1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Tr/trash.gen Trojan

Discussion in 'Malware Removal Help' started by SpiffyC, Jul 17, 2012.

  1. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hello, Mara.

    The Search Setting was bundled with the YouTube downloader based on the time stamp. If you're having slowness issues, I can be much more aggressive if you want me to be. There are a fair amount of toolbars I would recommend to remove with Revo...that may help the speed. When is the computer slow? As for WinPatrol, it was really good with XP, but Vista/7 has similar features in Windows, like the warning when something wanted to startup.
    YouTube Downloader 3.4
    YouTube Downloader Toolbar v6.0
    NCH FileBulldog Toolbar



    Step 1

    Install ERUNT
    This tool will create a complete backup of your registry. After every reboot, a new backup is created to ensure we have a safety net after each step. Do not delete these backups until we are finished.
    • Please download erunt-setup.exe to your desktop.
    • Double click erunt-setup.exe. Follow the prompts and allow ERUNT to be installed with the settings at default. If you do not want a Desktop icon, feel free to uncheck that. When asked if you want to create an ERUNT entry in the startup folder, answer Yes. You can delete the installation file after use.
    • Erunt will open when the installation is finished. Check all items to be backed up in the default location and click OK.

    The automatic part won't work with Vista or W7. Please backup manually using ERUNT with the following instructions:
    1. Please locate the ERUNT icon on the desktop. If it is not there, click Start and type ERUNT into the search box.
    2. Right click the ERUNT icon in the desktop or the Start menu, and select Run as Administrator
    3. Click OK at the first message box.
    4. Ensure the checkboxes for both "system registry" and "current user registry" are checked. Leave the default save location in there.
    5. Click OK.
    6. Click Yes to create the new folder.
    7. You'll get a window saying "registry backup complete" once it's done. Click OK. If you get an error message, please STOP here and let me know. Do not proceed with any additional instructions until you check back with me.

    Note that you'll get an error message on every boot about ERUNT...just ignore it. It's the automatic backup feature...but Vista stops it from doing the auto backup. It will go away when you remove ERUNT when we are done.


    Step 2

    We need run an OTL Script
    1. Please download OTL from one of the following mirrors if you do not still have it.
    2. Save it to your desktop.
    3. Double click on the [​IMG] icon on your desktop.
    4. Paste the following code under the Custom Scans/Fixes box at the bottom.
      Code:
      :OTL
      DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Programs -- (WISOVD)
      DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
      DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys -- (UrlFilter)
      DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys -- (RegFilter)
      DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
      DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
      DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
      DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
      DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
      DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Monfilt.sys -- (Monfilt)
      DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
      DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
      DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
      DRV - File not found [File_System | Disabled | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor)
      DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
      DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Ambfilt.sys -- (Ambfilt)
      SRV - File not found [Auto | Running] -- C:\Programs -- (SmcService)
      SRV - File not found [Auto | Stopped] -- C:\Programs -- (SkypeUpdate)
      SRV - File not found [Auto | Running] -- C:\Programs -- (NMSAccessU)
      SRV - File not found [Auto | Running] -- C:\Programs -- (MBAMService)
      SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
      SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5)
      SRV - File not found [Auto | Running] -- C:\Programs -- (AdvancedSystemCareService)
      SRV - File not found [Auto | Running] -- C:\Programs -- (AdobeActiveFileMonitor7.0)
      SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe -- (ADExchange)
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B}
      IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B}
      IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms}
      MsConfig - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
      :files
      C:\Program Files\Common Files\Spigot
      C:\Documents and Settings\Glen\Application Data\Search Settings
      
    5. Click the Run Fix button at the top.
    6. let the program run unhindered and reboot when it is done.
    7. You will get a log when it is done, please post that in your reply.
    8. Please then create a new OTL report....
    9. Click the "Scan All Users" checkbox.
    10. Push the [​IMG] button.
    11. A report will open, copy and paste it in a reply here.

    etavares
     
  2. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    The computer is faster now that it was (it was so slow, it would literally take up to 3 minutes to load a page) but it's not the same as it was before the woe hit. So yes, anything and everything you feel will help, I'd be so grateful for!

    I'm running Windows XP (Media version, I think) and while I really it's 'old', it's still what I have and will be ever so happy to have the poor thing rescued, etavares.

    1. The ERUNT is installed and the 'registry backup' and folder complete... as per instructions, haven't done anything with it.

    2. Both OTL scans results:

    OTL logfile created on: 7/25/2012 6:35:37 PM - Run 2
    OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Glen\Desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.22 Gb Total Physical Memory | 2.40 Gb Available Physical Memory | 74.51% Memory free
    6.27 Gb Paging File | 5.55 Gb Available in Paging File | 88.39% Paging File free
    Paging file location(s): C:\pagefile.sys 0 0 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 458.75 Gb Total Space | 357.41 Gb Free Space | 77.91% Space Free | Partition Type: NTFS

    Computer Name: GLEN-F50AB654EA | User Name: Glen | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    PRC - [2012/07/19 15:10:36 | 000,792,512 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
    PRC - [2012/07/19 10:38:46 | 000,400,352 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    PRC - [2012/07/18 22:21:32 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
    PRC - [2012/07/13 16:19:16 | 000,646,800 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\saUI.exe
    PRC - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    PRC - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
    PRC - [2012/05/09 21:26:15 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    PRC - [2012/05/09 21:26:15 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2011/05/15 12:53:20 | 000,325,512 | ---- | M] (BillP Studios) -- C:\Programs - SECURITY\WinPatrol - doggie\WinPatrol.exe
    PRC - [2010/07/12 05:55:03 | 000,218,112 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows NT\Accessories\wordpad.exe
    PRC - [2008/10/20 22:18:26 | 000,071,096 | ---- | M] () -- C:\Programs - MEDIA\CD BURNER XP - recommended by Kim Komando\CDBurnerXP\NMSAccessU.exe
    PRC - [2008/09/16 13:03:18 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Programs - PHOTO\Photoshop ELEMENTS\PhotoshopElementsFileAgent.exe
    PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/07/19 10:38:49 | 001,936,352 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\mozjs.dll
    MOD - [2012/07/19 10:38:49 | 000,162,784 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldap32v60.dll
    MOD - [2012/07/19 10:38:49 | 000,021,984 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldappr32v60.dll
    MOD - [2012/07/18 22:21:31 | 002,003,424 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
    MOD - [2012/05/09 21:26:16 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
    MOD - [2011/11/03 08:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
    MOD - [2011/04/14 18:01:33 | 000,548,854 | ---- | M] () -- C:\Programs - SECURITY\WinPatrol - doggie\sqlite3.dll
    MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
    MOD - [2008/10/20 22:18:26 | 000,071,096 | ---- | M] () -- C:\Programs - MEDIA\CD BURNER XP - recommended by Kim Komando\CDBurnerXP\NMSAccessU.exe
    MOD - [2008/04/13 17:12:03 | 000,562,176 | ---- | M] () -- C:\WINDOWS\system32\qedit.dll
    MOD - [2008/04/13 17:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
    MOD - [2008/04/13 17:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Auto | Stopped] -- C:\Programs -- (SmcService)
    SRV - File not found [Auto | Stopped] -- C:\Programs -- (SkypeUpdate)
    SRV - File not found [Auto | Running] -- C:\Programs -- (NMSAccessU)
    SRV - File not found [Auto | Running] -- C:\Programs -- (MBAMService)
    SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
    SRV - File not found [Auto | Running] -- C:\Programs -- (AdobeActiveFileMonitor7.0)
    SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe -- (ADExchange)
    SRV - [2012/07/19 15:10:36 | 000,792,512 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
    SRV - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
    SRV - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011/11/09 13:21:36 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Programs -- (WISOVD)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys -- (UrlFilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys -- (RegFilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Monfilt.sys -- (Monfilt)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [File_System | Disabled | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Ambfilt.sys -- (Ambfilt)
    DRV - [2012/05/09 21:26:16 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
    DRV - [2012/05/09 21:26:16 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
    DRV - [2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2011/10/11 15:00:32 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
    DRV - [2011/08/09 16:33:58 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BANTExt.sys -- (BANTExt)
    DRV - [2010/11/26 18:02:52 | 000,014,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
    DRV - [2010/08/04 06:16:54 | 002,127,728 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
    DRV - [2009/11/29 23:31:42 | 000,050,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
    DRV - [2009/11/12 14:48:56 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
    DRV - [2009/06/29 04:59:14 | 000,142,592 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
    DRV - [2009/06/26 18:21:02 | 001,956,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX3000.sys -- (VX3000)
    DRV - [2004/10/15 18:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg6n.sys -- (wg6n)
    DRV - [2004/10/15 18:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg5n.sys -- (wg5n)
    DRV - [2004/10/15 18:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg4n.sys -- (wg4n)
    DRV - [2004/10/15 18:32:38 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg3n.sys -- (wg3n)
    DRV - [2004/10/15 18:18:46 | 000,021,075 | ---- | M] (Sygate Technologies, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\wpsdrvnt.sys -- (wpsdrvnt)
    DRV - [2004/10/15 18:17:02 | 000,060,496 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\Teefer.sys -- (Teefer)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}
    IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\NCH FileBulldog Toolbar\tbhelper.dll ()
    IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    IE - HKCU\..\SearchScopes,DefaultScope = {F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}?q={searchTerms}
    IE - HKCU\..\SearchScopes\{F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Yahoo"
    FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
    FF - prefs.js..browser.search.selectedEngine: "Google"
    FF - prefs.js..browser.startup.homepage: "http://home.mytelus.com/telusen/portal/index.aspx"
    FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p="
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/07/20 06:15:55 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/18 22:21:34 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/06/20 11:05:37 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

    [2011/10/20 20:41:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Extensions
    [2012/07/19 12:35:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\fo0zfocb.default\extensions
    [2011/12/12 15:35:11 | 000,000,000 | ---D | M] (NCH FileBulldog Toolbar) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\fo0zfocb.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
    [2012/07/14 11:22:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2012/04/20 09:06:55 | 000,085,537 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\AFTERTHEDEADLINE@AFTERTHEDEADLINE.COM.XPI
    [2011/12/22 13:31:31 | 000,599,045 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FIREFOXADDON@SIMILARWEB.COM.XPI
    [2012/07/18 12:39:23 | 000,040,533 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FLATBM@XULDEV.ORG.XPI
    [2012/02/07 18:21:25 | 000,113,603 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\NOSQUINT@URANDOM.CA.XPI
    [2012/07/20 06:15:55 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
    [2011/10/29 15:26:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
    [2012/07/18 22:21:33 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2012/05/02 13:22:24 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
    [2012/02/19 23:37:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2012/05/02 13:22:24 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
    [2012/05/02 13:22:24 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
    [2012/07/14 11:29:22 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
    [2012/05/02 13:22:27 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
    [2012/05/02 13:22:24 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

