 2012 Hi, i then tried to re-install my bt internet software Was there a problem with this before you removed F_F ? How are you connected ? Wired or wireless ? Are there any other computers in the house and can they connect OK ? Which router are you using. Make and model number please ? This doesn't sound like malware - it is more likely to be a setting on your computer or the router. Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted January 15, 2012 Author Posted January 15, 2012 No I have done that before when i reinstalled firefox previously, firefox had become another search engine i didnt like so uninstalled it again. The desktop pc is wired but there is also a laptop that is wireless and running no problem i am using the BT homehub 2.0 Quote
KenB Posted January 15, 2012 Posted January 15, 2012 laptop that is wireless and running no problem This implies that there is no problem with the BT Homehub settings. Take the ethernet cable and use it to connect the laptop to the BT Homehub. It should connect no problem. If it cannot - then it looks like there is a problem with the ethernet cable. Switch off the Wireless Option on the laptop first - just to make sure. Let me know the results. Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted January 15, 2012 Author Posted January 15, 2012 Ethernet cable is fine just tried it in the laptop with wireless switched off Quote
KenB Posted January 15, 2012 Posted January 15, 2012 OK. Connect the ethernet cable back up to the desktop. Start ....type in ......devmgmt.msc ......ENTER Click the + next to Network Adapters What is listed? Are there any yellow exclamation marks or red Xs ? Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted January 15, 2012 Author Posted January 15, 2012 (edited) Yeah there is 3 yellow exclamation marks mate below network adapters one is at other devices one is at SM bus controller and the other is at Unknown device Edited January 15, 2012 by blakloks Quote
KenB Posted January 16, 2012 Posted January 16, 2012 You don't have the drivers for the NIC installed. What is the make and model number of your pc. I can try to locate them for you. Also let me know the Operating System please. Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted January 17, 2012 Author Posted January 17, 2012 Ok thanks for the info my pc is Fujitsu Siemens scaleo p model and I am running windows XP home. What would have happened to the drivers then as it was working? Quote
KenB Posted January 17, 2012 Posted January 17, 2012 According to the Fujitsu site the drivers for your NIC are embedded in XP. If this is the case then it could be that there is a problem with the card ( it is actually a chip ) itself. The drivers needed are Realtek RTL8139 and it is this that should be showing in Device Manager. Go back to Network Adapters in Device Manager ( devmgmt.msc ) right click on each of the devices with a yellow exclamation mark > uninstall. Re-boot the machine. Windows should locate new hardware and, if the drivers are embedded, should auto install them. If not then the drivers are here: click here Windows XP > click on US1 or US2 Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted January 18, 2012 Author Posted January 18, 2012 ive got my drivers back in i had a disc so many thanks for that. When i click on my icons to get onto the net it says internet explorer encountered a problem with the add on and needs to close!!! So close yet so far:D will i need to uninstall and reinstall Quote
KenB Posted January 18, 2012 Posted January 18, 2012 Can you let me know the exact error message please? Which version of IE are you using ? There should be an option in Tools > Manage Add Ons to turn them off. Do this and try connecting again. Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted January 26, 2012 Author Posted January 26, 2012 Sooty about the late reply I cannot even open Internet explorer it says it encounters a problem with an add on and needs to close and the following add on was running when the problem occurred :File: Wltcore.dllCompany name: MicrosoftDescription. : Windows live toolbar Quote
KenB Posted February 2, 2012 Posted February 2, 2012 Hi, Sorry for missing your last post. Wltcore.dll is linked with Windows Live Toolbar Does Windows Live Toolbar show in Control Panel or Control Panel > Add / Remove From Add / Remove ............which version of IE are you using? Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted February 5, 2012 Author Posted February 5, 2012 I went into add and remove programs but for some bizzare reason Internet explorer does not appear to be visible there so don't know what's happening there mate any ideas? Quote
KenB Posted February 6, 2012 Posted February 6, 2012 Wltcore.dll is linked with Windows Live Toolbar Does Windows Live Toolbar show in Control Panel Is Windows Live Toolbar there? It may be in Add / Remove ..............is it here ? Internet explorer does not appear If you are running IE6 it probably will not show in Add/Remove as it is integrated into the System Files. Updates do show. Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
blakloks Posted February 6, 2012 Author Posted February 6, 2012 i cannot see windows live toolbar there is a windows live upload tool(would that be it??) and another thing in relation to windows but that is it Quote
KenB Posted February 7, 2012 Posted February 7, 2012 windows live upload tool(would that be it??) No - Frustrating !! You don't see IE in Add/Remove ( presumably you have IE6 ) You cannot open IE There is a Fix-It here: click here Click the Run Now button This fixes defective add-ons and a lot more. Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
