1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved WinXP svchost overrun and bsod issues

Discussion in 'Malware and Virus Removal Archive' started by ZanKhelledros, 2012/01/05.

  1. 2012/01/05
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    [Resolved] WinXP svchost overrun and bsod issues

    Ok, so it started with some laggy issues. Then while not even at Pc would hear random alert noises with no message. Then a few messages saying something about not being able to run C++ (sorry didnt write it down, but i wasnt trying to run that anyway). Then, as before, my programs stopped responding to be opened and i couldnt run antivirus scans. So i opened in safe mode, ran Mbam and it found nothing, but i didnt believe it. So I got on here and ran Gmer and ran it, accidently left MSE protection up. Click no with first scan as stated then ran scan, it found issues with rootkey, i clicked save as stated and it froze. didnt get to get report. Now with security off when i try to run it i get the blue screen.... What next?
     
  2. 2012/01/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ==========================================================

    Please, complete all steps listed HERE
    See if you can run DDS.
     

  3. to hide this advert.

  4. 2012/01/07
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    I ran MSE before this problem got worse, it had found some sort of trojen.
    a Trojan:JS/Tracur.B {found in my mozilla folder} removed it.

    (The Mbam was run while in safe mode, i had updated it a day before so im sure its good. Ran it again and it worked, still says it found nothing but here it is.)
    ------------------
    Malwarebytes Anti-Malware (Trial) 1.60.0.1800
    www.malwarebytes.org

    Database version: v2012.01.03.04

    Windows XP Service Pack 3 x86 NTFS (Safe Mode)
    Internet Explorer 6.0.2900.5512
    Administrator :: YOUR-XHTR8HVC4P [administrator]

    Protection: Disabled

    1/5/2012 10:50:47 AM
    mbam-log-2012-01-05 (10-50-47).txt

    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 382893
    Time elapsed: 1 hour(s), 47 minute(s), 26 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
    -------------------
    Gmer ran but i forgot to turn off my MSE, it had found something but when i went to save it the pc froze, still unable to run

