She used a USB device(micro SD inserted) and import/exported some files, musics and such.
And what happend is, suddenly my computer starts to send group messages to all my buddy`s in my friend list of my Yahoo Messenger.
I then turned my anti virus program`s shield on. And fully scanned my system. (I use aVast! Antivirus)
Which exposed 3 viruses, I deleted them.
And I ran my "CCleaner" PC cleaning program. And refreshed my PC or whatever the case it does to speed up or whatever.
And restarted my PC.
That simple task didn`t solve my problem.
This also wouldn`t allow me to let visit any antivirus, or even microsoft websites.
Not to mention It won`t even let me install MMORPG-online games. (When I run the installer no installer setup pops out, and does not show on my Task Manager`s "Applications" but shows on the "Processes" tab but with only a small memory usage size of below 100kb)
Before I ended up here in your forum, I by the way, System restored just around 4hours ago.
To May,26,2011 system checkpoint.
Thinking it might go back to "none infected".Though I was stupid, it also didn`t work out.
Oh! Also, hours ago my TaskManager went "taskmanager has been disabled by the administrator". And trying to edit my computer config were also disabled for some reason. "Start"->"Run" thingy.
So here I am, I appreciate it if ya`ll can help me with this :/
And here is my OTL.txt copy paste *bows* :
OTL logfile created on: 6/5/2011 9:28:00 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Kevin\My Documents\Downloads\Programs
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 51.65% Memory free
3.85 Gb Paging File | 3.04 Gb Available in Paging File | 79.14% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 2.21 Gb Free Space | 5.93% Space Free | Partition Type: NTFS
Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/05 09:11:31 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kevin\My Documents\Downloads\Programs\OTL.exe
PRC - [2011/05/20 13:54:14 | 001,010,232 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2011/03/04 04:21:45 | 002,548,864 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlvknlg.exe
PRC - [2011/03/03 18:39:06 | 003,278,232 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2011/02/17 21:45:02 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/01/01 04:06:35 | 003,395,600 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/01/01 04:06:34 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/11/14 00:46:38 | 000,107,008 | ---- | M] () -- C:\Program Files\VideoLAN\VLC\vlc.exe
PRC - [2010/11/09 23:09:08 | 006,174,008 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/05/25 23:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\system32\NlsSrv32.exe
PRC - [2008/11/10 04:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2006/11/13 00:47:00 | 005,296,128 | ---- | M] () -- C:\Program Files\Audacity\audacity.exe
PRC - [2006/08/30 10:58:38 | 000,049,152 | ---- | M] (ZSMCSNAP) -- C:\WINDOWS\vmsnap3.exe
PRC - [2006/06/28 17:54:06 | 000,049,152 | ---- | M] (Vimicro) -- C:\WINDOWS\Domino.exe
PRC - [2004/08/04 06:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/06/05 09:11:31 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kevin\My Documents\Downloads\Programs\OTL.exe
MOD - [2011/03/04 04:21:41 | 000,545,408 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlls.dll
MOD - [2011/02/17 21:45:17 | 000,040,448 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2011/02/11 22:11:36 | 000,034,208 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\idmmkb.dll
MOD - [2011/01/01 04:06:33 | 000,187,144 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2009/07/12 00:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2009/07/12 00:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
MOD - [2004/08/04 06:57:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/01/01 04:06:34 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/05/04 08:10:00 | 003,539,184 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\system32\NlsSrv32.exe -- (nlsX86cc)
SRV - [2008/11/10 04:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ==========
DRV - [2011/03/19 08:37:16 | 000,443,448 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2011/01/25 18:40:06 | 000,097,112 | ---- | M] (Tonec Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\idmtdi.sys -- (IDMTDI)
DRV - [2011/01/01 04:00:18 | 000,293,968 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/01/01 03:59:23 | 000,047,440 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/01/01 03:59:11 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/01/01 03:56:49 | 000,023,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/01/01 03:56:29 | 000,029,264 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/01/01 03:56:27 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009/09/17 19:00:30 | 001,399,680 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/07/01 11:53:34 | 000,013,824 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2009/07/01 11:53:30 | 000,066,688 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2009/06/30 17:31:00 | 000,164,896 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvgts.sys -- (nvgts)
DRV - [2006/12/01 14:23:58 | 000,392,122 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbVM303.sys -- (ZSMC303)
DRV - [2006/04/25 10:57:42 | 000,428,160 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vmfilter303.sys -- (vmfilter303)
DRV - [2001/08/17 20:11:42 | 000,029,696 | ---- | M] (CNet Technology, Inc. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DM9PCI5.SYS -- (DM9102) DAVICOM 9102(A)
DRV - [2001/08/17 13:58:12 | 000,022,912 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\umaxpcls.sys -- (UMAXPCLS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.yahoo.com/?fr=fp-spt_gen
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://in.yahoo.com/?fr=fp-spt_gen
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoo...earchTerms}&f=4
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://start.facemoods.com/?a=ddr [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2737658
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Jookz"
FF - prefs.js..browser.search.defaultenginename: "Facemoods Search"
FF - prefs.js..browser.search.order.1: "Jookz"
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.jp/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {C8431CD2-C25A-45F3-BEA9-A9103C31409A}:1.0
FF - prefs.js..extensions.enabledItems: {d7521926-ede3-4a77-9073-e9374fc439a3}:2.5.6.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {6E19037A-12E3-4295-8915-ED48BC341614}:1.3.329.2
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:7.2.6
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.4.0024
