Hi Broni
It is looking better no question in that some of the functionality like the firewall, MS Update etc are now saying the work etc, but interestingly the computer seemed to run well (speed-wise) even with the viruses - I suspect these have been on the computer for several weeks unoticed by my daughter until I looked at the machine and noticed no antivirus icon in the task tray.
There are still things no doubt that are still affected - when I boot with the Malwarebytes active, its comes up each time with a site or two, the last saying "successfully blocked access to potentially malicious website 193.169.86.56, outgoing port 49166 svchost.exe.
I guess I'll feel more comforatble when I can create a restore disk successfully and get an antiviris loaded and working once it has been cleaned the best we can.
Anyhow, thanks so much for sticking with me, and below are the OTL and Extras reports requested, ssplit into 2 parts due to the character limit.
Cheers, Phil
OTL logfile created on: 6/10/2012 6:39:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Alison\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.99 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 49.43% Memory free
4.21 Gb Paging File | 3.14 Gb Available in Paging File | 74.44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 104.33 Gb Total Space | 48.62 Gb Free Space | 46.61% Space Free | Partition Type: NTFS
Computer Name: ALISON-PC | User Name: Alison | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/10/06 18:37:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alison\Desktop\OTL.exe
PRC - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/06/14 11:38:56 | 027,595,032 | ---- | M] (Dropbox, Inc.) -- C:\Users\Alison\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/05/10 14:16:48 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/10/29 15:59:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/08/26 15:07:04 | 000,091,648 | ---- | M] () -- C:\Windows\System32\SupportAppXL\AutoDect.exe
PRC - [2008/01/29 20:21:52 | 004,911,104 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/01/22 13:25:26 | 000,712,704 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2008/01/21 15:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/01/17 15:27:52 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2008/01/17 15:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2008/01/10 07:32:08 | 001,056,768 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2007/12/26 06:37:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2007/12/26 06:36:52 | 000,405,504 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2007/12/03 16:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
PRC - [2007/11/22 10:53:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2007/06/15 20:01:58 | 000,448,080 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
PRC - [2006/10/05 13:40:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2006/08/23 15:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (No Company Name) ==========
MOD - [2012/08/27 21:33:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/08/27 21:33:08 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012/05/10 14:16:44 | 001,952,696 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2009/07/18 12:51:00 | 003,883,424 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2008/08/26 15:07:04 | 000,091,648 | ---- | M] () -- C:\Windows\System32\SupportAppXL\AutoDect.exe
MOD - [2007/12/25 11:03:40 | 000,015,184 | ---- | M] () -- C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll
MOD - [2007/12/14 20:40:00 | 000,090,112 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\TWarnMsg\TWarnMsg.dll
MOD - [2007/12/14 20:28:38 | 004,726,784 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
MOD - [2007/09/13 15:41:18 | 000,249,856 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll
MOD - [2006/10/11 05:14:16 | 000,009,728 | ---- | M] () -- C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll
MOD - [2006/10/08 05:27:04 | 000,053,248 | ---- | M] () -- C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll
========== Services (SafeList) ==========
SRV - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/05/10 14:16:50 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/03/14 21:57:33 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/06/13 21:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2008/04/07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/01/21 15:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/01/21 11:53:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/17 15:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/26 06:37:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007/12/03 16:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/22 10:53:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/10/29 23:35:40 | 000,937,984 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2006/10/05 13:40:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006/08/23 15:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Alison\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/06/23 08:21:32 | 000,259,176 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/05/11 09:04:34 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/04/28 07:44:56 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/04/28 07:44:54 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/04/28 07:44:42 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/04/28 07:44:34 | 000,009,728 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2008/07/29 04:05:04 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/01/21 14:42:24 | 000,285,184 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tos_sps32.sys -- (tos_sps32)