    O1 HOSTS File: ([2006/03/15 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O3 - HKLM\..\Toolbar: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SmcService] C:\Programs - SECURITY\Sygate - FIREWALL\Smc.exe (Sygate Technologies, Inc.)
    O4 - HKLM..\Run: [WinPatrol] C:\Programs - SECURITY\WinPatrol - doggie\winpatrol.exe (BillP Studios)
    O4 - Startup: C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342391681625 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 75.153.176.9
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE6FF7B-9D9D-4B11-B6A4-E8A5AD181751}: DhcpNameServer = 192.168.1.254 75.153.176.9
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2011/10/20 20:14:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/07/25 18:31:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2012/07/25 18:31:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
    [2012/07/25 18:31:01 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
    [2012/07/25 18:28:38 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/24 15:31:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\AnvSoft Movie DVD Maker
    [2012/07/24 12:33:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\Photostage Projects
    [2012/07/24 11:42:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Search Settings
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\YouTube Downloader Toolbar
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
    [2012/07/24 01:29:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\BolideSoftware
    [2012/07/23 01:22:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\TuneUp Software
    [2012/07/23 01:22:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    [2012/07/23 01:21:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
    [2012/07/22 20:48:32 | 000,000,000 | ---D | C] -- C:\Program Files\Belarc
    [2012/07/22 18:17:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\ESTATE documents
    [2012/07/21 21:36:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Driver Tool
    [2012/07/21 17:42:00 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:27:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\WMTools Downloaded Files
    [2012/07/21 00:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\Speccy
    [2012/07/20 10:51:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Sun
    [2012/07/19 23:53:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Temp
    [2012/07/19 17:45:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
    [2012/07/19 17:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
    [2012/07/19 17:45:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Oracle
    [2012/07/19 17:45:09 | 000,772,544 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
    [2012/07/19 17:45:09 | 000,227,824 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 12:32:28 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
    [2012/07/19 12:14:32 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/18 22:19:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z computer woes, mid July
    [2012/07/18 20:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
    [2012/07/18 20:14:23 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonMP Uninstaller Information
    [2012/07/18 20:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP150
    [2012/07/18 20:14:07 | 000,000,000 | -H-D | C] -- C:\CanonMP
    [2012/07/18 19:42:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Start Menu\Programs\Revo Uninstaller
    [2012/07/17 12:09:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z legal templates READY
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    [2012/07/14 15:41:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Windows Search
    [2012/07/01 12:03:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IdealSoftware
    [2012/07/01 12:03:40 | 000,000,000 | ---D | C] -- C:\IDEALDVDCOPY_TEMP
    [2012/07/01 12:03:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Ideal DVD Copy
    [2012/07/01 12:03:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\IdealSoftware
    [2012/06/27 11:10:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\zz BURN TO CD for my SYLVIA
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/07/25 18:31:19 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/25 18:28:40 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/25 17:44:30 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/25 09:11:56 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/25 09:11:56 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag_Startup.job
    [2012/07/25 09:11:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/07/24 22:08:46 | 000,000,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | M] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:37:39 | 000,208,384 | ---- | M] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/07/24 15:14:07 | 000,000,700 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 13:50:22 | 000,038,198 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:15 | 000,000,235 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 21:01:36 | 000,001,723 | ---- | M] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 21:01:36 | 000,001,705 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Belarc Advisor.lnk
    [2012/07/22 20:57:34 | 000,000,833 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 14:34:08 | 000,001,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:18 | 000,020,973 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 19:21:51 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\MBR.dat
    [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:31:56 | 000,002,385 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Microsoft Office PowerPoint Viewer 2007.lnk
    [2012/07/21 00:15:26 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 17:44:48 | 000,227,824 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 17:44:48 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
    [2012/07/19 12:14:32 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/19 08:00:14 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/07/18 20:18:58 | 000,001,693 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 20:10:00 | 000,000,852 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\IObit Malware Fighter.lnk
    [2012/07/18 19:43:00 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Revo Uninstaller.lnk
    [2012/07/18 12:32:22 | 000,000,922 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Quick Care.lnk
    [2012/07/18 12:22:36 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/16 19:49:55 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\PixillionDowngrade.job
    [2012/07/16 18:23:46 | 000,002,437 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
    [2012/07/15 15:26:34 | 000,242,328 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2012/07/14 11:26:19 | 000,502,962 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2012/07/14 11:26:19 | 000,087,046 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2012/07/14 04:45:28 | 000,025,019 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.lst
    [2012/07/12 22:00:23 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\prismDowngrade.job
    [2012/07/07 14:42:02 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite
    [2012/07/06 11:47:01 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\switchShakeIcon.job
    [2012/07/05 22:06:30 | 000,772,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
    [2012/07/05 22:06:20 | 000,687,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
    [2012/07/01 12:03:37 | 000,000,955 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Ideal DVD Copy.lnk
    [2012/06/26 21:59:01 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\prismShakeIcon.job
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/07/25 18:31:19 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/25 12:09:47 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/24 22:08:46 | 000,000,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | C] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:13:37 | 000,000,700 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 01:42:54 | 000,038,198 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:14 | 000,000,235 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 20:57:34 | 000,000,833 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 20:48:35 | 000,001,723 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 20:48:35 | 000,001,705 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Belarc Advisor.lnk
    [2012/07/22 20:48:34 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Belarc Advisor.lnk
    [2012/07/22 20:48:32 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
    [2012/07/22 14:34:08 | 000,001,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:17 | 000,020,973 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 19:21:51 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\MBR.dat
    [2012/07/21 00:15:26 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 12:32:51 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 20:15:16 | 000,001,693 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 12:32:39 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/18 12:32:22 | 000,000,922 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Quick Care.lnk
    [2012/07/18 12:22:36 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/14 04:44:45 | 000,025,019 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.lst
    [2012/07/07 14:42:02 | 000,000,000 | ---- | C] () -- C:\extensions.sqlite
    [2012/07/06 10:41:28 | 000,034,207 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\ANIMATED blow bubbles.gif
    [2012/07/02 17:38:09 | 000,002,385 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Microsoft Office PowerPoint Viewer 2007.lnk
    [2012/07/01 12:03:37 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Ideal DVD Copy.lnk
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
    [2012/06/12 13:31:10 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5002.dll
    [2012/06/12 13:31:03 | 002,026,604 | R--- | C] () -- C:\WINDOWS\System32\igkrng500.bin
    [2012/06/12 13:31:03 | 000,442,964 | R--- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
    [2012/02/15 02:55:59 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
    [2012/01/23 03:26:22 | 000,135,189 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\PhotoStage.dmp
    [2012/01/20 15:10:52 | 000,311,296 | ---- | C] () -- C:\WINDOWS\System32\EMRegSys.dll
    [2012/01/09 13:00:48 | 004,346,880 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
    [2012/01/07 15:22:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\libbluray.dll
    [2012/01/07 15:21:50 | 006,366,094 | ---- | C] () -- C:\WINDOWS\System32\avcodec-lav-53.dll
    [2012/01/07 15:21:50 | 001,007,151 | ---- | C] () -- C:\WINDOWS\System32\avformat-lav-53.dll
    [2012/01/07 15:21:50 | 000,354,979 | ---- | C] () -- C:\WINDOWS\System32\swscale-lav-2.dll
    [2012/01/07 15:21:50 | 000,203,306 | ---- | C] () -- C:\WINDOWS\System32\avutil-lav-51.dll
    [2012/01/07 15:21:50 | 000,138,727 | ---- | C] () -- C:\WINDOWS\System32\avfilter-lav-2.dll
    [2012/01/06 03:19:39 | 000,163,029 | ---- | C] () -- C:\WINDOWS\DP Animation Maker Uninstaller.exe
    [2011/12/20 11:50:04 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2011/12/20 11:49:56 | 000,099,328 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
    [2011/12/20 11:49:54 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
    [2011/12/20 11:49:54 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
    [2011/12/20 11:49:52 | 001,525,248 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
    [2011/12/20 11:49:52 | 000,212,480 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
    [2011/12/20 11:49:52 | 000,115,200 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
    [2011/12/20 11:49:50 | 000,328,704 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
    [2011/12/20 11:49:50 | 000,260,608 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
    [2011/12/20 11:49:50 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
    [2011/12/12 22:58:51 | 000,160,992 | ---- | C] () -- C:\WINDOWS\Sqirlz Water Reflections Uninstaller.exe
    [2011/12/07 12:32:24 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\Lagarith.dll
    [2011/11/30 22:01:20 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7K.DLL
    [2011/11/30 16:51:44 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
    [2011/11/23 03:50:10 | 000,276,255 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-343818398-2111687655-682003330-1003-0.dat
    [2011/11/23 03:50:06 | 000,171,618 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
    [2011/11/21 16:54:54 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\fusioncache.dat
    [2011/11/20 00:41:53 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
    [2011/10/30 17:33:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\Cool Motion.dll
    [2011/10/29 19:08:34 | 000,025,944 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
    [2011/10/29 19:08:33 | 000,014,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
    [2011/10/21 18:16:47 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\sh33w32.dll
    [2011/10/21 18:02:03 | 000,208,384 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/10/20 20:21:24 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
    [2011/10/20 20:20:18 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
    [2011/10/20 20:16:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2011/10/20 20:09:43 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2011/10/20 13:01:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2011/10/20 13:00:24 | 000,242,328 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2011/09/08 07:00:52 | 000,150,528 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
    [2011/09/08 07:00:48 | 000,142,336 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
    [2011/09/08 07:00:42 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
    [2011/09/08 07:00:38 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
    [2011/09/08 07:00:34 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\dsmux.exe
    [2011/09/08 07:00:24 | 000,154,624 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
    [2011/09/08 07:00:10 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\mkv2vfr.exe
    [2011/09/08 07:00:06 | 000,358,400 | ---- | C] () -- C:\WINDOWS\System32\gdsmux.exe
    [2011/09/08 06:59:54 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
    [2011/09/08 06:59:52 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
    [2011/05/30 06:42:50 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2011/05/23 00:46:30 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2011/03/03 04:39:56 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
    [2011/03/03 04:38:10 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
    [2011/03/03 04:37:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
    [2011/02/15 05:46:02 | 014,454,784 | ---- | C] () -- C:\WINDOWS\System32\common_res.dll
    [2010/08/18 12:56:38 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini

    ========== Custom Scans ==========

    < :OTL >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Programs -- (WISOVD) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys -- (UrlFilter) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys -- (RegFilter) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Monfilt.sys -- (Monfilt) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) >

    < DRV - File not found [File_System | Disabled | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (Changer) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Ambfilt.sys -- (Ambfilt) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (SmcService) >

    < SRV - File not found [Auto | Stopped] -- C:\Programs -- (SkypeUpdate) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (NMSAccessU) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (MBAMService) >

    < SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice) >

    < SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (AdvancedSystemCareService) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (AdobeActiveFileMonitor7.0) >

    < SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe -- (ADExchange) >

    < IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B} >
    Invalid Switch: www.bigseekpr...4-89606D287C1B}

    < IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B} >
    Invalid Switch: www.bigseekpr...4-89606D287C1B}

    < IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms} >

    < MsConfig - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) >

    < :files >

    < C:\Program Files\Common Files\Spigot >

    < C:\Documents and Settings\Glen\Application Data\Search Settings >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8423A1CF

    < End of report >



    OTL logfile created on: 7/25/2012 7:59:07 PM - Run 3
    OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Glen\Desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.22 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 73.98% Memory free
    6.27 Gb Paging File | 5.51 Gb Available in Paging File | 87.89% Paging File free
    Paging file location(s): C:\pagefile.sys 0 0 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 458.75 Gb Total Space | 357.41 Gb Free Space | 77.91% Space Free | Partition Type: NTFS