FF - prefs.js..extensions.enabledItems: {f999a48b-1950-4d81-9971-79018f807b4b}:2.7.2.0
FF - HKLM\software\mozilla\Firefox\extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge [2011/06/05 07:52:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/17 21:45:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/26 11:34:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/06 19:23:53 | 000,000,000 | ---D | M]
[2010/06/13 00:15:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions
[2011/05/20 07:21:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\sktc4vuw.default\extensions
[2011/01/14 18:39:46 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\sktc4vuw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/01/14 11:42:18 | 000,000,000 | ---D | M] (Avanquest EN Toolbar) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\sktc4vuw.default\extensions\{d7521926-ede3-4a77-9073-e9374fc439a3}
[2011/04/20 15:18:31 | 000,000,000 | ---D | M] (FreeOnlineRadioPlayerRecorder Toolbar) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\sktc4vuw.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
[2011/03/10 18:54:32 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\sktc4vuw.default\extensions\[email protected]
[2011/03/09 05:07:40 | 000,000,000 | ---D | M] (Facemoods) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\sktc4vuw.default\extensions\[email protected]
[2011/03/10 18:54:27 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\sktc4vuw.default\searchplugins\daemon-search.xml
[2011/06/05 07:22:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/06/13 02:30:42 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/06/13 12:05:27 | 000,000,000 | ---D | M] (ResultUrl) -- C:\Program Files\Mozilla Firefox\extensions\{C8431CD2-C25A-45F3-BEA9-A9103C31409A}
[2010/06/13 01:16:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/17 21:45:18 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/03/07 21:02:32 | 000,000,000 | ---D | M] (IDM CC) -- C:\DOCUMENTS AND SETTINGS\KEVIN\APPLICATION DATA\IDM\IDMMZCC3
[2010/06/13 01:16:08 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/05 07:52:06 | 000,000,000 | ---D | M] (RelevantKnowledge) -- C:\PROGRAM FILES\RELEVANTKNOWLEDGE
[2010/06/13 01:16:07 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/09 05:08:13 | 000,002,046 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchddr.xml
[2010/09/02 16:09:28 | 000,002,486 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\iMeshWebSearch.xml
[2011/01/21 17:11:52 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jookz.xml
[2011/01/21 17:11:52 | 000,002,757 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jookz.xml.bak
O1 HOSTS File: ([2011/06/03 22:29:46 | 000,000,790 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 68.71.46.227 rohan.xor-net.com
O1 - Hosts: 68.71.46.227 xor-net.com
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll (facemoods.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Domino] C:\WINDOWS\Domino.exe (Vimicro)
O4 - HKLM..\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe (facemoods.com)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VMSnap3] C:\WINDOWS\vmsnap3.exe (ZSMCSNAP)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NofolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 202.78.97.41 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\RelevantKnowledge: DllName - C:\Program Files\RelevantKnowledge\rlls.dll - C:\Program Files\RelevantKnowledge\rlls.dll (TMRG, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/06/12 15:59:38 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{8f10dba2-4b05-11e0-8c8b-1078d284f316}\Shell - "" = AutoRun
O33 - MountPoints2\{8f10dba2-4b05-11e0-8c8b-1078d284f316}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8f10dba2-4b05-11e0-8c8b-1078d284f316}\Shell\AutoRun\command - "" = E:\FSETUP3.EXE
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/05 07:50:05 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Kevin\Recent
[2011/06/05 07:33:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge
[2011/06/05 07:23:11 | 000,000,000 | ---D | C] -- C:\Pcsx2
[2011/06/05 07:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kevin\neoncube
[2011/06/05 07:19:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/06/05 02:00:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2011/06/03 23:14:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kevin\My Documents\RohanScreenShot
[2011/06/03 22:06:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\XorNetworks Rohan
[2011/05/29 18:05:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kevin\Desktop\New Folder
[2011/05/19 20:50:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Solveig Multimedia
[2011/05/19 20:50:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Solveig Multimedia
[2011/05/19 20:50:13 | 000,000,000 | ---D | C] -- C:\Program Files\Solveig Multimedia
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/05 08:52:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/05 07:32:51 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/06/05 07:28:33 | 000,001,984 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/06/05 07:28:15 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/05 07:28:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/05 03:52:00 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/05 02:08:31 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-746137067-1284227242-725345543-1003.job
[2011/06/05 02:08:26 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-746137067-1284227242-725345543-1003.job
[2011/06/05 02:07:32 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-746137067-1284227242-725345543-1004.job
[2011/06/04 23:14:05 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-746137067-1284227242-725345543-1004.job
[2011/06/04 20:04:11 | 000,238,358 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\47388_149839795034443_100000252699155_412300_2762573_n.jpg
[2011/06/03 23:49:04 | 000,071,736 | ---- | M] () -- C:\romini.dmp
[2011/06/03 09:04:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/03 08:12:49 | 000,243,959 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\47388_149839761701113_100000252699155_412291_6542489_n.jpg
[2011/06/03 05:37:15 | 000,122,295 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\208e55k.png
[2011/05/30 23:59:56 | 000,092,006 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\216296_1913498046737_1520514783_32034096_3002769_n.jpg
[2011/05/26 11:37:44 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/05/22 17:12:08 | 000,013,312 | ---- | M] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/19 20:50:26 | 000,000,866 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\SolveigMM AVI Trimmer.lnk