Starbuck Posted February 7, 2012 Posted February 7, 2012 You don't see IE in Add/Remove ( presumably you have IE6 ) If you are running IE6, then it's a good bet that your copy of Windows is missing a lot of updates. The IE updates will have come as a default install along with the Windows updates. Are your Windows updates turned off? Quote Member of:UNITE
blakloks Posted February 14, 2012 Author Posted February 14, 2012 windows updates are on. How do i get that ie repair from my laptop onto the problem pc if i cant connect to the net? I put the drivers and utilities disk and avg detected a threat which i could not vault as it was in the optical drive!!!!! Quote
Starbuck Posted February 14, 2012 Posted February 14, 2012 When i used BT HomeHub in the past, i never installed any of their software. It's not needed anyway. (most of it is bloatware anyway) Any system using an ethernet cable will work without the software. Although IE may not be connecting.... you may still have a connection. Will your AV update? or if you have something like MBAM on your system.... will that update? To make things easier, why not download another browser to see if it will connect using that? Opera is a firm favourite. You can download it to the laptop. Save it to the desktop. Then transfer it by way of usb stick or disc to the other system. When installing it, if it asks if you want to transfer your IE settings..... click No. Quote Member of:UNITE
blakloks Posted February 19, 2012 Author Posted February 19, 2012 When i used BT HomeHub in the past, i never installed any of their software. It's not needed anyway. (most of it is bloatware anyway) Any system using an ethernet cable will work without the software. Although IE may not be connecting.... you may still have a connection. Will your AV update? or if you have something like MBAM on your system.... will that update? To make things easier, why not download another browser to see if it will connect using that? Opera is a firm favourite. You can download it to the laptop. Save it to the desktop. Then transfer it by way of usb stick or disc to the other system. When installing it, if it asks if you want to transfer your IE settings..... click No. I downloaded firefox onto a flash drive and put it on the desktop PC worked a treat mate the only thing is that sometimes it says local area network connection not connected for the first 5 minutes at leasts its up and running now thanks for all the help guys!!! Quote
Starbuck Posted February 19, 2012 Posted February 19, 2012 at leasts its up and running now thanks for all the help guys!!! Now it's up and running, it may be as well to check out your system for a possible cause. Download OTL to your desktop. right click on the link and select 'Save Link/Target As'. if you have problems, try this download link: OTL Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. When the window appears, underneath Output at the top change it to Minimal Output. Check the boxes beside LOP Check and Purity Check. . http://img.photobucket.com/albums/v708/starbuck50/new/Otllatest.png Now copy the lines in bold below. netsvcs msconfig %SYSTEMDRIVE%\*.* %systemroot%\system32\Spool\prtprocs\w32x86\*.dll %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\system32\*.exe /lockedfiles %systemroot%\System32\config\*.sav %PROGRAMFILES%\* %USERPROFILE%\..|smtmp;true;true;true /FP HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU hklm\software\clients\startmenuinternet|command /rs hklm\software\clients\startmenuinternet|command /64 /rs CREATERESTOREPOINT right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste. http://img.photobucket.com/albums/v708/starbuck50/new%20forum/scan-fix.png . Click the Run Scan button. http://img.photobucket.com/albums/v708/starbuck50/runscan.png Do not change any settings unless otherwise told to do so. The scan wont take long. When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply. Thanks Quote Member of:UNITE
blakloks Posted February 20, 2012 Author Posted February 20, 2012 (edited) this from otl notepad: OTL logfile created on: 20/02/2012 19:17:21 - Run 1 OTL by OldTimer - Version 3.2.33.1 Folder = C:\Documents and Settings\Jasper\My Documents\Downloads Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 2.00 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 67.52% Memory free 3.85 Gb Paging File | 3.37 Gb Available in Paging File | 87.57% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 232.88 Gb Total Space | 202.34 Gb Free Space | 86.89% Space Free | Partition Type: NTFS Drive F: | 3.74 Gb Total Space | 3.66 Gb Free Space | 97.94% Space Free | Partition Type: FAT32 Computer Name: HOME-86DCE43013 | User Name: Jasper | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Jasper\My Documents\Downloads\OTL(1).exe (OldTimer Tools) PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe () PRC - C:\Program Files\AVG Secure Search\vprot.exe () PRC - C:\Documents and Settings\Jasper\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc) PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe () PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (iMesh, Inc) PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.) PRC - C:\Program Files\Lexmark 4300 Series\lxcemon.exe (Lexmark International, Inc.) PRC - C:\WINDOWS\system32\lxcecoms.exe (Lexmark International, Inc.) PRC - C:\Program Files\Lexmark 4300 Series\ezprint.exe () PRC - C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw)) ========== Modules (No Company Name) ========== MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe () MOD - C:\Program Files\AVG Secure Search\vprot.exe () MOD - c:\Program Files\Common Files\Akamai\netsession_win_7de0ed9.dll () MOD - C:\WINDOWS\system32\quartz.dll () MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll () MOD - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe () MOD - C:\WINDOWS\system32\sbe.dll () MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\WINDOWS\system32\msdmo.dll () MOD - C:\WINDOWS\system32\devenum.dll () MOD - C:\WINDOWS\system32\LXPRMON.DLL () MOD - C:\Program Files\Lexmark 4300 Series\lxcecnv4.dll () MOD - C:\Program Files\Lexmark 4300 Series\ezprint.exe () ========== Win32 Services (SafeList) ========== SRV - (vToolbarUpdater) -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe () SRV - (Akamai) -- c:\program files\common files\akamai/netsession_win_7de0ed9.dll () SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.) SRV - (AVG Security Toolbar Service) -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe () SRV - (GoToAssist) -- C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.) SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.) SRV - (avgwd) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (lxce_device) -- C:\WINDOWS\System32\lxcecoms.exe (Lexmark International, Inc.) ========== Driver Services (SafeList) ========== DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. ) DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.) DRV - (Avgrkx86) -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.) DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AVGIDSEH) -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. ) DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. ) DRV - (AVGIDSFilter) -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. ) DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.) DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation) DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation ) DRV - (cmpci) C-Media PCI Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/ IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/ IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/cs/*http://uk.docs.yahoo.com/info/bt_side.html IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://bt.yahoo.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb&sysid=2 IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.google.com/" FF - prefs.js..extensions.enabledItems: avg@igeared:7.005.030.004 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: 2020Player@2020Technologies.com:4.5.2.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220 FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0 FF - prefs.js..extensions.enabledItems: {28387537-e3f9-4ed7-860c-11e69af4a8a0}:4.1.0.00 FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2 FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2 FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.3.3.2 FF - prefs.js..extensions.enabledItems: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}:4.1.0.00 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..keyword.URL: "http://search.imesh.com/web?src=ffb&systemid=1&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2012/02/18 14:47:00 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2012/02/19 15:20:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/11/25 20:10:24 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.0.0.7\ [2012/02/20 13:45:56 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/19 19:28:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/20 12:03:23 | 000,000,000 | ---D | M] [2006/02/25 23:59:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Extensions [2012/02/18 15:28:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\extensions [2011/02/03 18:10:00 | 000,000,000 | ---D | M] (MediaBar) -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0} [2011/04/11 14:56:35 | 000,000,000 | ---D | M] (MediaBar) -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} [2010/12/21 11:56:29 | 000,000,000 | ---D | M] (20-20 3D Viewer) -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\extensions\2020Player@2020Technologies.com [2011/06/15 16:27:18 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\extensions\engine@conduit.com [2011/09/30 11:21:28 | 000,002,613 | ---- | M] () -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\searchplugins\askcom.xml [2010/09/14 12:48:25 | 000,002,506 | ---- | M] () -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\searchplugins\BearShareWebSearch.xml [2010/09/02 08:09:28 | 000,002,486 | ---- | M] () -- C:\Documents and Settings\Jasper\Application Data\Mozilla\Firefox\Profiles\g9thydj2.default\searchplugins\iMeshWebSearch.xml [2012/02/18 15:27:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/02/20 13:45:56 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\10.0.0.7\ [2010/10/19 11:32:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2012/02/19 19:28:33 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011/02/02 20:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012/02/08 17:50:00 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml [2012/02/20 13:45:45 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml [2010/09/14 12:48:25 | 000,002,506 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml [2012/02/08 17:21:19 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/02/08 17:50:00 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml [2012/02/08 17:50:00 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml [2010/09/02 08:09:28 | 000,002,486 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\iMeshWebSearch.xml [2012/02/08 17:50:00 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml O1 HOSTS File: ([2004/08/10 19:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\imeshdtxmltbpi.dll () O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\MediaBar\Datamngr\IEBHO.dll (iMesh, Inc) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found. O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll () O2 - BHO: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found. O3 - HKLM\..