    Computer Name: GLEN-F50AB654EA | User Name: Glen | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    PRC - [2012/07/19 15:10:36 | 000,792,512 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
    PRC - [2012/07/19 10:38:46 | 000,400,352 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    PRC - [2012/07/18 22:21:32 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
    PRC - [2012/07/13 16:19:16 | 000,646,800 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\saUI.exe
    PRC - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    PRC - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
    PRC - [2012/05/09 21:26:15 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    PRC - [2012/05/09 21:26:15 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2011/05/15 12:53:20 | 000,325,512 | ---- | M] (BillP Studios) -- C:\Programs - SECURITY\WinPatrol - doggie\WinPatrol.exe
    PRC - [2010/07/12 05:55:03 | 000,218,112 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows NT\Accessories\wordpad.exe
    PRC - [2008/10/20 22:18:26 | 000,071,096 | ---- | M] () -- C:\Programs - MEDIA\CD BURNER XP - recommended by Kim Komando\CDBurnerXP\NMSAccessU.exe
    PRC - [2008/09/16 13:03:18 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Programs - PHOTO\Photoshop ELEMENTS\PhotoshopElementsFileAgent.exe
    PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/07/19 10:38:49 | 001,936,352 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\mozjs.dll
    MOD - [2012/07/19 10:38:49 | 000,162,784 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldap32v60.dll
    MOD - [2012/07/19 10:38:49 | 000,021,984 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldappr32v60.dll
    MOD - [2012/07/18 22:21:31 | 002,003,424 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
    MOD - [2012/05/09 21:26:16 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
    MOD - [2011/11/03 08:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
    MOD - [2011/04/14 18:01:33 | 000,548,854 | ---- | M] () -- C:\Programs - SECURITY\WinPatrol - doggie\sqlite3.dll
    MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
    MOD - [2008/10/20 22:18:26 | 000,071,096 | ---- | M] () -- C:\Programs - MEDIA\CD BURNER XP - recommended by Kim Komando\CDBurnerXP\NMSAccessU.exe
    MOD - [2008/04/13 17:12:03 | 000,562,176 | ---- | M] () -- C:\WINDOWS\system32\qedit.dll
    MOD - [2008/04/13 17:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
    MOD - [2008/04/13 17:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Auto | Stopped] -- C:\Programs -- (SmcService)
    SRV - File not found [Auto | Stopped] -- C:\Programs -- (SkypeUpdate)
    SRV - File not found [Auto | Running] -- C:\Programs -- (NMSAccessU)
    SRV - File not found [Auto | Running] -- C:\Programs -- (MBAMService)
    SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
    SRV - File not found [Auto | Running] -- C:\Programs -- (AdobeActiveFileMonitor7.0)
    SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe -- (ADExchange)
    SRV - [2012/07/19 15:10:36 | 000,792,512 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
    SRV - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
    SRV - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011/11/09 13:21:36 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Programs -- (WISOVD)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys -- (UrlFilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys -- (RegFilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Monfilt.sys -- (Monfilt)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [File_System | Disabled | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Ambfilt.sys -- (Ambfilt)
    DRV - [2012/05/09 21:26:16 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
    DRV - [2012/05/09 21:26:16 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
    DRV - [2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2011/10/11 15:00:32 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
    DRV - [2011/08/09 16:33:58 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BANTExt.sys -- (BANTExt)
    DRV - [2010/11/26 18:02:52 | 000,014,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
    DRV - [2010/08/04 06:16:54 | 002,127,728 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
    DRV - [2009/11/29 23:31:42 | 000,050,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
    DRV - [2009/11/12 14:48:56 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
    DRV - [2009/06/29 04:59:14 | 000,142,592 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
    DRV - [2009/06/26 18:21:02 | 001,956,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX3000.sys -- (VX3000)
    DRV - [2004/10/15 18:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg6n.sys -- (wg6n)
    DRV - [2004/10/15 18:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg5n.sys -- (wg5n)
    DRV - [2004/10/15 18:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg4n.sys -- (wg4n)
    DRV - [2004/10/15 18:32:38 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg3n.sys -- (wg3n)
    DRV - [2004/10/15 18:18:46 | 000,021,075 | ---- | M] (Sygate Technologies, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\wpsdrvnt.sys -- (wpsdrvnt)
    DRV - [2004/10/15 18:17:02 | 000,060,496 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\Teefer.sys -- (Teefer)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\NCH FileBulldog Toolbar\tbhelper.dll ()
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes,DefaultScope = {F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}?q={searchTerms}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Yahoo"
    FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
    FF - prefs.js..browser.search.selectedEngine: "Google"
    FF - prefs.js..browser.startup.homepage: "http://home.mytelus.com/telusen/portal/index.aspx"
    FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p="
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/07/20 06:15:55 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/18 22:21:34 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/06/20 11:05:37 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

    [2011/10/20 20:41:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Extensions
    [2012/07/19 12:35:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\fo0zfocb.default\extensions
    [2011/12/12 15:35:11 | 000,000,000 | ---D | M] (NCH FileBulldog Toolbar) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\fo0zfocb.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
    [2012/07/14 11:22:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2012/04/20 09:06:55 | 000,085,537 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\AFTERTHEDEADLINE@AFTERTHEDEADLINE.COM.XPI
    [2011/12/22 13:31:31 | 000,599,045 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FIREFOXADDON@SIMILARWEB.COM.XPI
    [2012/07/18 12:39:23 | 000,040,533 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FLATBM@XULDEV.ORG.XPI
    [2012/02/07 18:21:25 | 000,113,603 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\NOSQUINT@URANDOM.CA.XPI
    [2012/07/20 06:15:55 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
    [2011/10/29 15:26:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
    [2012/07/18 22:21:33 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2012/05/02 13:22:24 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
    [2012/02/19 23:37:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2012/05/02 13:22:24 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
    [2012/05/02 13:22:24 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
    [2012/07/14 11:29:22 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
    [2012/05/02 13:22:27 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
    [2012/05/02 13:22:24 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

    O1 HOSTS File: ([2006/03/15 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O3 - HKLM\..\Toolbar: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    O3 - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\Toolbar\WebBrowser: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SmcService] C:\Programs - SECURITY\Sygate - FIREWALL\Smc.exe (Sygate Technologies, Inc.)
    O4 - HKLM..\Run: [WinPatrol] C:\Programs - SECURITY\WinPatrol - doggie\winpatrol.exe (BillP Studios)
    O4 - Startup: C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342391681625 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 75.153.176.9
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE6FF7B-9D9D-4B11-B6A4-E8A5AD181751}: DhcpNameServer = 192.168.1.254 75.153.176.9
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2011/10/20 20:14:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/07/25 18:31:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2012/07/25 18:31:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
    [2012/07/25 18:31:01 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
    [2012/07/25 18:28:38 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/24 15:31:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\AnvSoft Movie DVD Maker
    [2012/07/24 12:33:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\Photostage Projects
    [2012/07/24 11:42:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Search Settings
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\YouTube Downloader Toolbar
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
    [2012/07/24 01:29:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\BolideSoftware
    [2012/07/23 01:22:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\TuneUp Software
    [2012/07/23 01:22:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    [2012/07/23 01:21:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
    [2012/07/22 20:48:32 | 000,000,000 | ---D | C] -- C:\Program Files\Belarc
    [2012/07/22 18:17:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\ESTATE documents
    [2012/07/21 21:36:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Driver Tool
    [2012/07/21 17:42:00 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:27:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\WMTools Downloaded Files
    [2012/07/21 00:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\Speccy
    [2012/07/20 10:51:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Sun
    [2012/07/19 23:53:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Temp
    [2012/07/19 17:45:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
    [2012/07/19 17:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
    [2012/07/19 17:45:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Oracle
    [2012/07/19 17:45:09 | 000,772,544 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
    [2012/07/19 17:45:09 | 000,227,824 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 12:32:28 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
    [2012/07/19 12:14:32 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/18 22:19:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z computer woes, mid July
    [2012/07/18 20:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
    [2012/07/18 20:14:23 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonMP Uninstaller Information
    [2012/07/18 20:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP150
    [2012/07/18 20:14:07 | 000,000,000 | -H-D | C] -- C:\CanonMP
    [2012/07/18 19:42:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Start Menu\Programs\Revo Uninstaller
    [2012/07/17 12:09:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z legal templates READY
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    [2012/07/14 15:41:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Windows Search
    [2012/07/01 12:03:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IdealSoftware
    [2012/07/01 12:03:40 | 000,000,000 | ---D | C] -- C:\IDEALDVDCOPY_TEMP
    [2012/07/01 12:03:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Ideal DVD Copy
    [2012/07/01 12:03:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\IdealSoftware
    [2012/06/27 11:10:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\zz BURN TO CD for my SYLVIA
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/07/25 20:10:42 | 000,790,242 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\doug 02.BMP
    [2012/07/25 20:09:17 | 000,074,838 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\doug 01.BMP
    [2012/07/25 20:00:22 | 000,000,545 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\etavares f.rtf
    [2012/07/25 18:31:19 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/25 18:28:40 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/25 17:44:30 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/25 09:11:56 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/25 09:11:56 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag_Startup.job
    [2012/07/25 09:11:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/07/24 22:08:46 | 000,000,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | M] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:37:39 | 000,208,384 | ---- | M] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/07/24 15:14:07 | 000,000,700 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 13:50:22 | 000,038,198 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:15 | 000,000,235 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 21:01:36 | 000,001,723 | ---- | M] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 21:01:36 | 000,001,705 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Belarc Advisor.lnk
    [2012/07/22 20:57:34 | 000,000,833 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 14:34:08 | 000,001,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:18 | 000,020,973 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 19:21:51 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\MBR.dat
    [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:31:56 | 000,002,385 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Microsoft Office PowerPoint Viewer 2007.lnk
    [2012/07/21 00:15:26 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 17:44:48 | 000,227,824 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 17:44:48 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
    [2012/07/19 12:14:32 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/19 08:00:14 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/07/18 20:18:58 | 000,001,693 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 20:10:00 | 000,000,852 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\IObit Malware Fighter.lnk
    [2012/07/18 19:43:00 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Revo Uninstaller.lnk
    [2012/07/18 12:32:22 | 000,000,922 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Quick Care.lnk
    [2012/07/18 12:22:36 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/16 19:49:55 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\PixillionDowngrade.job
    [2012/07/16 18:23:46 | 000,002,437 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
    [2012/07/15 15:26:34 | 000,242,328 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2012/07/14 11:26:19 | 000,502,962 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2012/07/14 11:26:19 | 000,087,046 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2012/07/14 04:45:28 | 000,025,019 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.lst
    [2012/07/12 22:00:23 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\prismDowngrade.job
    [2012/07/07 14:42:02 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite
    [2012/07/06 11:47:01 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\switchShakeIcon.job
    [2012/07/05 22:06:30 | 000,772,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
    [2012/07/05 22:06:20 | 000,687,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
    [2012/07/01 12:03:37 | 000,000,955 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Ideal DVD Copy.lnk
    [2012/06/26 21:59:01 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\prismShakeIcon.job
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/07/25 20:10:42 | 000,790,242 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\doug 02.BMP
    [2012/07/25 20:09:17 | 000,074,838 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\doug 01.BMP
    [2012/07/25 20:00:22 | 000,000,545 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\etavares f.rtf
    [2012/07/25 18:31:19 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/25 12:09:47 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/24 22:08:46 | 000,000,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | C] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:13:37 | 000,000,700 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 01:42:54 | 000,038,198 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:14 | 000,000,235 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 20:57:34 | 000,000,833 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 20:48:35 | 000,001,723 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 20:48:35 | 000,001,705 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Belarc Advisor.lnk
    [2012/07/22 20:48:34 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Belarc Advisor.lnk
    [2012/07/22 20:48:32 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
    [2012/07/22 14:34:08 | 000,001,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:17 | 000,020,973 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 19:21:51 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\MBR.dat
    [2012/07/21 00:15:26 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 12:32:51 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 20:15:16 | 000,001,693 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 12:32:39 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/18 12:32:22 | 000,000,922 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Quick Care.lnk
    [2012/07/18 12:22:36 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/14 04:44:45 | 000,025,019 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.lst
    [2012/07/07 14:42:02 | 000,000,000 | ---- | C] () -- C:\extensions.sqlite
    [2012/07/06 10:41:28 | 000,034,207 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\ANIMATED blow bubbles.gif
    [2012/07/02 17:38:09 | 000,002,385 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Microsoft Office PowerPoint Viewer 2007.lnk
    [2012/07/01 12:03:37 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Ideal DVD Copy.lnk
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
    [2012/06/12 13:31:10 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5002.dll
    [2012/06/12 13:31:03 | 002,026,604 | R--- | C] () -- C:\WINDOWS\System32\igkrng500.bin
    [2012/06/12 13:31:03 | 000,442,964 | R--- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
    [2012/02/15 02:55:59 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
    [2012/01/23 03:26:22 | 000,135,189 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\PhotoStage.dmp
    [2012/01/20 15:10:52 | 000,311,296 | ---- | C] () -- C:\WINDOWS\System32\EMRegSys.dll
    [2012/01/09 13:00:48 | 004,346,880 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
    [2012/01/07 15:22:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\libbluray.dll
    [2012/01/07 15:21:50 | 006,366,094 | ---- | C] () -- C:\WINDOWS\System32\avcodec-lav-53.dll
    [2012/01/07 15:21:50 | 001,007,151 | ---- | C] () -- C:\WINDOWS\System32\avformat-lav-53.dll
    [2012/01/07 15:21:50 | 000,354,979 | ---- | C] () -- C:\WINDOWS\System32\swscale-lav-2.dll
    [2012/01/07 15:21:50 | 000,203,306 | ---- | C] () -- C:\WINDOWS\System32\avutil-lav-51.dll
    [2012/01/07 15:21:50 | 000,138,727 | ---- | C] () -- C:\WINDOWS\System32\avfilter-lav-2.dll
    [2012/01/06 03:19:39 | 000,163,029 | ---- | C] () -- C:\WINDOWS\DP Animation Maker Uninstaller.exe
    [2011/12/20 11:50:04 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2011/12/20 11:49:56 | 000,099,328 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
    [2011/12/20 11:49:54 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
    [2011/12/20 11:49:54 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
    [2011/12/20 11:49:52 | 001,525,248 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
    [2011/12/20 11:49:52 | 000,212,480 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
    [2011/12/20 11:49:52 | 000,115,200 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
    [2011/12/20 11:49:50 | 000,328,704 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
    [2011/12/20 11:49:50 | 000,260,608 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
    [2011/12/20 11:49:50 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
    [2011/12/12 22:58:51 | 000,160,992 | ---- | C] () -- C:\WINDOWS\Sqirlz Water Reflections Uninstaller.exe
    [2011/12/07 12:32:24 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\Lagarith.dll
    [2011/11/30 22:01:20 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7K.DLL
    [2011/11/30 16:51:44 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
    [2011/11/23 03:50:10 | 000,276,255 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-343818398-2111687655-682003330-1003-0.dat
    [2011/11/23 03:50:06 | 000,171,618 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
    [2011/11/21 16:54:54 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\fusioncache.dat
    [2011/11/20 00:41:53 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
    [2011/10/30 17:33:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\Cool Motion.dll
    [2011/10/29 19:08:34 | 000,025,944 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
    [2011/10/29 19:08:33 | 000,014,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
    [2011/10/21 18:16:47 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\sh33w32.dll
    [2011/10/21 18:02:03 | 000,208,384 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/10/20 20:21:24 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
    [2011/10/20 20:20:18 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
    [2011/10/20 20:16:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2011/10/20 20:09:43 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2011/10/20 13:01:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2011/10/20 13:00:24 | 000,242,328 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2011/09/08 07:00:52 | 000,150,528 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
    [2011/09/08 07:00:48 | 000,142,336 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
    [2011/09/08 07:00:42 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
    [2011/09/08 07:00:38 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
    [2011/09/08 07:00:34 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\dsmux.exe
    [2011/09/08 07:00:24 | 000,154,624 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
    [2011/09/08 07:00:10 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\mkv2vfr.exe
    [2011/09/08 07:00:06 | 000,358,400 | ---- | C] () -- C:\WINDOWS\System32\gdsmux.exe
    [2011/09/08 06:59:54 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
    [2011/09/08 06:59:52 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
    [2011/05/30 06:42:50 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2011/05/23 00:46:30 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2011/03/03 04:39:56 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
    [2011/03/03 04:38:10 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
    [2011/03/03 04:37:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
    [2011/02/15 05:46:02 | 014,454,784 | ---- | C] () -- C:\WINDOWS\System32\common_res.dll
    [2010/08/18 12:56:38 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8423A1CF