[2011/05/19 05:23:51 | 002,641,317 | ---- | M] () -- C:\Documents and Settings\Kevin\My Documents\DSC02956.JPG
[2011/05/16 19:31:20 | 000,000,689 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\Shortcut to nos32 - multiclient.exe.lnk
[2011/05/10 07:35:39 | 000,000,676 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\96acoo.lnk
[2011/05/10 07:33:11 | 000,000,715 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\69merch.lnk
[2011/05/09 08:34:07 | 000,866,901 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\asdf.mp3
[2011/05/09 04:35:02 | 004,414,806 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\asdf.wav
[2011/05/09 04:31:12 | 013,954,126 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\ppf.wav
[2011/05/06 15:38:39 | 002,902,362 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\aloneshaha.mp3
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/03 23:32:19 | 000,071,736 | ---- | C] () -- C:\romini.dmp
[2011/06/03 05:37:17 | 000,122,295 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\208e55k.png
[2011/06/01 23:19:16 | 000,238,358 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\47388_149839795034443_100000252699155_412300_2762573_n.jpg
[2011/06/01 23:18:27 | 000,243,959 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\47388_149839761701113_100000252699155_412291_6542489_n.jpg
[2011/05/31 00:00:01 | 000,092,006 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\216296_1913498046737_1520514783_32034096_3002769_n.jpg
[2011/05/19 20:50:26 | 000,000,866 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\SolveigMM AVI Trimmer.lnk
[2011/05/19 05:21:49 | 002,641,317 | ---- | C] () -- C:\Documents and Settings\Kevin\My Documents\DSC02956.JPG
[2011/05/16 19:31:19 | 000,000,689 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\Shortcut to nos32 - multiclient.exe.lnk
[2011/05/10 07:35:39 | 000,000,676 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\96acoo.lnk
[2011/05/10 07:33:11 | 000,000,715 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\69merch.lnk
[2011/05/09 04:38:00 | 000,866,901 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\asdf.mp3
[2011/05/09 04:35:01 | 004,414,806 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\asdf.wav
[2011/05/09 04:31:11 | 013,954,126 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\ppf.wav
[2011/02/26 19:52:18 | 000,000,261 | ---- | C] () -- C:\WINDOWS\wpepro.INI
[2011/01/29 23:00:50 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\setupfilter.exe
[2011/01/16 05:16:07 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/14 13:54:13 | 000,240,592 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/14 13:54:09 | 000,240,592 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/14 13:54:09 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/01/14 13:24:39 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/01/14 11:30:00 | 000,002,462 | ---- | C] () -- C:\WINDOWS\Sandboxie.ini
[2011/01/13 14:17:53 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/06/13 03:15:12 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/06/13 00:15:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/06/12 23:38:43 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/06/12 23:36:20 | 000,268,600 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 16:53:13 | 000,001,984 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/12 16:50:04 | 000,006,136 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2010/06/12 16:02:37 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/06/12 15:55:11 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 07:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/04 06:56:44 | 000,162,793 | RHS- | C] () -- C:\WINDOWS\System32\ktumb.dll
[2004/08/02 20:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/07/17 17:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001/08/23 20:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 20:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 20:00:00 | 000,314,508 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 20:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 20:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 20:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 20:00:00 | 000,040,836 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 20:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 20:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 20:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/01/21 10:33:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\035B
[2010/06/12 17:00:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/03/19 07:57:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/03/19 08:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2011/02/18 04:11:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GetRight
[2011/04/14 21:26:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HighAndes
[2011/03/10 19:01:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2011/01/27 17:15:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ResultUrl
[2011/04/27 01:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/16 16:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/14 21:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Blue Cat Audio
[2011/03/10 19:33:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\DAEMON Tools Lite
[2011/03/19 08:46:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\DAEMON Tools Pro
[2011/06/05 09:27:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\DMCache
[2011/03/09 21:03:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\facemoods.com
[2011/04/02 08:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\FALCOM
[2011/04/25 13:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\FileZilla
[2011/04/21 05:53:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Free Audio Editor
[2011/05/03 04:59:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\FrostWire
[2011/02/18 04:11:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\GetRight
[2011/04/14 21:26:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\HighAndes
[2011/03/16 04:16:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\IDM
[2011/01/23 13:14:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\imeshbandmltbpi
[2011/01/31 11:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Moyea
[2011/02/24 13:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\OpenCandy
[2011/02/24 08:53:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\PriceGong
[2011/01/14 13:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\SystemRequirementsLab
[2011/04/07 08:22:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\TeamViewer
========== Purity Check ==========
< End of report >