\Toolbar: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\imeshdtxmltbpi.dll () O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found. O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw)) O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (iMesh, Inc) O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 4300 Series\ezprint.exe () O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe () O4 - HKLM..\Run: [LXCECATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.DLL () O4 - HKLM..\Run: [lxcemon.exe] C:\Program Files\Lexmark 4300 Series\lxcemon.exe (Lexmark International, Inc.) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [ROC_roc_dec12] C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe () O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe () O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Jasper\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc) O4 - Startup: C:\Documents and Settings\Jasper\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme () O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6407C1E3-3E20-47F4-88E6-0C74EF45D788}: DhcpNameServer = 192.168.1.254 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll () O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\datamngr.dll) - C:\Program Files\iMesh Applications\MediaBar\Datamngr\datamngr.dll (iMesh, Inc) O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll) - C:\Program Files\iMesh Applications\MediaBar\Datamngr\IEBHO.dll (iMesh, Inc) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\570\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\Jasper\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jasper\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011/04/07 20:13:05 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ] O32 - AutoRun File - [2006/02/25 23:36:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2011/03/22 15:07:56 | 000,000,000 | ---D | M] - F:\AUTOCAD -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 0 MsConfig - State: "startup" - 0 CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012/02/18 15:38:15 | 000,000,000 | ---D | C] -- C:\37b7bbde4b59dd63d7a8a55834f6cc3a [2012/02/18 15:33:10 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Jasper\Recent [2012/02/18 14:47:30 | 000,000,000 | ---D | C] -- C:\Program Files\ConduitEngine [2012/02/18 14:47:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jasper\Local Settings\Application Data\ConduitEngine [2012/02/18 14:47:30 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit [2012/02/18 14:47:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jasper\Local Settings\Application Data\Conduit [2012/02/14 19:26:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jasper\Application Data\ElevatedDiagnostics [2012/02/14 19:25:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell [2012/02/14 19:16:34 | 000,000,000 | ---D | C] -- C:\$AVG [2012/02/04 13:33:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache [2006/02/25 23:57:32 | 000,022,600 | ---- | C] () -- C:\Documents and Settings\Jasper\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2006/02/25 23:54:50 | 006,410,196 | -H-- | C] () -- C:\Documents and Settings\Jasper\Local Settings\Application Data\IconCache.db [33 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/02/20 18:22:42 | 089,557,944 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm [2012/02/20 18:02:09 | 000,253,748 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2012/02/20 18:01:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/02/20 12:03:24 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk [2012/02/19 15:20:08 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk [2012/02/18 16:29:07 | 000,502,098 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/02/18 16:29:07 | 000,096,394 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/02/18 16:21:20 | 000,134,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/02/18 16:16:00 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012/02/18 15:28:03 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Jasper\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2012/02/18 15:28:03 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2012/02/18 14:20:02 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [33 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/02/20 12:03:24 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk [2012/02/20 12:03:24 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk [2012/02/18 15:33:53 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK [2012/02/18 15:28:03 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2012/02/16 19:59:16 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012/02/16 19:59:16 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll [2011/04/12 11:24:45 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2011/04/07 21:24:47 | 000,431,744 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat [2011/02/03 19:02:10 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll [2010/11/04 16:10:49 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2010/10/06 11:37:52 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Jasper\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/10/05 15:19:51 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Jasper\Local Settings\Application Data\fusioncache.dat [2010/10/05 10:41:49 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXPRMON.DLL [2010/10/05 10:41:49 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\LXPMONUI.DLL [2010/10/05 10:39:06 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcevs.dll [2010/10/04 17:57:38 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini ========== LOP Check ========== [2011/04/11 14:56:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1E35B [2011/09/28 18:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk [2012/02/18 14:47:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search [2011/02/03 18:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar [2012/01/26 19:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10 [2011/09/28 17:50:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess [2011/05/13 08:06:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files [2011/11/25 20:10:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData [2010/10/06 13:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2011/01/20 16:55:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\Amazon [2011/04/07 20:45:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\Autodesk [2010/10/04 15:56:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\AVG10 [2012/02/14 19:26:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\ElevatedDiagnostics [2011/02/04 13:09:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\FrostWire [2011/02/27 19:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\GARMIN [2010/10/13 13:34:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\GetRightToGo [2011/02/03 18:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\imeshbandmltbpi [2011/07/07 09:01:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\LibreOffice [2011/04/11 14:56:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\mediabarbs [2011/02/03 18:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\mediabarim [2010/10/04 16:00:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\MSNInstaller [2011/05/27 11:10:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\OpenOffice.org [2011/02/28 10:19:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\SmartDraw [2010/10/13 13:25:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\SystemRequirementsLab [2012/02/18 15:03:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\uTorrent ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2006/02/25 23:36:32 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2010/10/12 14:40:07 | 000,000,209 | -HS- | M] () -- C:\boot.ini [2010/10/05 10:38:49 | 000,000,242 | ---- | M] () -- C:\CDFE.log [2006/02/25 23:36:32 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2006/02/25 23:36:32 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2012/01/15 18:24:07 | 000,000,811 | ---- | M] () -- C:\lxce.log [2010/10/05 10:38:46 | 000,000,000 | ---- | M] () -- C:\lxcefire.csv [2010/10/05 10:39:25 | 000,000,291 | ---- | M] () -- C:\LXCEINST.csv [2006/02/25 23:36:32 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2004/08/10 19:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2010/10/11 14:54:25 | 000,250,048 | RHS- | M] () -- C:\ntldr [2012/02/20 18:01:48 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll > [2008/07/06 12:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll [2005/03/08 02:09:24 | 000,073,728 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\lxcePP5C.DLL < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\system32\*.exe /lockedfiles > [2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < %systemroot%\System32\config\*.sav > [2006/02/25 23:17:58 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2006/02/25 23:17:58 | 000,659,456 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2006/02/25 23:17:58 | 000,901,120 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %PROGRAMFILES%\* > < %USERPROFILE%\..|smtmp;true;true;true /FP > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU > < hklm\software\clients\startmenuinternet|command /rs > HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/02/19 19:28:29 | 000,834,832 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/02/19 19:28:29 | 000,834,832 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/02/19 19:28:29 | 000,834,832 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/02/19 19:28:33 | 000,924,632 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/02/19 19:28:33 | 000,924,632 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/02/19 19:28:33 | 000,924,632 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2008/04/14 00:12:35 | 000,045,056 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2008/04/14 00:12:35 | 000,045,056 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2008/04/14 00:12:35 | 000,045,056 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "%programfiles%\Internet Explorer\iexplore.exe" [2008/04/14 00:12:22 | 000,093,184 | ---- | M] (Microsoft Corporation) < hklm\software\clients\startmenuinternet|command /64 /rs > HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/02/19 19:28:29 | 000,834,832 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/02/19 19:28:29 | 000,834,832 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/02/19 19:28:29 | 000,834,832 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/02/19 19:28:33 | 000,924,632 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/02/19 19:28:33 | 000,924,632 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/02/19 19:28:33 | 000,924,632 | ---- | M] (Mozilla Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2008/04/14 00:12:35 | 000,045,056 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2008/04/14 00:12:35 | 000,045,056 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2008/04/14 00:12:35 | 000,045,056 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "%programfiles%\Internet Explorer\iexplore.exe" [2008/04/14 00:12:22 | 000,093,184 | ---- | M] (Microsoft Corporation) < End of report > This is from extras txt: OTL Extras logfile created on: 20/02/2012 19:17:21 - Run 1 OTL by OldTimer - Version 3.2.33.1 Folder = C:\Documents and Settings\Jasper\My Documents\Downloads Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 2.00 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 67.52% Memory free 3.85 Gb Paging File | 3.37 Gb Available in Paging File | 87.57% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 232.88 Gb Total Space | 202.34 Gb Free Space | 86.89% Space Free | Partition