    Here is the DDS then attach

    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_23
    Run by Owner at 15:49:12 on 2012-01-06
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.71 [GMT -5:00]
    .
    AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    FW: Norton AntiVirus *Enabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Softex\OmniPass\Omniserv.exe
    C:\WINDOWS\System32\PGPsdkServ.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Softex\OmniPass\OPXPApp.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
    C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\PGP Corporation\PGP for Windows XP\PGPtray.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\iPod\bin\iPodService.exe
    c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
    c:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Page_URL =
    uSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    mStart Page = hxxp://www.msn.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    uInternet Connection Wizard,ShellNext = hxxp://us9.hpwis.com/
    uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    BHO: {2d45cdbe-8420-4d2e-b1c6-7fa278d50c58} - c:\documents and settings\owner\local settings\application data\SystemCodec.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
    TB: HP View: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hewlett-packard\digital imaging\bin\hpdtlk02.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    EB: hp view: {8f4902b6-6c04-4ade-8052-aa58578a21bd} - c:\windows\system32\Shdocvw.dll
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [BackupNotify] c:\program files\hewlett-packard\digital imaging\bin\backupnotify.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
    uRun: [IntelNotifierNotifier] rundll32.exe ",DllRegisterServer
    mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
    mRun: [RegSvr32]
    mRun: [AlcxMonitor] ALCXMNTR.EXE
    mRun: [IPInSightMonitor 02] "c:\program files\visual networks\visual ip insight\sbc\IPMon32.exe "
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll "
    mRun: [Monitor] "c:\program files\leapfrog\leapfrog connect\Monitor.exe "
    mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [PLFSetL] c:\windows\\PLFSetL.exe
    mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
    mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" --auto-start
    mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
    mRunServices: [Service] real.exe
    dRun: [ALUAlert] c:\program files\symantec\liveupdate\ALUNotify.exe
    dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.0\program\quickstart.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pgptray.lnk - c:\program files\pgp corporation\pgp for windows xp\PGPtray.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sbcsel~1.lnk - c:\program files\sbc self support tool\bin\matcli.exe
    IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
    IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
    IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
    IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
    IE: {10F055B8-F443-4adf-948A-EC551E9DBCE4} - c:\documents and settings\owner\start menu\programs\ultimatebet\UltimateBet.lnk
    IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\progra~1\aim\aim.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1135455836765
    DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} - hxxps://photos.riteaid.com/control/RiteAidOneHourPhotoOnline.cab
    DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
    DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    TCP: Interfaces\{4000BCD1-33E5-42BC-8BF0-9F783C10E2CB} : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{BEC2E07B-95CB-427A-91FC-A75F3FD3E784} : DhcpNameServer = 172.16.0.1
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
    Notify: igfxcui - igfxsrvc.dll
    Notify: OPXPGina - c:\program files\softex\omnipass\opxpgina.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\vgens2qp.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: network.proxy.type - 2
    FF - plugin: c:\documents and settings\owner\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    FF - Ext: XUL Cache: {5290e661-a829-4402-a85e-e8ff3031d22f} - %profile%\extensions\{5290e661-a829-4402-a85e-e8ff3031d22f}
    FF - Ext: XUL Cache: {3140763c-a0c8-4748-b0d2-bdf74d9cd63c} - %profile%\extensions\{3140763c-a0c8-4748-b0d2-bdf74d9cd63c}
    FF - Ext: XUL Cache: {25bd20e4-9136-4e68-9895-52968b78d009} - %profile%\extensions\{25bd20e4-9136-4e68-9895-52968b78d009}
    FF - Ext: XUL Cache: {d50b427b-ce3c-4456-8661-519810830d5e} - %profile%\extensions\{d50b427b-ce3c-4456-8661-519810830d5e}
    FF - Ext: XUL Cache: {ae2685b6-2b97-4ba4-a536-e52e27298a2f} - %profile%\extensions\{ae2685b6-2b97-4ba4-a536-e52e27298a2f}