    < End of report >
     
  3. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Oh dear, I must be loosing my mind as I was so sure I'd uninstalled 'IOBit Malware Fighter' when I got rid of the other IOBit stuff ... but hmmm, here it was. So used 'Revo' again and this time found reference to something called 'Bluebird' ... do got rid of it, too.

    Had a bit of a problem getting back to our site here ... pages slow to load and mouse takes forever to make page scroll, etc. Mind you, if the scans show no problem, could be just my computer getting old (like me - huge grin!).

    Thanks again for everything you are doing for me!
     
  4. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi Mara,

    Please run my instructions again...it looks like you pasted the script properly, but clicked Run Scan instead of Run Fix. We'll see how it runs after that.

    Thanks!
    -etavares
     
  5. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Oh dod, I'm so so sorry, Etavares! Here's the 'Fix' scan results:

    :OTL
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Programs -- (WISOVD)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys -- (UrlFilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys -- (RegFilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Monfilt.sys -- (Monfilt)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [File_System | Disabled | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Ambfilt.sys -- (Ambfilt)
    SRV - File not found [Auto | Running] -- C:\Programs -- (SmcService)
    SRV - File not found [Auto | Stopped] -- C:\Programs -- (SkypeUpdate)
    SRV - File not found [Auto | Running] -- C:\Programs -- (NMSAccessU)
    SRV - File not found [Auto | Running] -- C:\Programs -- (MBAMService)
    SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
    SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5)
    SRV - File not found [Auto | Running] -- C:\Programs -- (AdvancedSystemCareService)
    SRV - File not found [Auto | Running] -- C:\Programs -- (AdobeActiveFileMonitor7.0)
    SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe -- (ADExchange)
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms}
    MsConfig - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
    :files
    C:\Program Files\Common Files\Spigot
    C:\Documents and Settings\Glen\Application Data\Search Settings
     
  6. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    ========== OTL ==========
    Error: No service named WISOVD was found to stop!
    Service\Driver key WISOVD not found.
    File C:\Programs not found.
    Error: No service named WDICA was found to stop!
    Service\Driver key WDICA not found.
    Error: No service named UrlFilter was found to stop!
    Service\Driver key UrlFilter not found.
    File C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys not found.
    Error: No service named RegFilter was found to stop!
    Service\Driver key RegFilter not found.
    File C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys not found.
    Error: No service named PDRFRAME was found to stop!
    Service\Driver key PDRFRAME not found.
    Error: No service named PDRELI was found to stop!
    Service\Driver key PDRELI not found.
    Error: No service named PDFRAME was found to stop!
    Service\Driver key PDFRAME not found.
    Error: No service named PDCOMP was found to stop!
    Service\Driver key PDCOMP not found.
    Error: No service named PCIDump was found to stop!
    Service\Driver key PCIDump not found.
    Error: No service named Monfilt was found to stop!
    Service\Driver key Monfilt not found.
    File system32\drivers\Monfilt.sys not found.
    Error: No service named lbrtfdc was found to stop!
    Service\Driver key lbrtfdc not found.
    Error: No service named IntcAzAudAddService) Service for Realtek HD Audio (WDM was found to stop!
    Service\Driver key IntcAzAudAddService) Service for Realtek HD Audio (WDM not found.
    File system32\drivers\RtkHDAud.sys not found.
    Error: No service named i2omgmt was found to stop!
    Service\Driver key i2omgmt not found.
    Error: No service named FileMonitor was found to stop!
    Service\Driver key FileMonitor not found.
    File C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys not found.
    Error: No service named Changer was found to stop!
    Service\Driver key Changer not found.
    Error: No service named Ambfilt was found to stop!
    Service\Driver key Ambfilt not found.
    File system32\drivers\Ambfilt.sys not found.
    Error: No service named SmcService was found to stop!
    Service\Driver key SmcService not found.
    File C:\Programs not found.
    Error: No service named SkypeUpdate was found to stop!
    Service\Driver key SkypeUpdate not found.
    File C:\Programs not found.
    Error: No service named NMSAccessU was found to stop!
    Service\Driver key NMSAccessU not found.
    File C:\Programs not found.
    Error: Unable to stop service MBAMService!
    Service\Driver key MBAMService not found.
    File C:\Programs not found.
    Error: No service named IMFservice was found to stop!
    Service\Driver key IMFservice not found.
    File C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe not found.
    Error: No service named AdvancedSystemCareService5 was found to stop!
    Service\Driver key AdvancedSystemCareService5 not found.
    File C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe not found.
    Error: No service named AdvancedSystemCareService was found to stop!
    Service\Driver key AdvancedSystemCareService not found.
    File C:\Programs not found.
    Error: No service named AdobeActiveFileMonitor7.0 was found to stop!
    Service\Driver key AdobeActiveFileMonitor7.0 not found.
    File C:\Programs not found.
    Error: No service named ADExchange was found to stop!
    Service\Driver key ADExchange not found.
    File C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    Registry key HKEY_USERS\S-1-5-21-343818398-2111687655-682003330-1003\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SearchSettings\ not found.
    ========== FILES ==========
    File\Folder C:\Program Files\Common Files\Spigot not found.
    File\Folder C:\Documents and Settings\Glen\Application Data\Search Settings not found.

    OTL by OldTimer - Version 3.2.54.0 log created on 07262012_182326
     
  7. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Etavares, I hope it's okay I'm 'starting over again' with the OTL scans .... I'm not trying to deliberately be obtuse, just get more than a tad confused at time so I do appreciate your patience with me.

    Here's the first OTL Scan - using the 'Run Fix' button:

    Etavares, I hope it's okay I'm 'starting over again' with the OTL scans .... I'm not trying to deliberately be obtuse, just get more than a tad confused at time so I do appreciate your patience with me.

    Here's the first OTL Scan - using the 'Run Fix' button:
    ========== OTL ==========
    Error: No service named WISOVD was found to stop!
    Service\Driver key WISOVD not found.
    File C:\Programs not found.
    Error: No service named WDICA was found to stop!
    Service\Driver key WDICA not found.
    Error: No service named UrlFilter was found to stop!
    Service\Driver key UrlFilter not found.
    File C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys not found.
    Error: No service named RegFilter was found to stop!
    Service\Driver key RegFilter not found.
    File C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys not found.
    Error: No service named PDRFRAME was found to stop!
    Service\Driver key PDRFRAME not found.
    Error: No service named PDRELI was found to stop!
    Service\Driver key PDRELI not found.
    Error: No service named PDFRAME was found to stop!
    Service\Driver key PDFRAME not found.
    Error: No service named PDCOMP was found to stop!
    Service\Driver key PDCOMP not found.
    Error: No service named PCIDump was found to stop!
    Service\Driver key PCIDump not found.
    Error: No service named Monfilt was found to stop!
    Service\Driver key Monfilt not found.
    File system32\drivers\Monfilt.sys not found.
    Error: No service named lbrtfdc was found to stop!
    Service\Driver key lbrtfdc not found.
    Error: No service named IntcAzAudAddService) Service for Realtek HD Audio (WDM was found to stop!
    Service\Driver key IntcAzAudAddService) Service for Realtek HD Audio (WDM not found.
    File system32\drivers\RtkHDAud.sys not found.
    Error: No service named i2omgmt was found to stop!
    Service\Driver key i2omgmt not found.
    Error: No service named FileMonitor was found to stop!
    Service\Driver key FileMonitor not found.
    File C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys not found.
    Error: No service named Changer was found to stop!
    Service\Driver key Changer not found.
    Error: No service named Ambfilt was found to stop!
    Service\Driver key Ambfilt not found.
    File system32\drivers\Ambfilt.sys not found.
    Error: No service named SmcService was found to stop!
    Service\Driver key SmcService not found.
    File C:\Programs not found.
    Error: No service named SkypeUpdate was found to stop!
    Service\Driver key SkypeUpdate not found.
    File C:\Programs not found.
    Error: No service named NMSAccessU was found to stop!
    Service\Driver key NMSAccessU not found.
    File C:\Programs not found.
    Error: Unable to stop service MBAMService!
    Service\Driver key MBAMService not found.
    File C:\Programs not found.
    Error: No service named IMFservice was found to stop!
    Service\Driver key IMFservice not found.
    File C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe not found.
    Error: No service named AdvancedSystemCareService5 was found to stop!
    Service\Driver key AdvancedSystemCareService5 not found.
    File C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe not found.
    Error: No service named AdvancedSystemCareService was found to stop!
    Service\Driver key AdvancedSystemCareService not found.
    File C:\Programs not found.
    Error: No service named AdobeActiveFileMonitor7.0 was found to stop!
    Service\Driver key AdobeActiveFileMonitor7.0 not found.
    File C:\Programs not found.
    Error: No service named ADExchange was found to stop!
    Service\Driver key ADExchange not found.
    File C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    Registry key HKEY_USERS\S-1-5-21-343818398-2111687655-682003330-1003\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SearchSettings\ not found.
    ========== FILES ==========
    File\Folder C:\Program Files\Common Files\Spigot not found.
    File\Folder C:\Documents and Settings\Glen\Application Data\Search Settings not found.