Type: NTFS Drive F: | 3.74 Gb Total Space | 3.66 Gb Free Space | 97.94% Space Free | Partition Type: FAT32 Computer Name: HOME-86DCE43013 | User Name: Jasper | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 "1050:TCP" = 1050:TCP:*:Enabled:Akamai NetSession Interface "5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh "C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare "C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.) "C:\Documents and Settings\Jasper\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\Jasper\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Interface -- (Akamai Technologies, Inc) "C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer "{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java 6 Update 29 "{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java 6 Update 22 "{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant "{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail "{73AA12E1-5FFD-4545-9A28-CE7C318F284E}" = AVG 2011 "{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{82AF3E91-57E1-4754-84D0-40A46E2479AB}" = OpenOffice.org 3.3 "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011 "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser "{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0 "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint "{ADD72094-D289-4714-A62E-70574478A2BC}" = System Requirements Lab for Intel "{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync "{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support "{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{DA898F5C-4C85-4CF4-825B-E05D07DC39DD}" = BT Broadband Support Tools "{DAB5C521-80B2-48C3-B0DA-326A1B331F55}" = GoToAssist Corporate "{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support "{E533E637-FB3E-4F28-8B18-449CC9AB7235}" = AVG 2011 "{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime "{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Akamai" = Akamai NetSession Interface Service "Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9 "AVG" = AVG 2011 "BT Wireless Connection Manager" = BT Wireless Connection Manager "BT Yahoo! Applications" = BT Yahoo! Applications "CCleaner" = CCleaner "conduitEngine" = Conduit Engine "GoToAssist" = GoToAssist Corporate "iMesh 1 MediaBar" = MediaBar "Lexmark 4300 Series" = Lexmark 4300 Series "Lexmark Fax Solutions" = Lexmark Fax Solutions "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MSNINST" = MSN "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NVIDIA Drivers" = NVIDIA Drivers "PCI Audio Driver" = PCI Audio Driver "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR 4.01 (32-bit) "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Toolbar" = Yahoo! Toolbar ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 03/02/2011 14:58:07 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module wltcore.dll, version 14.0.8117.416, fault address 0x0001f4ce. Error - 03/02/2011 14:58:08 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module wltcore.dll, version 14.0.8117.416, fault address 0x0001f4ce. Error - 03/02/2011 14:58:08 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module wltcore.dll, version 14.0.8117.416, fault address 0x0001f4ce. Error - 03/02/2011 14:58:11 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module wltcore.dll, version 14.0.8117.416, fault address 0x0001f4ce. Error - 03/02/2011 14:58:23 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1001 Description = Fault bucket 1863732553. Error - 03/02/2011 14:58:28 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1001 Description = Fault bucket 1863732553. Error - 03/02/2011 14:58:35 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1001 Description = Fault bucket 1863732553. Error - 03/02/2011 18:32:00 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module wltcore.dll, version 14.0.8117.416, fault address 0x0001f4ce. Error - 03/02/2011 18:32:10 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1001 Description = Fault bucket 1863732553. Error - 05/02/2011 12:10:39 | Computer Name = HOME-86DCE43013 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module wltcore.dll, version 14.0.8117.416, fault address 0x0002060b. [ System Events ] Error - 18/01/2012 16:38:08 | Computer Name = HOME-86DCE43013 | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout. Error - 18/01/2012 16:40:28 | Computer Name = HOME-86DCE43013 | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout. Error - 04/02/2012 09:33:10 | Computer Name = HOME-86DCE43013 | Source = Service Control Manager | ID = 7011 Description = Timeout (30000 milliseconds) waiting for a transaction response from the Akamai service. Error - 06/02/2012 15:25:55 | Computer Name = HOME-86DCE43013 | Source = Windows Update Agent | ID = 16 Description = Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. Error - 06/02/2012 15:35:00 | Computer Name = HOME-86DCE43013 | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout. Error - 14/02/2012 16:13:37 | Computer Name = HOME-86DCE43013 | Source = Service Control Manager | ID = 7011 Description = Timeout (30000 milliseconds) waiting for a transaction response from the Akamai service. Error - 18/02/2012 11:18:33 | Computer Name = HOME-86DCE43013 | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout. Error - 18/02/2012 12:22:39 | Computer Name = HOME-86DCE43013 | Source = Service Control Manager | ID = 7011 Description = Timeout (30000 milliseconds) waiting for a transaction response from the Akamai service. Error - 18/02/2012 12:25:10 | Computer Name = HOME-86DCE43013 | Source = DCOM | ID = 10010 Description = The server {33D8C85A-B8C1-4828-B51A-4F3349AD5F9E} did not register with DCOM within the required timeout. Error - 20/02/2012 14:11:16 | Computer Name = HOME-86DCE43013 | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout. < End of report > That might aswell be in another language for me haha Edited February 20, 2012 by blakloks Quote