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    ============= SERVICES / DRIVERS ===============
    .
    R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
    R1 MpKsl2e2f9cfb;MpKsl2e2f9cfb;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKsl2e2f9cfb.sys [2012-1-5 29904]
    R1 MpKsl4f9774f9;MpKsl4f9774f9;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKsl4f9774f9.sys [2012-1-5 29904]
    R1 MpKslf7ed5795;MpKslf7ed5795;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKslf7ed5795.sys [2012-1-4 29904]
    R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2011-8-15 1361288]
    R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-13 652872]
    R2 PGPsdkServ;PGPsdkService;c:\windows\system32\PGPsdkServ.exe [2003-11-4 65536]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-13 20464]
    S1 MpKslfca545f3;MpKslfca545f3;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKslfca545f3.sys [2012-1-5 29904]
    S1 Pernmdd;Pernmdd;\??\c:\windows\system32\drivers\dmitcpip.sys --> c:\windows\system32\drivers\dmitcpip.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 mrtRate;mrtRate; [x]
    S2 QGKDNWIH;QGKDNWIH;\??\c:\windows\system32\qgkdnwih.tyw --> c:\windows\system32\qgkdnwih.tyw [?]
    S3 kbeepm;kbeepm;c:\docume~1\owner\locals~1\temp\kbeepm.sys [2003-11-8 31744]
    S3 Leapfrog-USBLAN;Leapfrog-USBLAN;c:\windows\system32\drivers\btblan.sys [2011-12-25 33792]
    S3 USBNET;Instant Wireless USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\vnetusbl.sys [2007-10-7 107648]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2012-01-05 20:14:06 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKsl2e2f9cfb.sys
    2012-01-05 20:13:58 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\offreg.dll
    2012-01-05 20:08:37 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKslca877dae.sys
    2012-01-05 18:44:18 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKsl4f9774f9.sys
    2012-01-05 15:46:05 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKslfca545f3.sys
    2012-01-04 15:36:42 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\MpKslf7ed5795.sys
    2012-01-04 03:02:25 6823496 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17de866b-43d6-4d18-8a69-ee0b448d3a1b}\mpengine.dll
    2012-01-04 03:02:24 222080 ------w- c:\windows\system32\MpSigStub.exe
    2012-01-04 02:57:34 -------- d-----w- c:\program files\Microsoft Security Client
    2011-12-25 18:09:56 -------- d-----w- c:\windows\9013B37099D4404B9DB9779B51CEB5FF.TMP
    2011-12-25 18:08:24 33792 ----a-w- c:\windows\system32\drivers\btblan.sys
    .
    ==================== Find3M ====================
    .
    2011-12-10 20:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-10-19 09:26:25 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-10-19 02:43:53 0 ---ha-w- c:\documents and settings\owner\sikidjqwrm.tmp
    2011-03-02 19:26:19 8593992 ----a-w- c:\program files\Firefox Setup 3.6.14.exe
    2011-02-03 03:15:52 36069 ----a-w- c:\program files\uninstall.exe
    2011-01-19 08:27:48 76464 ----a-w- c:\program files\fraps64.dat
    2011-01-19 08:27:46 2350256 ----a-w- c:\program files\fraps.exe
    2011-01-19 08:26:10 159744 ----a-w- c:\program files\frapslcd.dll
    2010-12-02 08:08:12 253104 ----a-w- c:\program files\fraps32.dll
    2010-12-02 08:08:12 197808 ----a-w- c:\program files\fraps64.dll
    2010-11-23 00:32:37 5840851 ----a-w- c:\program files\3dfiction_v01.scr
    2010-11-23 00:32:37 206754 ----a-w- c:\program files\uninstall 3dfiction_v01.exe
    .
    =================== ROOTKIT ====================
    .
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: ST3120022A rev.3.06 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
    .
    device: opened successfully
    user: MBR read successfully
    .
    Disk trace:
    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86E5449F]<<
    _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x86e5b738]; MOV EAX, [0x86e5b8ac]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
    1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x86F51AB8]
    3 CLASSPNP[0xF74C7FD7] -> nt!IofCallDriver[0x804E37D5] -> \Device\00000068[0x86F8AF18]
    5 ACPI[0xF743E620] -> nt!IofCallDriver[0x804E37D5] -> [0x86FDED98]
    \Driver\atapi[0x86EF5620] -> IRP_MJ_CREATE -> 0x86E5449F
    error: Read A device attached to the system is not functioning.
    kernel: MBR read successfully
    _asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; CLD ; REP MOVSB ; JMP FAR 0x7a0:0x52; }
    detected disk devices:
    detected hooks:
    \Driver\atapi DriverStartIo -> 0x86E542C6
    user & kernel MBR OK
    Warning: possible TDL3 rootkit infection !
    .
    ============= FINISH: 15:54:03.89 ===============