    OTL by OldTimer - Version 3.2.54.0 log created on 07262012_204523


    Will be back with the second OTL scan the moment it's finished.
     
  8. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Here's the other OTL Scan - using the 'Run Scan' button:

    OTL logfile created on: 7/26/2012 8:48:44 PM - Run 4
    OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Glen\Desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.22 Gb Total Physical Memory | 2.29 Gb Available Physical Memory | 71.24% Memory free
    6.27 Gb Paging File | 5.40 Gb Available in Paging File | 86.00% Paging File free
    Paging file location(s): C:\pagefile.sys 0 0 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 458.75 Gb Total Space | 357.12 Gb Free Space | 77.85% Space Free | Partition Type: NTFS

    Computer Name: GLEN-F50AB654EA | User Name: Glen | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    PRC - [2012/07/19 15:10:36 | 000,792,512 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
    PRC - [2012/07/18 22:21:32 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
    PRC - [2012/07/13 16:19:16 | 000,646,800 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\saUI.exe
    PRC - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    PRC - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
    PRC - [2012/05/09 21:26:15 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    PRC - [2012/05/09 21:26:15 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/04/04 15:56:38 | 000,981,680 | ---- | M] (Malwarebytes Corporation) -- C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbam.exe
    PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2011/05/15 12:53:20 | 000,325,512 | ---- | M] (BillP Studios) -- C:\Programs - SECURITY\WinPatrol - doggie\WinPatrol.exe
    PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2006/12/13 18:03:50 | 000,739,328 | ---- | M] () -- C:\Programs - SECURITY\SNAG SCREEN\SnagScreen.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/07/18 22:21:31 | 002,003,424 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
    MOD - [2012/05/09 21:26:16 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
    MOD - [2011/11/05 19:28:07 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
    MOD - [2011/11/03 08:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
    MOD - [2011/04/14 18:01:33 | 000,548,854 | ---- | M] () -- C:\Programs - SECURITY\WinPatrol - doggie\sqlite3.dll
    MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
    MOD - [2008/09/02 13:29:52 | 000,098,304 | ---- | M] () -- C:\Programs - PHOTO\Photo!Edit May 2011\Photo! Editor\IvBar\ivbshlext.dll
    MOD - [2008/09/01 22:39:06 | 000,804,352 | ---- | M] () -- C:\Programs - PHOTO\Photo!Edit May 2011\Photo! Editor\IvBar\locs.dll
    MOD - [2008/04/13 17:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
    MOD - [2008/04/13 17:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
    MOD - [2006/12/13 18:03:50 | 000,739,328 | ---- | M] () -- C:\Programs - SECURITY\SNAG SCREEN\SnagScreen.exe


    ========== Win32 Services (SafeList) ==========

    SRV - [2012/07/19 15:10:36 | 000,792,512 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
    SRV - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
    SRV - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011/11/09 13:21:36 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - [2012/07/26 19:40:28 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
    DRV - [2012/05/09 21:26:16 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
    DRV - [2012/05/09 21:26:16 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
    DRV - [2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2011/10/11 15:00:32 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
    DRV - [2011/08/09 16:33:58 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BANTExt.sys -- (BANTExt)
    DRV - [2010/11/26 18:02:52 | 000,014,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
    DRV - [2010/08/04 06:16:54 | 002,127,728 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
    DRV - [2009/11/29 23:31:42 | 000,050,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
    DRV - [2009/11/12 14:48:56 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
    DRV - [2009/06/29 04:59:14 | 000,142,592 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
    DRV - [2009/06/26 18:21:02 | 001,956,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX3000.sys -- (VX3000)
    DRV - [2004/10/15 18:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg6n.sys -- (wg6n)
    DRV - [2004/10/15 18:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg5n.sys -- (wg5n)
    DRV - [2004/10/15 18:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg4n.sys -- (wg4n)
    DRV - [2004/10/15 18:32:38 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg3n.sys -- (wg3n)
    DRV - [2004/10/15 18:18:46 | 000,021,075 | ---- | M] (Sygate Technologies, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\wpsdrvnt.sys -- (wpsdrvnt)
    DRV - [2004/10/15 18:17:02 | 000,060,496 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\Teefer.sys -- (Teefer)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\NCH FileBulldog Toolbar\tbhelper.dll ()
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes,DefaultScope = {F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Yahoo"
    FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
    FF - prefs.js..browser.search.selectedEngine: "Google"
    FF - prefs.js..browser.startup.homepage: "http://home.mytelus.com/telusen/portal/index.aspx"
    FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p="
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/07/20 06:15:55 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/18 22:21:34 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/06/20 11:05:37 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

    [2011/10/20 20:41:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Extensions
    [2012/07/25 22:34:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\fo0zfocb.default\extensions
    [2011/12/12 15:35:11 | 000,000,000 | ---D | M] (NCH FileBulldog Toolbar) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\fo0zfocb.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
    [2012/07/14 11:22:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2012/04/20 09:06:55 | 000,085,537 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\AFTERTHEDEADLINE@AFTERTHEDEADLINE.COM.XPI
    [2012/07/25 22:34:14 | 000,599,034 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FIREFOXADDON@SIMILARWEB.COM.XPI
    [2012/07/18 12:39:23 | 000,040,533 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FLATBM@XULDEV.ORG.XPI
    [2012/02/07 18:21:25 | 000,113,603 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\NOSQUINT@URANDOM.CA.XPI
    [2012/07/20 06:15:55 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
    [2011/10/29 15:26:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
    [2012/07/18 22:21:33 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2012/05/02 13:22:24 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
    [2012/02/19 23:37:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2012/05/02 13:22:24 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
    [2012/05/02 13:22:24 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
    [2012/07/14 11:29:22 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
    [2012/05/02 13:22:27 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
    [2012/05/02 13:22:24 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