DRV - [2007/11/09 13:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/09/17 14:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/08/31 16:43:32 | 000,020,352 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2006/11/28 16:41:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/21 07:41:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/10/19 05:20:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3201318
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\..\SearchScopes,DefaultScope = {CCC7A320-B3CA-4199-B1A6-9F516DD69829}
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3201318
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" =
http://search.avg.com/?d=4d609404&I=23&tp=chrome&q={searchTerms}&lng={language}&nt=1
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "MakeMeBabies 2.0 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.conduit.com/ResultsExt.aspx?ctid=CT3027459&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "MakeMeBabies 2.0 Customized Web Search"
FF - prefs.js..browser.startup.homepage: "
http://search.conduit.com/?ctid=CT3027459&SearchSource=13"
FF - prefs.js..extensions.enabledAddons: {9E2C191D-C57A-11E1-8270-B8AC6F996F26}:2.0.14
FF - prefs.js..extensions.enabledAddons: {d4330680-c0ae-4226-8a21-0afe2fd1ac24}:3.15.1.0
FF - prefs.js..extensions.enabledAddons: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.2.2
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1410
FF - prefs.js..keyword.URL: "
http://search.avg.com/?d=4d609352&I=23&tp=ab&nt=1&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/10 14:16:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/10 09:11:28 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{9E2C191D-C57A-11E1-8270-B8AC6F996F26}: C:\Users\Alison\AppData\Local\{9E2C191D-C57A-11E1-8270-B8AC6F996F26}\ [2012/07/04 11:20:24 | 000,000,000 | ---D | M]
[2009/07/18 10:59:57 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Alison\AppData\Roaming\Mozilla\Extensions
[2012/09/28 22:08:52 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Alison\AppData\Roaming\Mozilla\Firefox\Profiles\a12r84fu.default\extensions
[2012/08/27 17:37:32 | 000,000,000 | ---D | M] (MakeMeBabies 2.0 Community Toolbar) -- C:\Users\Alison\AppData\Roaming\Mozilla\Firefox\Profiles\a12r84fu.default\extensions\{d4330680-c0ae-4226-8a21-0afe2fd1ac24}
[2012/03/24 18:24:13 | 000,020,591 | -H-- | M] () (No name found) -- C:\Users\Alison\AppData\Roaming\Mozilla\Firefox\Profiles\a12r84fu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/09/28 22:08:52 | 001,268,546 | ---- | M] () (No name found) -- C:\Users\Alison\AppData\Roaming\Mozilla\Firefox\Profiles\a12r84fu.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
[2012/04/05 13:35:34 | 000,000,935 | ---- | M] () -- C:\Users\Alison\AppData\Roaming\Mozilla\Firefox\Profiles\a12r84fu.default\searchplugins\conduit.xml
[2011/11/13 20:01:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/07/04 11:20:24 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\ALISON\APPDATA\LOCAL\{9E2C191D-C57A-11E1-8270-B8AC6F996F26}
[2012/05/10 14:16:48 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/05/10 14:16:41 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/03/24 18:19:35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/05/10 14:16:41 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/05/10 14:16:41 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/05/10 14:16:50 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/05/10 14:16:41 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2012/10/04 03:17:22 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (FLV Runner Toolbar) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (FLV Runner Toolbar) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\..\Toolbar\WebBrowser: (FLV Runner Toolbar) - {3BBD3C14-4C16-4989-8366-95BC9179779D} - C:\Program Files\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [autodetect] C:\Windows\System32\SupportAppXL\AutoDect.exe ()
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Alison\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Alison\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-3856432456-3556964881-2861625783-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 203.12.160.35 203.12.160.36
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BE5C39F8-23C8-4A19-A0B0-BC23C74B7A48}: DhcpNameServer = 203.12.160.35 203.12.160.36
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DEB86AD1-BDE7-408B-A121-1BF279B5B29C}: DhcpNameServer = 203.12.160.35 203.12.160.36
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Alison\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Alison\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/10/06 18:36:55 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Alison\Desktop\OTL.exe
[2012/10/06 01:14:43 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/10/06 01:14:42 | 000,000,000 | ---D | C] -- C:\Users\Alison\AppData\Local\temp