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 10/29/2003 3:01:39 PM
    System Uptime: 1/6/2012 3:38:10 PM (0 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. | | A7N8X-LA
    Processor: AMD Athlon(tm) XP 2600+ | Socket A | 2079/166mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 105 GiB total, 39.75 GiB free.
    D: is FIXED (FAT32) - 7 GiB total, 2.419 GiB free.
    E: is CDROM ()
    F: is CDROM ()
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    K: is FIXED (NTFS) - 75 GiB total, 12.576 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP1201: 10/5/2011 11:55:17 PM - System Checkpoint
    RP1202: 10/7/2011 10:05:21 AM - System Checkpoint
    RP1203: 10/8/2011 2:05:37 PM - System Checkpoint
    RP1204: 10/9/2011 2:34:14 PM - System Checkpoint
    RP1205: 10/10/2011 5:25:57 PM - System Checkpoint
    RP1206: 10/11/2011 7:04:24 PM - System Checkpoint
    RP1207: 10/12/2011 8:08:47 PM - System Checkpoint
    RP1208: 10/14/2011 4:37:22 AM - System Checkpoint
    RP1209: 10/15/2011 2:00:41 PM - System Checkpoint
    RP1210: 10/16/2011 2:18:57 PM - System Checkpoint
    RP1211: 10/17/2011 2:39:29 PM - System Checkpoint
    RP1212: 10/17/2011 7:11:31 PM - Installed DirectX
    RP1213: 10/19/2011 12:08:28 AM - System Checkpoint
    RP1214: 10/19/2011 5:38:47 AM - Removed CA eTrust PestPatrol
    RP1215: 10/20/2011 8:00:59 AM - System Checkpoint
    RP1216: 10/21/2011 11:16:14 AM - System Checkpoint
    RP1217: 10/22/2011 12:45:26 PM - System Checkpoint
    RP1218: 10/23/2011 2:12:25 PM - System Checkpoint
    RP1219: 10/24/2011 4:41:15 PM - System Checkpoint
    RP1220: 10/25/2011 5:14:20 PM - System Checkpoint
    RP1221: 10/26/2011 6:37:28 PM - System Checkpoint
    RP1222: 10/28/2011 12:41:42 PM - System Checkpoint
    RP1223: 10/29/2011 4:30:27 PM - System Checkpoint
    RP1224: 10/30/2011 7:04:54 PM - System Checkpoint
    RP1225: 10/31/2011 7:24:12 PM - System Checkpoint
    RP1226: 11/2/2011 12:52:45 PM - System Checkpoint
    RP1227: 11/3/2011 2:53:42 PM - System Checkpoint
    RP1228: 11/4/2011 6:05:07 PM - System Checkpoint
    RP1229: 11/5/2011 9:04:41 PM - System Checkpoint
    RP1230: 11/6/2011 11:20:26 PM - System Checkpoint
    RP1231: 11/8/2011 12:56:20 PM - System Checkpoint
    RP1232: 11/9/2011 5:44:39 PM - System Checkpoint
    RP1233: 11/10/2011 7:04:21 PM - System Checkpoint
    RP1234: 11/11/2011 11:00:07 PM - System Checkpoint
    RP1235: 11/13/2011 2:26:42 AM - System Checkpoint
    RP1236: 11/14/2011 12:07:43 PM - System Checkpoint
    RP1237: 11/15/2011 1:36:02 PM - System Checkpoint
    RP1238: 11/16/2011 4:49:03 PM - System Checkpoint
    RP1239: 11/17/2011 5:54:53 PM - System Checkpoint
    RP1240: 11/18/2011 7:04:02 PM - System Checkpoint
    RP1241: 11/20/2011 3:35:18 AM - System Checkpoint
    RP1242: 11/21/2011 1:18:52 PM - System Checkpoint
    RP1243: 11/22/2011 5:00:58 PM - System Checkpoint
    RP1244: 11/23/2011 7:17:39 PM - System Checkpoint
    RP1245: 11/25/2011 3:26:40 AM - System Checkpoint
    RP1246: 11/26/2011 3:44:48 AM - System Checkpoint
    RP1247: 11/27/2011 3:55:54 AM - System Checkpoint
    RP1248: 11/28/2011 6:45:33 AM - System Checkpoint
    RP1249: 11/29/2011 10:19:07 AM - System Checkpoint
    RP1250: 11/30/2011 12:16:58 PM - System Checkpoint
    RP1251: 12/1/2011 1:14:45 PM - System Checkpoint
    RP1252: 12/2/2011 6:26:29 PM - System Checkpoint
    RP1253: 12/3/2011 8:17:29 PM - System Checkpoint
    RP1254: 12/4/2011 11:44:00 PM - System Checkpoint
    RP1255: 12/6/2011 2:18:44 AM - System Checkpoint
    RP1256: 12/7/2011 4:19:03 AM - System Checkpoint
    RP1257: 12/8/2011 8:16:58 AM - System Checkpoint
    RP1258: 12/9/2011 10:02:00 AM - System Checkpoint
    RP1259: 12/10/2011 1:08:40 PM - System Checkpoint
    RP1260: 12/11/2011 1:09:56 PM - System Checkpoint
    RP1261: 12/12/2011 7:14:23 PM - System Checkpoint
    RP1262: 12/13/2011 11:08:08 PM - System Checkpoint
    RP1263: 12/15/2011 8:01:19 AM - System Checkpoint
    RP1264: 12/16/2011 11:44:11 AM - System Checkpoint
    RP1265: 12/17/2011 12:48:50 PM - System Checkpoint
    RP1266: 12/18/2011 4:45:51 PM - System Checkpoint
    RP1267: 12/20/2011 1:34:44 AM - System Checkpoint
    RP1268: 12/21/2011 1:28:39 PM - System Checkpoint
    RP1269: 12/22/2011 2:21:57 PM - System Checkpoint
    RP1270: 12/23/2011 6:30:31 PM - System Checkpoint
    RP1271: 12/25/2011 11:45:49 AM - System Checkpoint
    RP1272: 12/26/2011 2:27:19 PM - System Checkpoint
    RP1273: 12/27/2011 5:48:24 PM - System Checkpoint
    RP1274: 12/28/2011 6:42:20 PM - System Checkpoint
    RP1275: 12/30/2011 12:20:22 AM - System Checkpoint
    RP1276: 12/31/2011 11:47:55 AM - System Checkpoint
    RP1277: 1/1/2012 12:13:51 PM - System Checkpoint
    RP1278: 1/2/2012 6:31:37 PM - System Checkpoint
    RP1279: 1/3/2012 7:39:53 PM - System Checkpoint
    .
    ==== Installed Programs ======================
    .
    .
    Adobe Acrobat 4.0