Starbuck Posted February 20, 2012 Posted February 20, 2012 Hi blakloks I think we can safely say that the cause of your problems is due to P2P programs. Bearshare, Frostwire, U Torrent etc. Although these are not showing in the uninstall list now.... you still get the warning! P2P Warning Please note that as long as you're using any form of Peer-to-Peer networking ( Frostwire, Limewire, Bit Torrent etc.) and downloading files from non-documented sources, you can expect infestations of malware to occur. Once upon a time, P2P file sharing was fairly safe. That is no longer true. P2P programmes form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P programme is not configured correctly you may be sharing more files than you realise. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured programme. Many of the programmes come bundled with other unwanted programmes, but even the ones free of any bundled software are not safe to use. When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections. You may decide to continue P2P sharing, but keep in mind that this practice may be the source of future malware infestation. If we clean your computer of infection, and you return to us a short time later with an infection contracted by the use of P2P programmes, we may refuse to help you. You also have some dodgy BHO and Toolbars, these are normally added by the P2P programs. We'll clean those up along with a bunch of 'Orphan Entries'. Step 1 Double click on OTL to run it. Copy the lines in the codebox below. (make sure that :Otl is on the first line ) :Otl IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar....rc=ssb&sysid=2 IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found [2010/09/14 12:48:25 | 000,002,506 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml [2010/09/02 08:09:28 | 000,002,486 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\iMeshWebSearch.xml O2 - BHO: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\imeshdtxmltbpi.dll () O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\MediaBar\Datamngr\IEBHO.dll (iMesh, Inc) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found. O2 - BHO: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found. O3 - HKLM\..\Toolbar: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\imeshdtxmltbpi.dll () O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (iMesh, Inc) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.) O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\datamngr.d ll) - C:\Program Files\iMesh Applications\MediaBar\Datamngr\datamngr.dll (iMesh, Inc) O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll) - C:\Program Files\iMesh Applications\MediaBar\Datamngr\IEBHO.dll (iMesh, Inc) [2011/02/04 13:09:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\FrostWire [2012/02/18 15:03:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jasper\Application Data\uTorrent :Files C:\Program Files\BearShare Applications C:\Program Files\FrostWire C:\Program Files\iMesh Applications ipconfig /flushdns /c :commands [emptytemp] [purity] [RESETHOSTS] Return to OTL, right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste. http://img.photobucket.com/albums/v708/starbuck50/new%20forum/scan-fix.png Click the red Run Fix button. http://img.photobucket.com/albums/v708/starbuck50/runfixbutton.png OTL will reboot your system once the fix has completed. After the reboot, you may need to double click OTL to launch the program and retrieve the log. Copy and paste the contents of the OTL log that comes up after the fix in your next reply. if you lose the report, there will be a copy here: C:\_OTL\MovedFiles Step 2 I'd like you to do an ESET OnlineScan You may find it beneficial to close your resident AV program before running the scan. Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop. Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop. [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png [*]Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button. [*]Accept any security warnings from your browser. [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png [*]Click the Start button. [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. [*]When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png [*]Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. [*]Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button. [*]Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Note: It's been found that on some systems the Eset's Online Scan fails during the database download ( around 20% ) To prevent this happening: When the Computer scan settings display shows, click the Advanced option, the place a check next to the following (if it is not already checked): Enable Anti-Stealth technology http://img.photobucket.com/albums/v708/starbuck50/eset.png Step 3 Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:Download the latest version of Java Runtime Environment (JRE) 7 Update 3 and save it to your desktop. Scroll down to where it says "Java SE 7 Update 3". Click the "Download JRE" button to the right. Accept the license agreement. select 'Windows x86'offline from the list. Save the file to your desktop. Close any programs you may have running - especially your web browser. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions. . Java 6 Update 29 Java 6 Update 22 J2SE Runtime Environment 5.0 Update 6 . Reboot your computer once all Java components are removed. Then from your desktop double-click on jre-7u3-windows-i586-p.exe to install the newest version. In your next reply, please submit: Otl fix report Eset scan report Thanks. Quote Member of:UNITE
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.