    O1 HOSTS File: ([2006/03/15 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O3 - HKLM\..\Toolbar: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
    O3 - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\Toolbar\WebBrowser: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SmcService] C:\Programs - SECURITY\Sygate - FIREWALL\Smc.exe (Sygate Technologies, Inc.)
    O4 - HKLM..\Run: [WinPatrol] C:\Programs - SECURITY\WinPatrol - doggie\winpatrol.exe (BillP Studios)
    O4 - Startup: C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342391681625 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 75.153.176.9
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE6FF7B-9D9D-4B11-B6A4-E8A5AD181751}: DhcpNameServer = 192.168.1.254 75.153.176.9
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2011/10/20 20:14:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/07/26 18:20:59 | 000,000,000 | ---D | C] -- C:\_OTL
    [2012/07/26 18:10:38 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2012/07/25 18:31:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2012/07/25 18:31:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
    [2012/07/25 18:31:01 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
    [2012/07/25 18:28:38 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/24 15:31:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\AnvSoft Movie DVD Maker
    [2012/07/24 12:33:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\Photostage Projects
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\YouTube Downloader Toolbar
    [2012/07/24 11:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
    [2012/07/24 01:29:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\BolideSoftware
    [2012/07/23 01:22:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\TuneUp Software
    [2012/07/23 01:22:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    [2012/07/23 01:21:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
    [2012/07/22 20:48:32 | 000,000,000 | ---D | C] -- C:\Program Files\Belarc
    [2012/07/22 18:17:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\ESTATE documents
    [2012/07/21 21:36:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Driver Tool
    [2012/07/21 17:42:00 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:27:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\WMTools Downloaded Files
    [2012/07/21 00:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\Speccy
    [2012/07/20 10:51:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Sun
    [2012/07/19 23:53:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Temp
    [2012/07/19 17:45:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
    [2012/07/19 17:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
    [2012/07/19 17:45:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Oracle
    [2012/07/19 17:45:09 | 000,772,544 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
    [2012/07/19 17:45:09 | 000,227,824 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 12:32:28 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
    [2012/07/19 12:14:32 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/18 22:19:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z computer woes, mid July
    [2012/07/18 20:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
    [2012/07/18 20:14:23 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonMP Uninstaller Information
    [2012/07/18 20:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP150
    [2012/07/18 20:14:07 | 000,000,000 | -H-D | C] -- C:\CanonMP
    [2012/07/18 19:42:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Start Menu\Programs\Revo Uninstaller
    [2012/07/17 12:09:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z legal templates READY
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    [2012/07/14 15:41:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Windows Search
    [2012/07/01 12:03:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IdealSoftware
    [2012/07/01 12:03:40 | 000,000,000 | ---D | C] -- C:\IDEALDVDCOPY_TEMP
    [2012/07/01 12:03:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Ideal DVD Copy
    [2012/07/01 12:03:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\IdealSoftware
    [2012/06/27 11:10:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\zz BURN TO CD for my SYLVIA
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/07/26 22:00:00 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\prismDowngrade.job
    [2012/07/26 20:48:29 | 000,614,934 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\BIG SEEK confused.BMP
    [2012/07/26 19:40:28 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2012/07/26 19:37:33 | 000,000,364 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\bookcases, Craig's list.rtf
    [2012/07/26 18:14:08 | 000,845,934 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Malwarebytes won't respond.BMP
    [2012/07/26 17:45:38 | 000,001,312 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to FreeVideoToAudioConverter.exe.lnk
    [2012/07/26 16:14:40 | 000,001,287 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\wedding historynt.rtf
    [2012/07/26 15:33:54 | 000,000,720 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\fixing out of sync video.rtf
    [2012/07/26 13:38:04 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/26 13:29:05 | 000,063,648 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\woodland_shoot_018.jpg
    [2012/07/26 10:03:17 | 000,343,511 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\xmh4apww.jpg
    [2012/07/26 08:07:55 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/26 08:07:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/07/25 20:36:57 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\etavares f.rtf
    [2012/07/25 20:10:42 | 000,790,242 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\doug 02.BMP
    [2012/07/25 20:09:17 | 000,074,838 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\doug 01.BMP
    [2012/07/25 18:31:19 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/25 18:28:40 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/24 22:08:46 | 000,000,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | M] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:37:39 | 000,208,384 | ---- | M] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/07/24 15:14:07 | 000,000,700 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 13:50:22 | 000,038,198 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:15 | 000,000,235 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 21:01:36 | 000,001,723 | ---- | M] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 21:01:36 | 000,001,705 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Belarc Advisor.lnk
    [2012/07/22 20:57:34 | 000,000,833 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 14:34:08 | 000,001,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:18 | 000,020,973 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 19:21:51 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\MBR.dat
    [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:35:56 | 000,188,416 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\deer and green.jpg
    [2012/07/21 00:31:56 | 000,002,385 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Microsoft Office PowerPoint Viewer 2007.lnk
    [2012/07/21 00:15:26 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 17:44:48 | 000,227,824 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 17:44:48 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
    [2012/07/19 12:14:32 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/19 08:00:14 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/07/18 20:18:58 | 000,001,693 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 19:43:00 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Revo Uninstaller.lnk
    [2012/07/18 12:22:36 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/16 19:49:55 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\PixillionDowngrade.job
    [2012/07/16 18:23:46 | 000,002,437 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
    [2012/07/15 15:26:34 | 000,242,328 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2012/07/14 11:26:19 | 000,502,962 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2012/07/14 11:26:19 | 000,087,046 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2012/07/14 04:45:28 | 000,025,019 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.lst
    [2012/07/07 14:42:02 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite
    [2012/07/06 11:47:01 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\switchShakeIcon.job
    [2012/07/05 22:06:30 | 000,772,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
    [2012/07/05 22:06:20 | 000,687,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
    [2012/07/01 12:03:37 | 000,000,955 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Ideal DVD Copy.lnk
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/07/26 20:48:29 | 000,614,934 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\BIG SEEK confused.BMP
    [2012/07/26 19:24:03 | 000,000,364 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\bookcases, Craig's list.rtf
    [2012/07/26 18:14:07 | 000,845,934 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Malwarebytes won't respond.BMP
    [2012/07/26 16:14:39 | 000,001,287 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\wedding historynt.rtf
    [2012/07/26 15:25:42 | 000,000,720 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\fixing out of sync video.rtf
    [2012/07/26 13:38:03 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/26 10:04:22 | 000,357,916 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\light-yellow-rose-garden-wedding-dress.jpg
    [2012/07/26 10:03:26 | 000,343,511 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\xmh4apww.jpg
    [2012/07/25 20:10:42 | 000,790,242 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\doug 02.BMP
    [2012/07/25 20:09:17 | 000,074,838 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\doug 01.BMP
    [2012/07/25 20:00:22 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\etavares f.rtf
    [2012/07/25 18:31:19 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/24 22:08:46 | 000,000,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | C] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:13:37 | 000,000,700 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 01:42:54 | 000,038,198 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:14 | 000,000,235 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 20:57:34 | 000,000,833 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 20:48:35 | 000,001,723 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 20:48:35 | 000,001,705 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Belarc Advisor.lnk
    [2012/07/22 20:48:34 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Belarc Advisor.lnk
    [2012/07/22 20:48:32 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
    [2012/07/22 14:34:08 | 000,001,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:17 | 000,020,973 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 19:21:51 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\MBR.dat
    [2012/07/21 00:35:56 | 000,188,416 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\deer and green.jpg
    [2012/07/21 00:15:26 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 12:32:51 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 20:15:16 | 000,001,693 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 12:32:39 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/18 12:22:36 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/14 04:44:45 | 000,025,019 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.lst
    [2012/07/07 14:42:02 | 000,000,000 | ---- | C] () -- C:\extensions.sqlite
    [2012/07/06 10:41:28 | 000,034,207 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\ANIMATED blow bubbles.gif
    [2012/07/02 17:38:09 | 000,002,385 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Microsoft Office PowerPoint Viewer 2007.lnk
    [2012/07/01 12:03:37 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Ideal DVD Copy.lnk
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
    [2012/06/12 13:31:10 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5002.dll
    [2012/06/12 13:31:03 | 002,026,604 | R--- | C] () -- C:\WINDOWS\System32\igkrng500.bin
    [2012/06/12 13:31:03 | 000,442,964 | R--- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
    [2012/02/15 02:55:59 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
    [2012/01/23 03:26:22 | 000,135,189 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\PhotoStage.dmp
    [2012/01/20 15:10:52 | 000,311,296 | ---- | C] () -- C:\WINDOWS\System32\EMRegSys.dll
    [2012/01/09 13:00:48 | 004,346,880 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
    [2012/01/07 15:22:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\libbluray.dll
    [2012/01/07 15:21:50 | 006,366,094 | ---- | C] () -- C:\WINDOWS\System32\avcodec-lav-53.dll
    [2012/01/07 15:21:50 | 001,007,151 | ---- | C] () -- C:\WINDOWS\System32\avformat-lav-53.dll
    [2012/01/07 15:21:50 | 000,354,979 | ---- | C] () -- C:\WINDOWS\System32\swscale-lav-2.dll
    [2012/01/07 15:21:50 | 000,203,306 | ---- | C] () -- C:\WINDOWS\System32\avutil-lav-51.dll
    [2012/01/07 15:21:50 | 000,138,727 | ---- | C] () -- C:\WINDOWS\System32\avfilter-lav-2.dll
    [2012/01/06 03:19:39 | 000,163,029 | ---- | C] () -- C:\WINDOWS\DP Animation Maker Uninstaller.exe
    [2011/12/20 11:50:04 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2011/12/20 11:49:56 | 000,099,328 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
    [2011/12/20 11:49:54 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
    [2011/12/20 11:49:54 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
    [2011/12/20 11:49:52 | 001,525,248 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
    [2011/12/20 11:49:52 | 000,212,480 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
    [2011/12/20 11:49:52 | 000,115,200 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
    [2011/12/20 11:49:50 | 000,328,704 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
    [2011/12/20 11:49:50 | 000,260,608 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
    [2011/12/20 11:49:50 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
    [2011/12/12 22:58:51 | 000,160,992 | ---- | C] () -- C:\WINDOWS\Sqirlz Water Reflections Uninstaller.exe
    [2011/12/07 12:32:24 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\Lagarith.dll
    [2011/11/30 22:01:20 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7K.DLL
    [2011/11/30 16:51:44 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
    [2011/11/23 03:50:10 | 000,276,255 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-343818398-2111687655-682003330-1003-0.dat
    [2011/11/23 03:50:06 | 000,171,618 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
    [2011/11/21 16:54:54 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\fusioncache.dat
    [2011/11/20 00:41:53 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
    [2011/10/30 17:33:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\Cool Motion.dll
    [2011/10/29 19:08:34 | 000,025,944 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
    [2011/10/29 19:08:33 | 000,014,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
    [2011/10/21 18:16:47 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\sh33w32.dll
    [2011/10/21 18:02:03 | 000,208,384 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/10/20 20:21:24 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
    [2011/10/20 20:20:18 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
    [2011/10/20 20:16:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2011/10/20 20:09:43 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2011/10/20 13:01:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2011/10/20 13:00:24 | 000,242,328 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2011/09/08 07:00:52 | 000,150,528 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
    [2011/09/08 07:00:48 | 000,142,336 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
    [2011/09/08 07:00:42 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
    [2011/09/08 07:00:38 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
    [2011/09/08 07:00:34 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\dsmux.exe
    [2011/09/08 07:00:24 | 000,154,624 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
    [2011/09/08 07:00:10 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\mkv2vfr.exe
    [2011/09/08 07:00:06 | 000,358,400 | ---- | C] () -- C:\WINDOWS\System32\gdsmux.exe
    [2011/09/08 06:59:54 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
    [2011/09/08 06:59:52 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
    [2011/05/30 06:42:50 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2011/05/23 00:46:30 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2011/03/03 04:39:56 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
    [2011/03/03 04:38:10 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
    [2011/03/03 04:37:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
    [2011/02/15 05:46:02 | 014,454,784 | ---- | C] () -- C:\WINDOWS\System32\common_res.dll
    [2010/08/18 12:56:38 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini

    ========== Custom Scans ==========

    < :OTL >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Programs -- (WISOVD) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys -- (UrlFilter) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys -- (RegFilter) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Monfilt.sys -- (Monfilt) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) >

    < DRV - File not found [File_System | Disabled | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor) >

    < DRV - File not found [Kernel | System | Stopped] -- -- (Changer) >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Ambfilt.sys -- (Ambfilt) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (SmcService) >

    < SRV - File not found [Auto | Stopped] -- C:\Programs -- (SkypeUpdate) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (NMSAccessU) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (MBAMService) >

    < SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice) >

    < SRV - File not found [Auto | Stopped] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (AdvancedSystemCareService) >

    < SRV - File not found [Auto | Running] -- C:\Programs -- (AdobeActiveFileMonitor7.0) >

    < SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe -- (ADExchange) >

    < IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B} >
    Invalid Switch: www.bigseekpr...4-89606D287C1B}

    < IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B} >
    Invalid Switch: www.bigseekpr...4-89606D287C1B}

    < IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms} >

    < MsConfig - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) >

    < :files >

    < C:\Program Files\Common Files\Spigot >

    < C:\Documents and Settings\Glen\Application Data\Search Settings >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8423A1CF

    < End of report >
     
  9. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    (Couldn't interpret these scans myself for love nor money and don't know if this matters at all, but I've never used "Amazon or eBay or Twitter', let along their tool bars ...nor something called 'Tune-Up Software - in fact, never even realized I had them).

    This came up a few times and I'm not sure what it is so just clicking 'no' - hope that's the right thing to do.
    [​IMG]

    Thank you very much once again!
     
  10. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hello, Mara.

    It's still not running correctly. I did forget to mention to disable WinPatrol before running these commands...you can turn it off after completing step 2.




    Step 1

    Please uninstall any of the following program(s) using Add/Remove Programs if they are present. To do this, go to Start > Settings > Control Panel and double-click on Add/Remove Programs. From within Add/Remove Programs highlight each one and select Remove.

    YouTube Downloader 3.4
    YouTube Downloader Toolbar v6.0
    NCH FileBulldog Toolbar



    Be sure to reboot when done.



    Step 2

    Please pull anything out of the recycle bin that you want to save. Part of this fix will empty temp files, and that does include the recycle bin.

    We need run an OTL Script
    1. Please download OTL from one of the following mirrors if you do not still have it.
    2. Save it to your desktop.
    3. Double click on the [​IMG] icon on your desktop.
    4. Paste the following code under the Custom Scans/Fixes box at the bottom.
      Code:
      :OTL
      DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B}
      IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B}
      IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms}
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B}
      IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
      IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
      IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\NCH FileBulldog Toolbar\tbhelper.dll ()
      IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
      IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms}
      O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
      O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
      O3 - HKLM\..\Toolbar: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
      O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
      O3 - HKCU\..\Toolbar\WebBrowser: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll ()
      MsConfig - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
      :files
      C:\Program Files\Common Files\Spigot
      C:\Program Files\NCH FileBulldog Toolbar\
      C:\Program Files\YouTube Downloader Toolbar
      C:\Documents and Settings\Glen\Application Data\Search Settings
      :Commands
      [EmptyTemp]
      
    5. Click the Run Fix button at the top.
    6. let the program run unhindered and reboot when it is done.
    7. You will get a log when it is done, please post that in your reply.
    8. Please then create a new OTL report....
    9. Click the "Scan All Users" checkbox.
    10. Push the [​IMG] button.
    11. A report will open, copy and paste it in a reply here.
    etavares
     
  11. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    I do hope you'll forgive my adding little things that you've not asked for - and if they aren't any help, please just 'dump' - thanks so much.

    Seem to spend more time thumping 'ctrl/alt/del' than doing anything else and in fact, am having a hard time typing this post as something called:

    "soffice.bin" keeps throwing up a "The program is not responding". Have no idea what it is, but it's taking to living on my screen.

    Anyway, I do apologise if these aren't at all helpful ...