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Photoshop 5.0 Limited Edition
    Adobe Reader 7.1.0
    AOL Instant Messenger
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft ShowBiz 2
    AT&T Yahoo! Applications
    Audacity 1.2.6
    Blackhawk Striker from Hewlett-Packard Desktops (remove only)
    Blasterball 2 from Hewlett-Packard Desktops (remove only)
    Bonjour
    Bounce from Hewlett-Packard Desktops (remove only)
    BrettspielWelt
    BroadJump Client Foundation
    BufferChm
    Cannonballs from Hewlett-Packard Desktops (remove only)
    CDex extraction audio
    Color LaserJet 2600n
    Compatibility Pack for the 2007 Office system
    Coupon Printer for Windows
    CreativeProjects
    Critical Update for Windows Media Player 11 (KB959772)
    CustomerResearchQFolder
    D&D35E Screen Saver
    Destinations
    DeviceFunctionQFolder
    DeviceManagementQFolder
    Diablo
    Diablo II
    Easy Internet Sign-up
    ElectriCalm 3D Screensaver (remove only)
    Enhanced Multimedia Keyboard Solution
    eSupportQFolder
    Excavation from Hewlett-Packard Desktops (remove only)
    Five Card Frenzy from Hewlett-Packard Desktops (remove only)
    FLV Player 2.0, build 24
    Fraps
    GemMaster 3 from Hewlett-Packard Desktops (remove only)
    GIMP 2.4.4
    Google Video Player
    HeroScribe 1.0pre1
    HijackThis 1.99.0
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    Hoyle Board Games 3
    hp deskjet 3600
    HP Extended Capabilities 5.0
    HP Image Zone Express
    HP Imaging Device Functions 5.0
    HP Photo & Imaging 3.0
    HP Photo and Imaging 2.0 - Deskjet Series
    HP Photo and Imaging 2.0 - Photosmart Cameras
    HP Photo and Imaging 2.1 - Scanjet 2400 Series
    HP Software Update
    HP Solution Center & Imaging Support Tools 5.0
    HPImageZone
    HPIZ Fix2
    hpmdtab
    HpSdpAppCoreApp
    HPSystemDiagnostics
    IKEA HomePlanner Kitchen
    InstantShare
    Intel(R) Extreme Graphics Driver
    IntelliMover Data Transfer Demo
    InterVideo WinDVD Player
    iTunes
    Java 2 Runtime Environment, SE v1.4.1_02
    Java Auto Updater
    Java Web Start
    Java(TM) 6 Update 23
    LeapFrog Connect
    LeapFrog Leapster Explorer Plugin
    LeapFrog My Pals Plugin
    LiveUpdate Notice (Symantec Corporation)
    Logitech Gaming Software
    Logitech Vid HD
    Logitech Webcam Software
    Logitech Webcam Software Driver Package
    LogMeIn Hamachi
    Macromedia Dreamweaver 4
    Macromedia Extension Manager
    Macromedia Shockwave Player
    Malwarebytes Anti-Malware version 1.60.0.1800
    Mars Rover from Hewlett-Packard Desktops (remove only)
    Matrix-ks
    Memoir '44 Online
    Memories Disc Creator 2.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Extended
    Microsoft Antimalware
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Digital Image Library 9 - Blocker
    Microsoft Digital Image Standard 2006
    Microsoft Digital Image Standard 2006 Editor
    Microsoft Digital Image Standard 2006 Library
    Microsoft Encarta Encyclopedia Standard 2006
    Microsoft Money 2006
    Microsoft Office Word Viewer 2003
    Microsoft Plus! Digital Media Edition
    Microsoft Security Client
    Microsoft Security Essentials
    Microsoft Streets & Trips 2006
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual Basic 6.0 Working Model Edition
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft Visual J# .NET Redistributable Package 1.1
    Microsoft Web Publishing Wizard 1.53
    Microsoft Word 2002
    Microsoft Works
    Microsoft Works Suite 2006 Setup Launcher
    Microsoft Works Suite Add-in for Microsoft Word
    Microsoft XNA Framework Redistributable 4.0
    MobileMe Control Panel
    Mozilla Firefox (3.6.25)
    MSN Music Assistant
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Multimedia Card Reader
    MUSICMATCH® Jukebox
    NetAssistant
    NetAssistant for Firefox
    Network Play System (Patching)
    NVIDIA Drivers
    OmniPass
    OpenOffice.org 2.0
    Orbital from Hewlett-Packard Desktops (remove only)
    OSS Video Decompiler 5.5.0.3
    Otto from Hewlett-Packard Desktops (remove only)
    PC-Doctor for Windows
    PDFCreator
    PGP 8.0.3
    PhotoGallery
    Photosmart 140,240,7200,7600,7700,7900 Series
    Polar Bowler from Hewlett-Packard Desktops (remove only)
    Portal
    PrintScreen
    PS2
    PSShortcutsP
    Python 2.2 combined Win32 extensions
    Python 2.2.1
    QFolder
    Quake 4(TM)
    Quake II
    Quake III Arena
    Quicken 2003 New User Edition
    QuickProjects
    QuickTime
    RealPlayer
    RecordNow!
    Rhapsody Player Engine
    RolePlayingMaster
    S3Display
    S3Gamma2
    S3Info2
    S3Overlay
    SBC Self Support Tool
    SBC Yahoo! Applications
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360131)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2416400)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476490)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2479943)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2482017)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2491683)