[2012/10/06 01:12:54 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/10/06 00:20:46 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/10/05 22:48:52 | 004,762,471 | R--- | C] (Swearware) -- C:\Users\Alison\Desktop\ComboFix.exe
[2012/10/05 00:31:38 | 000,000,000 | ---D | C] -- C:\Users\Alison\Desktop\RK_Quarantine
[2012/10/05 00:20:43 | 000,000,000 | ---D | C] -- C:\Users\Alison\Desktop\tdsskiller
[2012/10/04 14:18:05 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/10/04 03:19:45 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/10/04 02:30:18 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/10/04 02:30:18 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/10/04 02:30:18 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/10/04 02:28:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/04 02:26:45 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/10/01 17:18:39 | 000,905,740 | ---- | C] (Farbar) -- C:\Users\Alison\Desktop\FRST.exe
[2012/10/01 17:18:39 | 000,607,260 | ---- | C] (Swearware) -- C:\Users\Alison\Desktop\dds.com
[2012/10/01 17:18:31 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Alison\Desktop\mbam-setup-1.65.0.1400.exe
[2012/10/01 17:18:04 | 000,000,000 | ---D | C] -- C:\Users\Alison\Desktop\Attempt1
[2012/10/01 09:35:09 | 000,000,000 | ---D | C] -- C:\Users\Alison\AppData\Roaming\Malwarebytes
[2012/10/01 09:34:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/01 09:34:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/10/01 09:34:43 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/10/01 09:34:43 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/09/28 19:01:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/09/28 19:00:24 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/09/28 19:00:18 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/09/28 18:53:18 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/09/28 16:27:11 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Photo Creations
[2012/09/28 16:27:11 | 000,000,000 | ---D | C] -- C:\Program Files\HP Photo Creations
[2012/09/28 16:26:01 | 000,000,000 | ---D | C] -- C:\Users\Alison\AppData\Roaming\HpUpdate
[2012/09/28 16:25:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2012/09/28 16:23:23 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2012/09/28 16:22:57 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2012/09/28 16:22:06 | 000,000,000 | ---D | C] -- C:\Users\Alison\AppData\Local\HP
[2012/09/17 19:25:14 | 002,212,440 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Alison\Desktop\TDSSKiller.exe
[2010/05/28 16:50:23 | 097,547,048 | ---- | C] (Apple Inc.) -- C:\Users\Alison\iTunesSetup.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/06 18:41:32 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F286256D-BAC5-40C4-B58B-2459DA730926}.job
[2012/10/06 18:37:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alison\Desktop\OTL.exe
[2012/10/06 18:29:40 | 000,600,770 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/10/06 18:29:40 | 000,106,244 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/10/06 18:25:32 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/06 18:25:32 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/06 18:25:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/06 18:25:16 | 2136,969,216 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/06 00:01:01 | 000,000,258 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Messager.job
[2012/10/05 22:49:43 | 004,762,471 | R--- | M] (Swearware) -- C:\Users\Alison\Desktop\ComboFix.exe
[2012/10/05 10:07:08 | 002,212,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Alison\Desktop\TDSSKiller.exe
[2012/10/05 00:30:14 | 001,422,336 | ---- | M] () -- C:\Users\Alison\Desktop\RogueKiller.exe
[2012/10/05 00:20:20 | 002,193,278 | ---- | M] () -- C:\Users\Alison\Desktop\tdsskiller.zip
[2012/10/04 03:19:45 | 240,088,771 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/10/04 03:17:22 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/10/01 17:04:51 | 000,905,740 | ---- | M] (Farbar) -- C:\Users\Alison\Desktop\FRST.exe
[2012/10/01 17:02:37 | 000,607,260 | ---- | M] (Swearware) -- C:\Users\Alison\Desktop\dds.com
[2012/10/01 17:01:40 | 000,302,592 | ---- | M] () -- C:\Users\Alison\Desktop\Gmerrbhhj6er.exe
[2012/10/01 17:00:40 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Alison\Desktop\mbam-setup-1.65.0.1400.exe
[2012/10/01 13:49:24 | 000,117,168 | ---- | M] () -- C:\Users\Alison\Desktop\recdisc_x86.zip
[2012/10/01 11:17:31 | 000,002,311 | ---- | M] () -- C:\Users\Alison\Desktop\[Active] - Read Instructions - but cannot access antivirus sites for Step 1 - TechSpot Forums#post-1236488#post-1236488.url
[2012/10/01 09:34:45 | 000,000,951 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/29 15:55:07 | 000,173,056 | ---- | M] () -- C:\Users\Alison\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/29 11:52:53 | 000,002,305 | ---- | M] () -- C:\Users\Alison\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2012/09/29 11:21:03 | 000,002,651 | ---- | M] () -- C:\Users\Alison\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2012/09/28 19:01:47 | 000,001,709 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/09/28 18:54:33 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2012/09/28 16:27:19 | 000,001,833 | ---- | M] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk
[2012/09/28 16:25:45 | 000,002,160 | ---- | M] () -- C:\Users\Public\Desktop\HP Photosmart 7510 series.lnk
[2012/09/28 16:25:45 | 000,001,128 | ---- | M] () -- C:\Users\Public\Desktop\Shop for Supplies - HP Photosmart 7510 series.lnk
[2012/09/28 16:25:44 | 000,001,795 | ---- | M] () -- C:\Users\Public\Desktop\HP ePrintCenter - HP Photosmart 7510 series.lnk
[2012/09/28 16:22:47 | 000,000,057 | ---- | M] () -- C:\ProgramData\Ament.ini
[2012/09/16 20:30:07 | 000,000,374 | ---- | M] () -- C:\Users\Alison\Desktop\Media Makeup Character Assignment.pdf - Shortcut.lnk
[2012/09/11 11:08:36 | 001,063,607 | ---- | M] () -- C:\Users\Alison\Documents\Slim-Down-Meal-Plan.pdf
[2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/06 01:17:16 | 2136,969,216 | -HS- | C] () -- C:\hiberfil.sys
[2012/10/05 00:30:13 | 001,422,336 | ---- | C] () -- C:\Users\Alison\Desktop\RogueKiller.exe
[2012/10/04 23:41:20 | 002,193,278 | ---- | C] () -- C:\Users\Alison\Desktop\tdsskiller.zip
[2012/10/04 03:19:20 | 240,088,771 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/10/04 02:30:18 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/10/04 02:30:18 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/10/04 02:30:18 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/10/04 02:30:18 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/10/04 02:30:18 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/10/01 17:18:28 | 000,302,592 | ---- | C] () -- C:\Users\Alison\Desktop\Gmerrbhhj6er.exe
[2012/10/01 13:48:59 | 000,117,168 | ---- | C] () -- C:\Users\Alison\Desktop\recdisc_x86.zip
[2012/10/01 11:17:31 | 000,002,311 | ---- | C] () -- C:\Users\Alison\Desktop\[Active] - Read Instructions - but cannot access antivirus sites for Step 1 - TechSpot Forums#post-1236488#post-1236488.url
[2012/10/01 09:34:45 | 000,000,951 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/28 19:01:47 | 000,001,709 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/09/28 16:27:19 | 000,001,833 | ---- | C] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk
[2012/09/28 16:27:16 | 000,000,258 | ---- | C] () -- C:\Windows\tasks\HP Photo Creations Messager.job
[2012/09/28 16:25:45 | 000,002,160 | ---- | C] () -- C:\Users\Public\Desktop\HP Photosmart 7510 series.lnk
[2012/09/28 16:25:45 | 000,001,128 | ---- | C] () -- C:\Users\Public\Desktop\Shop for Supplies - HP Photosmart 7510 series.lnk
[2012/09/28 16:25:44 | 000,001,795 | ---- | C] () -- C:\Users\Public\Desktop\HP ePrintCenter - HP Photosmart 7510 series.lnk
[2012/09/28 16:22:47 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012/09/16 20:30:07 | 000,000,374 | ---- | C] () -- C:\Users\Alison\Desktop\Media Makeup Character Assignment.pdf - Shortcut.lnk
[2012/09/11 11:08:36 | 001,063,607 | ---- | C] () -- C:\Users\Alison\Documents\Slim-Down-Meal-Plan.pdf
[2012/06/16 15:51:53 | 000,363,432 | ---- | C] () -- C:\Users\Alison\new5.jpg
[2011/11/13 11:49:42 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/11/13 11:49:42 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/21 20:49:35 | 000,024,206 | -H-- | C] () -- C:\Users\Alison\AppData\Roaming\UserTile.png
[2008/10/21 20:40:43 | 000,173,056 | ---- | C] () -- C:\Users\Alison\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/17 19:17:43 | 000,000,680 | -H-- | C] () -- C:\Users\Alison\AppData\Local\d3d9caps.dat
========== ZeroAccess Check ==========
[2006/11/02 22:24:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2011/01/22 01:16:32 | 011,582,464 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/03/03 14:06:24 | 000,615,424 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/01/21 11:54:03 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/11/10 08:03:35 | 000,000,000 | -H-D | M] -- C:\Users\Alison\AppData\Roaming\AVG
[2012/06/29 22:15:54 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\Caguah
[2012/10/06 18:28:00 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\Dropbox
[2012/06/27 21:26:41 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\Gely
[2012/04/02 15:58:55 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\GetRightToGo
[2010/12/26 14:15:21 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\LimeWire
[2012/07/31 22:17:04 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\Lite
[2012/10/04 14:18:06 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\Ossa
[2009/12/29 09:17:42 | 000,000,000 | -H-D | M] -- C:\Users\Alison\AppData\Roaming\PC Suite
[2012/07/08 13:31:00 | 000,000,000 | ---D | M] -- C:\Users\Alison\AppData\Roaming\Qukun
[2011/11/08 21:08:49 | 000,000,000 | -H-D | M] -- C:\Users\Alison\AppData\Roaming\Samsung
[2008/10/24 21:21:57 | 000,000,000 | -H-D | M] -- C:\Users\Alison\AppData\Roaming\toshiba
[2011/11/08 19:44:24 | 000,000,000 | -H-D | M] -- C:\Users\Alison\AppData\Roaming\Ulead Systems
========== Purity Check ==========
========== Custom Scans ==========
< MD5 for: SERVICES.EXE >
[2008/01/21 11:54:48 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\erdnt\cache\services.exe
[2008/01/21 11:54:48 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\System32\services.exe
[2008/01/21 11:54:48 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
< End of report >