    [​IMG]

    And the below with only Snagscreen and page here at our computer home running when I opened Windows Task Manager:
    [​IMG]
     
  12. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Hi etavare,

    Deleted the things and disabled 'Scotty' before starting the OTL 'Run Fix' ... and here's the results of that part of the scan ..
    All processes killed
    ========== OTL ==========
    Error: No service named IntcAzAudAddService) Service for Realtek HD Audio (WDM was found to stop!
    Service\Driver key IntcAzAudAddService) Service for Realtek HD Audio (WDM not found.
    File system32\drivers\RtkHDAud.sys not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    Registry key HKEY_USERS\S-1-5-21-343818398-2111687655-682003330-1003\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
    Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{CA3EB689-8F09-4026-AA10-B9534C691CE0} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\ not found.
    File C:\Program Files\NCH FileBulldog Toolbar\tbhelper.dll not found.
    Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{F3FEE66E-E034-436a-86E4-9690573BEE8A} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3FEE66E-E034-436a-86E4-9690573BEE8A}\ not found.
    File C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3FEE66E-E034-436a-86E4-9690573BEE8A}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3FEE66E-E034-436a-86E4-9690573BEE8A}\ not found.
    File C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ not found.
    File C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{338B4DFE-2E2C-4338-9E41-E176D497299E} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}\ not found.
    File C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{F3FEE66E-E034-436a-86E4-9690573BEE8A} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3FEE66E-E034-436a-86E4-9690573BEE8A}\ not found.
    File C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{338B4DFE-2E2C-4338-9E41-E176D497299E} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}\ not found.
    File C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SearchSettings\ not found.
    ========== FILES ==========
    File\Folder C:\Program Files\Common Files\Spigot not found.
    Folder C:\Program Files\NCH FileBulldog Toolbar not found.
    File\Folder C:\Program Files\YouTube Downloader Toolbar not found.
    File\Folder C:\Documents and Settings\Glen\Application Data\Search Settings not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Glen
    ->Temp folder emptied: 1162778676 bytes
    ->Temporary Internet Files folder emptied: 4188263 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 1156846086 bytes
    ->Flash cache emptied: 7762 bytes

    User: LocalService
    ->Temp folder emptied: 66016 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33237 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 1240100 bytes
    %systemroot%\System32 .tmp files removed: 2675729 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 7174440 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 129406472 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes
    RecycleBin emptied: 420994209 bytes

    Total Files Cleaned = 2,752.00 mb


    OTL by OldTimer - Version 3.2.54.0 log created on 07272012_234807

    Files\Folders moved on Reboot...

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  13. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    And here is the 'Run Scan' part of the OTL ... and thanks so much once again!

    OTL logfile created on: 7/28/2012 12:02:06 AM - Run 5
    OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Glen\Desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.22 Gb Total Physical Memory | 2.67 Gb Available Physical Memory | 83.05% Memory free
    6.27 Gb Paging File | 5.79 Gb Available in Paging File | 92.26% Paging File free
    Paging file location(s): C:\pagefile.sys 0 0 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 458.75 Gb Total Space | 360.25 Gb Free Space | 78.53% Space Free | Partition Type: NTFS

    Computer Name: GLEN-F50AB654EA | User Name: Glen | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    PRC - [2012/07/18 22:21:32 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
    PRC - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    PRC - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
    PRC - [2012/05/09 21:26:15 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    PRC - [2012/05/09 21:26:15 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2011/05/15 12:53:20 | 000,325,512 | ---- | M] (BillP Studios) -- C:\Programs - SECURITY\WinPatrol - doggie\WinPatrol.exe
    PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/07/18 22:21:31 | 002,003,424 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
    MOD - [2012/05/09 21:26:16 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
    MOD - [2011/11/05 19:28:07 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
    MOD - [2011/11/03 08:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
    MOD - [2011/04/14 18:01:33 | 000,548,854 | ---- | M] () -- C:\Programs - SECURITY\WinPatrol - doggie\sqlite3.dll
    MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
    MOD - [2008/04/13 17:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
    MOD - [2008/04/13 17:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll


    ========== Win32 Services (SafeList) ==========

    SRV - [2012/06/15 12:26:22 | 000,095,232 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
    SRV - [2012/05/09 21:26:16 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2012/05/09 21:26:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011/11/09 13:21:36 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - [2012/05/09 21:26:16 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
    DRV - [2012/05/09 21:26:16 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
    DRV - [2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2011/10/11 15:00:32 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
    DRV - [2011/08/09 16:33:58 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BANTExt.sys -- (BANTExt)
    DRV - [2010/11/26 18:02:52 | 000,014,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
    DRV - [2010/08/04 06:16:54 | 002,127,728 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
    DRV - [2009/11/29 23:31:42 | 000,050,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
    DRV - [2009/11/12 14:48:56 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
    DRV - [2009/06/29 04:59:14 | 000,142,592 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
    DRV - [2009/06/26 18:21:02 | 001,956,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX3000.sys -- (VX3000)
    DRV - [2004/10/15 18:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg6n.sys -- (wg6n)
    DRV - [2004/10/15 18:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg5n.sys -- (wg5n)
    DRV - [2004/10/15 18:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg4n.sys -- (wg4n)
    DRV - [2004/10/15 18:32:38 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg3n.sys -- (wg3n)
    DRV - [2004/10/15 18:18:46 | 000,021,075 | ---- | M] (Sygate Technologies, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\wpsdrvnt.sys -- (wpsdrvnt)
    DRV - [2004/10/15 18:17:02 | 000,060,496 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\Teefer.sys -- (Teefer)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
    IE - HKLM\..\SearchScopes,DefaultScope =


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com chfilebulldog/{01F88567-4CC7-4456-A0A4-89606D287C1B}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes,DefaultScope = {F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{F673FC1B-4FF6-4424-8B1F-96CFCD3AB53A}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
    IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Yahoo"
    FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
    FF - prefs.js..browser.search.selectedEngine: "Google"
    FF - prefs.js..browser.startup.homepage: "http://home.mytelus.com/telusen/portal/index.aspx"
    FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p="
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/07/20 06:15:55 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/18 22:21:34 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/06/20 11:05:37 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

    [2011/10/20 20:41:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Extensions
    [2012/07/27 23:39:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\fo0zfocb.default\extensions
    [2012/07/14 11:22:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2012/04/20 09:06:55 | 000,085,537 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\AFTERTHEDEADLINE@AFTERTHEDEADLINE.COM.XPI
    [2012/07/25 22:34:14 | 000,599,034 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FIREFOXADDON@SIMILARWEB.COM.XPI
    [2012/07/18 12:39:23 | 000,040,533 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\FLATBM@XULDEV.ORG.XPI
    [2012/02/07 18:21:25 | 000,113,603 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FO0ZFOCB.DEFAULT\EXTENSIONS\NOSQUINT@URANDOM.CA.XPI
    [2012/07/20 06:15:55 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
    [2011/10/29 15:26:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
    [2012/07/18 22:21:33 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2012/05/02 13:22:24 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
    [2012/02/19 23:37:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2012/05/02 13:22:24 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
    [2012/05/02 13:22:24 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
    [2012/07/14 11:29:22 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
    [2012/05/02 13:22:27 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
    [2012/05/02 13:22:24 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

    O1 HOSTS File: ([2006/03/15 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programs - SECURITY\MALWARE BYTES\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SmcService] C:\Programs - SECURITY\Sygate - FIREWALL\Smc.exe (Sygate Technologies, Inc.)
    O4 - HKLM..\Run: [WinPatrol] C:\Programs - SECURITY\WinPatrol - doggie\winpatrol.exe (BillP Studios)
    O4 - Startup: C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342391681625 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 75.153.176.9
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE6FF7B-9D9D-4B11-B6A4-E8A5AD181751}: DhcpNameServer = 192.168.1.254 75.153.176.9
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glen\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2011/10/20 20:14:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    ========== Files/Folders - Created Within 14 Days ==========

    [2012/07/27 23:54:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Desktop\OTL scans
    [2012/07/26 18:20:59 | 000,000,000 | ---D | C] -- C:\_OTL
    [2012/07/25 18:31:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2012/07/25 18:31:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
    [2012/07/25 18:31:01 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
    [2012/07/25 18:28:38 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/24 15:31:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\AnvSoft Movie DVD Maker
    [2012/07/24 12:33:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\Photostage Projects
    [2012/07/24 01:29:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\BolideSoftware
    [2012/07/23 01:21:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
    [2012/07/22 20:48:32 | 000,000,000 | ---D | C] -- C:\Program Files\Belarc
    [2012/07/22 18:17:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\ESTATE documents
    [2012/07/21 21:36:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Driver Tool
    [2012/07/21 17:42:00 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:27:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\WMTools Downloaded Files
    [2012/07/21 00:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\Speccy
    [2012/07/20 10:51:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Sun
    [2012/07/19 23:53:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Local Settings\Application Data\Temp
    [2012/07/19 17:45:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
    [2012/07/19 17:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
    [2012/07/19 17:45:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Oracle
    [2012/07/19 17:45:09 | 000,772,544 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
    [2012/07/19 17:45:09 | 000,227,824 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:59 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 12:32:28 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
    [2012/07/19 12:14:32 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/18 22:19:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z computer woes, mid July
    [2012/07/18 20:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
    [2012/07/18 20:14:23 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonMP Uninstaller Information
    [2012/07/18 20:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP150
    [2012/07/18 20:14:07 | 000,000,000 | -H-D | C] -- C:\CanonMP
    [2012/07/18 19:42:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Start Menu\Programs\Revo Uninstaller
    [2012/07/17 12:09:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\My Documents\z legal templates READY
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
    [2012/07/16 18:07:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    [2012/07/14 15:41:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Glen\Application Data\Windows Search

    ========== Files - Modified Within 14 Days ==========

    [2012/07/27 23:53:20 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/27 23:53:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/07/27 23:36:56 | 000,000,156 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\30.rtf
    [2012/07/27 22:37:45 | 000,000,475 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\YOUTUBE - MY uploads.rtf
    [2012/07/27 17:36:58 | 000,434,530 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\soffice.bin
    [2012/07/27 17:28:32 | 001,010,518 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Windows Task Manager - Performance.BMP
    [2012/07/27 17:27:46 | 001,074,294 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Windows Task Manager - Processes.BMP
    [2012/07/27 16:53:13 | 000,209,920 | ---- | M] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/07/27 16:50:52 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/27 11:10:26 | 000,000,679 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Youtube - MY VIDEOS and info.rtf
    [2012/07/26 22:00:00 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\prismDowngrade.job
    [2012/07/26 20:48:29 | 000,614,934 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\BIG SEEK confused.BMP
    [2012/07/26 19:37:33 | 000,000,364 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\bookcases, Craig's list.rtf
    [2012/07/26 18:14:08 | 000,845,934 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Malwarebytes won't respond.BMP
    [2012/07/26 17:45:38 | 000,001,312 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to FreeVideoToAudioConverter.exe.lnk
    [2012/07/26 16:14:40 | 000,001,287 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\wedding historynt.rtf
    [2012/07/26 15:33:54 | 000,000,720 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\fixing out of sync video.rtf
    [2012/07/25 20:36:57 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\etavares f.rtf
    [2012/07/25 20:10:42 | 000,790,242 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\doug 02.BMP
    [2012/07/25 20:09:17 | 000,074,838 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\doug 01.BMP
    [2012/07/25 18:31:19 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/25 18:28:40 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Glen\Desktop\erunt-setup.exe
    [2012/07/24 22:08:46 | 000,000,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | M] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:14:07 | 000,000,700 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 13:50:22 | 000,038,198 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:15 | 000,000,235 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 21:01:36 | 000,001,723 | ---- | M] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 20:57:34 | 000,000,833 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 14:34:08 | 000,001,274 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:18 | 000,020,973 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 17:42:01 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Glen\Desktop\OTL.exe
    [2012/07/21 00:35:56 | 000,188,416 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\deer and green.jpg
    [2012/07/21 00:31:56 | 000,002,385 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Microsoft Office PowerPoint Viewer 2007.lnk
    [2012/07/21 00:15:26 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 17:44:48 | 000,227,824 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
    [2012/07/19 17:44:48 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
    [2012/07/19 17:44:48 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
    [2012/07/19 12:14:32 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/07/19 12:14:32 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/07/19 08:00:14 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/07/18 20:18:58 | 000,001,693 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 19:43:00 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Revo Uninstaller.lnk
    [2012/07/18 12:22:36 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/16 19:49:55 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\PixillionDowngrade.job
    [2012/07/16 18:23:46 | 000,002,437 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
    [2012/07/15 15:26:34 | 000,242,328 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2012/07/14 11:26:19 | 000,502,962 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2012/07/14 11:26:19 | 000,087,046 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2012/07/14 04:45:28 | 000,025,019 | ---- | M] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | M] () -- C:\WINDOWS\is-EK1Q8.lst