    Security Update for Windows XP (KB2497640)
    Security Update for Windows XP (KB2503658)
    Security Update for Windows XP (KB2503665)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2510581)
    Security Update for Windows XP (KB2511455)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB2530548)
    Security Update for Windows XP (KB2535512)
    Security Update for Windows XP (KB2536276)
    Security Update for Windows XP (KB2544521)
    Security Update for Windows XP (KB2544893)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972260)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974455)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB976325)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981349)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982381)
    Security Update for Windows XP (KB982665)
    SEGA Genesis & Mega Drive Classics
    ShareIns
    SkinsHP1
    SkinsHP2
    Skypeâ„¢ 5.5
    Slyder from Hewlett-Packard Desktops (remove only)
    SolutionCenter
    SpamSubtract
    Spybot - Search & Destroy
    Spybot - Search & Destroy 1.4
    Status
    Steam(TM)
    STX from Hewlett-Packard Desktops (remove only)
    Terraria
    TextDraw v5.9 and Imagetrix v5.5
    toolkit
    TrayApp
    UltimateBet
    Unity Web Player
    Unload
    Unreal Editor
    Upaint
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update for Windows XP (KB976749)
    Update for Windows XP (KB978207)
    Update for Windows XP (KB980182)
    Updates from HP
    Use the entry named LeapFrog Connect to uninstall (LeapFrog Leapster Explorer Plugin)
    Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)
    VC Temptresses Screen Saver
    Viewpoint Manager (Remove Only)
    Virtual Warfare from Hewlett-Packard Desktops (remove only)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    Visual IP InSight(SBC)
    WebFldrs XP
    Weblink
    WebReg
    Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    Works Upgrade
    www.UselessCreations.com - The Amazing Spider-Man 3D Screensaver v1.7
    Yahoo! Photos Easy Upload Tool 1v4
    Zune Desktop Theme
    .
    ==== Event Viewer Messages From Past Week ========
    .
    12/31/2011 10:06:20 AM, error: Service Control Manager [7034] - The LogMeIn Hamachi Tunneling Engine service terminated unexpectedly. It has done this 1 time(s).
    12/31/2011 10:06:06 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    1/6/2012 3:49:13 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2196.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    1/6/2012 3:21:59 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2196.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    1/5/2012 3:24:12 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2196.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    1/5/2012 12:50:53 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments " " in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    1/5/2012 10:58:41 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2196.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    1/5/2012 1:58:57 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
    1/5/2012 1:54:38 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2196.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    1/4/2012 11:44:22 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2196.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    1/4/2012 11:35:27 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments " " in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    1/4/2012 11:35:15 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    1/4/2012 11:34:37 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK7 Fips IPSec MpFilter MRxSmb NetBIOS NetBT Pernmdd RasAcd Rdbss Tcpip WS2IFSL
    1/4/2012 11:34:37 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
    1/4/2012 11:34:37 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    1/4/2012 11:34:37 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    1/4/2012 11:34:37 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning.
    1/4/2012 11:34:37 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    1/3/2012 6:01:01 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Pernmdd
    1/3/2012 6:00:53 PM, error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: The system cannot find the file specified.
    1/3/2012 6:00:52 PM, error: Service Control Manager [7023] - The MicroSoft Security Management service terminated with the following error: The specified module could not be found.
    1/3/2012 12:14:21 AM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
    1/3/2012 10:01:07 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    1/3/2012 10:00:18 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
    .
    ==== End Of File ===========================

    Now aswMBR
    -------------
    aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
    Run date: 2012-01-06 16:06:12
    -----------------------------
    16:06:12.093 OS Version: Windows 5.1.2600 Service Pack 3
    16:06:12.093 Number of processors: 1 586 0x801
    16:06:12.093 ComputerName: YOUR-XHTR8HVC4P UserName: Owner
    16:06:36.046 Initialize success
    16:07:00.812 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
    16:07:00.812 Disk 0 Vendor: ST3120022A 3.06 Size: 114473MB BusType: 3
    16:07:00.828 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
    16:07:00.828 Disk 1 Vendor: WDC_WD800JB-00JJC0 05.01C05 Size: 76319MB BusType: 3
    16:07:00.828 Device \Driver\atapi -> DriverStartIo 86e542c6
    16:07:00.859 Disk 0 MBR read successfully
    16:07:00.859 Disk 0 MBR scan
    16:07:00.859 Disk 0 TDL4@MBR code has been found
    16:07:00.875 Disk 0 MBR hidden
    16:07:00.875 Disk 0 Partition 1 00 0B FAT32 RECOVERY 7198 MB offset 63
    16:07:00.890 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 107264 MB offset 14742000
    16:07:00.906 Disk 0 MBR [TDL4] **ROOTKIT**
    16:07:00.906 Disk 0 trace - called modules:
    16:07:00.937 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86e5449f]<<
    16:07:00.937 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f51ab8]
    16:07:00.937 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\00000068[0x86f8af18]
    16:07:00.953 5 ACPI.sys[f743e620] -> nt!IofCallDriver -> [0x86fded98]
    16:07:00.953 \Driver\atapi[0x86ef5620] -> IRP_MJ_CREATE -> 0x86e5449f
    16:07:00.953 Scan finished successfully
    16:07:12.515 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat "
    16:07:12.515 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt "
    -----------------