    ========== Files Created - No Company Name ==========

    [2012/07/27 23:36:56 | 000,000,156 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\30.rtf
    [2012/07/27 19:39:19 | 000,000,475 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\YOUTUBE - MY uploads.rtf
    [2012/07/27 17:36:58 | 000,434,530 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\soffice.bin
    [2012/07/27 17:28:32 | 001,010,518 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Windows Task Manager - Performance.BMP
    [2012/07/27 17:27:46 | 001,074,294 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Windows Task Manager - Processes.BMP
    [2012/07/27 16:50:51 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\photostageShakeIcon.job
    [2012/07/27 11:08:51 | 000,000,679 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Youtube - MY VIDEOS and info.rtf
    [2012/07/26 20:48:29 | 000,614,934 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\BIG SEEK confused.BMP
    [2012/07/26 19:24:03 | 000,000,364 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\bookcases, Craig's list.rtf
    [2012/07/26 18:14:07 | 000,845,934 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Malwarebytes won't respond.BMP
    [2012/07/26 16:14:39 | 000,001,287 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\wedding historynt.rtf
    [2012/07/26 15:25:42 | 000,000,720 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\fixing out of sync video.rtf
    [2012/07/25 20:10:42 | 000,790,242 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\doug 02.BMP
    [2012/07/25 20:09:17 | 000,074,838 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\doug 01.BMP
    [2012/07/25 20:00:22 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\etavares f.rtf
    [2012/07/25 18:31:19 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Glen\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/25 18:31:03 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\NTREGOPT.lnk
    [2012/07/25 18:31:03 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\ERUNT.lnk
    [2012/07/24 22:08:46 | 000,000,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\food bank depot.rtf
    [2012/07/24 19:27:26 | 000,000,144 | -H-- | C] () -- C:\Documents and Settings\Glen\My Documents\.~lock.SHRUB, have eMERALD gAIETY eUONYMUS.odt#
    [2012/07/24 15:13:37 | 000,000,700 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\sorting 27 July.rtf
    [2012/07/24 01:42:54 | 000,038,198 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\words friendship slide show.rtf
    [2012/07/23 22:28:14 | 000,000,235 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\as per e on our computer sites - uninstalls.rtf
    [2012/07/22 20:57:34 | 000,000,833 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Internet Explorer (No Add-ons).lnk
    [2012/07/22 20:48:35 | 000,001,723 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
    [2012/07/22 20:48:34 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Belarc Advisor.lnk
    [2012/07/22 20:48:32 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
    [2012/07/22 14:34:08 | 000,001,274 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\did I post this on Condor's thread.rtf
    [2012/07/21 23:01:17 | 000,020,973 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\Remote help for Mara.odt
    [2012/07/21 00:35:56 | 000,188,416 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\deer and green.jpg
    [2012/07/21 00:15:26 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Speccy.lnk
    [2012/07/19 12:32:51 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
    [2012/07/18 20:15:49 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
    [2012/07/18 20:15:16 | 000,001,693 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MP Navigator 2.0.lnk
    [2012/07/18 12:32:39 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
    [2012/07/18 12:22:36 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Glen\Desktop\Shortcut to moviemk.exe.lnk
    [2012/07/14 04:44:45 | 000,025,019 | ---- | C] () -- C:\Documents and Settings\Glen\My Documents\strange laws.odt
    [2012/07/14 00:23:59 | 000,010,550 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.msg
    [2012/07/14 00:23:59 | 000,000,539 | ---- | C] () -- C:\WINDOWS\is-EK1Q8.lst
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
    [2012/06/12 13:33:13 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
    [2012/06/12 13:31:10 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5002.dll
    [2012/06/12 13:31:03 | 002,026,604 | R--- | C] () -- C:\WINDOWS\System32\igkrng500.bin
    [2012/06/12 13:31:03 | 000,442,964 | R--- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
    [2012/02/15 02:55:59 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
    [2012/01/23 03:26:22 | 000,135,189 | ---- | C] () -- C:\Documents and Settings\Glen\Application Data\PhotoStage.dmp
    [2012/01/20 15:10:52 | 000,311,296 | ---- | C] () -- C:\WINDOWS\System32\EMRegSys.dll
    [2012/01/09 13:00:48 | 004,346,880 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
    [2012/01/07 15:22:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\libbluray.dll
    [2012/01/07 15:21:50 | 006,366,094 | ---- | C] () -- C:\WINDOWS\System32\avcodec-lav-53.dll
    [2012/01/07 15:21:50 | 001,007,151 | ---- | C] () -- C:\WINDOWS\System32\avformat-lav-53.dll
    [2012/01/07 15:21:50 | 000,354,979 | ---- | C] () -- C:\WINDOWS\System32\swscale-lav-2.dll
    [2012/01/07 15:21:50 | 000,203,306 | ---- | C] () -- C:\WINDOWS\System32\avutil-lav-51.dll
    [2012/01/07 15:21:50 | 000,138,727 | ---- | C] () -- C:\WINDOWS\System32\avfilter-lav-2.dll
    [2011/12/20 11:50:04 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2011/12/20 11:49:56 | 000,099,328 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
    [2011/12/20 11:49:54 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
    [2011/12/20 11:49:54 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
    [2011/12/20 11:49:52 | 001,525,248 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
    [2011/12/20 11:49:52 | 000,212,480 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
    [2011/12/20 11:49:52 | 000,115,200 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
    [2011/12/20 11:49:50 | 000,328,704 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
    [2011/12/20 11:49:50 | 000,260,608 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
    [2011/12/20 11:49:50 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
    [2011/12/12 22:58:51 | 000,160,992 | ---- | C] () -- C:\WINDOWS\Sqirlz Water Reflections Uninstaller.exe
    [2011/12/07 12:32:24 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\Lagarith.dll
    [2011/11/30 22:01:20 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7K.DLL
    [2011/11/30 16:51:44 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
    [2011/11/23 03:50:10 | 000,276,255 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-343818398-2111687655-682003330-1003-0.dat
    [2011/11/23 03:50:06 | 000,171,618 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
    [2011/11/21 16:54:54 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\fusioncache.dat
    [2011/11/20 00:41:53 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
    [2011/10/30 17:33:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\Cool Motion.dll
    [2011/10/29 19:08:34 | 000,025,944 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
    [2011/10/29 19:08:33 | 000,014,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
    [2011/10/21 18:16:47 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\sh33w32.dll
    [2011/10/21 18:02:03 | 000,209,920 | ---- | C] () -- C:\Documents and Settings\Glen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/10/20 20:21:24 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
    [2011/10/20 20:20:18 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
    [2011/10/20 20:16:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2011/10/20 20:09:43 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2011/10/20 13:01:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2011/10/20 13:00:24 | 000,242,328 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2011/09/08 07:00:52 | 000,150,528 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
    [2011/09/08 07:00:48 | 000,142,336 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
    [2011/09/08 07:00:42 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
    [2011/09/08 07:00:38 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
    [2011/09/08 07:00:34 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\dsmux.exe
    [2011/09/08 07:00:24 | 000,154,624 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
    [2011/09/08 07:00:10 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\mkv2vfr.exe
    [2011/09/08 07:00:06 | 000,358,400 | ---- | C] () -- C:\WINDOWS\System32\gdsmux.exe
    [2011/09/08 06:59:54 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
    [2011/09/08 06:59:52 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
    [2011/05/30 06:42:50 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2011/05/23 00:46:30 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2011/03/03 04:39:56 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
    [2011/03/03 04:38:10 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
    [2011/03/03 04:37:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
    [2010/08/18 12:56:38 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini

    ========== Custom Scans ==========

    < :OTL >

    < DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) >

    < IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B} >
    Invalid Switch: www.bigseekpr...4-89606D287C1B}

    < IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B} >
    Invalid Switch: www.bigseekpr...4-89606D287C1B}

    < IE - HKU\S-1-5-21-343818398-2111687655-682003330-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms} >

    < IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpr...4-89606D287C1B} >
    Invalid Switch: www.bigseekpr...4-89606D287C1B}

    < IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} >

    < IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?} >

    < IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\NCH FileBulldog Toolbar\tbhelper.dll () >

    < IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.) >

    < IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpr...q={searchTerms} >

    < O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.) >

    < O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll () >

    < O3 - HKLM\..\Toolbar: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll () >

    < O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\6.1\youtubedownloaderToolbarIE.dll (Spigot, Inc.) >

    < O3 - HKCU\..\Toolbar\WebBrowser: (NCH FileBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\NCH FileBulldog Toolbar\tbcore3.dll () >

    < MsConfig - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) >

    < :files >

    < C:\Program Files\Common Files\Spigot >

    < C:\Program Files\NCH FileBulldog Toolbar\ >

    < C:\Program Files\YouTube Downloader Toolbar >

    < C:\Documents and Settings\Glen\Application Data\Search Settings >

    < :Commands >

    < [EmptyTemp] >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8423A1CF

    < End of report >
     
  14. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Sorry for the delay...crazy day yesterday. It's looking better. soffice.bin is related to OpenOffice. How is your computer running now?
     
  15. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    PS> You can uninstall and reinstall OpenOffice if you want.
     
  16. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    No problem at all about the 'delay', etavares - none at all as you are entitled to a life away from the computer - huge smile!

    Yes, it's running much, much better now and I've uninstalled and then reinstalled Open Office, too.

    Thank you so very much for your wonderful help - I truly appreciate it!

     
  17. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hello, Mara.

    It was my daughter's first birthday, so the life away form the computer was quite important. :)

    Please keep ERUNT installed for now...we'll clean up, then please let me know how the computer is running in another day or two...e.g. is it slow or back to normal? If it looks good, we'll uninstall ERUNT.


    Step 1

    Next, we need to remove the other tools we have used.
    • Please download OTC by OldTimer and save it to you desktop
    • If that link doesn't work, try this one.
    • Doubleclick the [​IMG] icon to start the program.
    • Then, click the big [​IMG] button.
    • You will get a prompt saying Begin Cleanup Process. Click Yes.
    • Restart your computer when prompted.



    Step 2

    We need to purge your system restore so malware is not accidently restored. First, let's create a new restore point.
    1. Go to Start --> All Programs --> Accessories --> System Tools --> System Restore.
    2. Select Create a Restore Point and click Next.
    3. Give the restore point a name and press create.
    4. You'll see it work, then say that it was created sucessfully. Click Close.


    Now, we need to remove the old, infected points using DiskCleanup.
    1. Click on Start --> Run.
    2. Type in cleanmgr into the run box and hit OK.
    3. Select C: and press OK
    4. Select the More Options tab.
    5. Click on Clean up in the System Restore section..
    6. Click OK.
    7. You'll get a couple of prompts asking if you're sure you want do to this, select Yes and OK for them.
    8. Disk cleanup will remove the old restore points that included the malware.

    etavares
     
  18. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    First, a very very happy belated Birthday to your precious little daughter, etavares - I bet she is simply and utterly adorable!
    [​IMG]
     
  19. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    I ran the OTL 'Clean up' using the original OTL that I'd downloaded, and thank you. (Just as reference, the second live link - the 'try this one' link - leads to a page that wanted me to sign into to gain access to).... and followed your other steps and ta da, finished now.

    Thank you again for all your help, etavares - the computer is run normally once again - really really appreciate your kindness!
     
  20. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    AH, thanks for letting me know about that link. OldTimer doesn't host his tool there anymore...he has about five or ten different ones. It looks like I missed it here. I updated my speech. And thanks for the birthday wish! :) We're all good here unless you have any other questions or issues with your computer.
     

Share This Page