    Not sure if the virus is still there or if i have damaged my PC somehow but stil having issues. Thanks for your help.
     
  5. 2012/01/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download TDSSKiller and save it to your desktop.
    • Doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  6. 2012/01/07
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    14:45:44.0437 2272 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
    14:45:44.0750 2272 ============================================================
    14:45:44.0750 2272 Current date / time: 2012/01/07 14:45:44.0750
    14:45:44.0750 2272 SystemInfo:
    14:45:44.0750 2272
    14:45:44.0750 2272 OS Version: 5.1.2600 ServicePack: 3.0
    14:45:44.0750 2272 Product type: Workstation
    14:45:44.0750 2272 ComputerName: YOUR-XHTR8HVC4P
    14:45:44.0750 2272 UserName: Owner
    14:45:44.0750 2272 Windows directory: C:\WINDOWS
    14:45:44.0750 2272 System windows directory: C:\WINDOWS
    14:45:44.0750 2272 Processor architecture: Intel x86
    14:45:44.0750 2272 Number of processors: 1
    14:45:44.0750 2272 Page size: 0x1000
    14:45:44.0750 2272 Boot type: Normal boot
    14:45:44.0750 2272 ============================================================
    14:45:51.0812 2272 Initialize success
    14:45:57.0781 0292 ============================================================
    14:45:57.0781 0292 Scan started
    14:45:57.0781 0292 Mode: Manual;
    14:45:57.0781 0292 ============================================================
    14:46:01.0734 0292 Abiosdsk - ok
    14:46:02.0046 0292 abp480n5 - ok
    14:46:02.0578 0292 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    14:46:02.0593 0292 ACPI - ok
    14:46:02.0828 0292 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
    14:46:02.0843 0292 ACPIEC - ok
    14:46:03.0015 0292 adpu160m - ok
    14:46:03.0218 0292 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    14:46:03.0218 0292 aec - ok
    14:46:03.0359 0292 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
    14:46:03.0359 0292 AFD - ok
    14:46:03.0515 0292 AFS2K (c685cc27a2e637f0dcb5a45e67cc6f74) C:\WINDOWS\system32\drivers\AFS2K.sys
    14:46:03.0515 0292 AFS2K - ok
    14:46:03.0687 0292 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
    14:46:03.0687 0292 agp440 - ok
    14:46:03.0796 0292 Aha154x - ok
    14:46:03.0906 0292 aic78u2 - ok
    14:46:04.0046 0292 aic78xx - ok
    14:46:04.0296 0292 ALCXWDM (8d6c30e515717248e0e52b85fd7ac466) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
    14:46:04.0546 0292 ALCXWDM - ok
    14:46:04.0828 0292 AliIde - ok
    14:46:05.0015 0292 AmdK7 (8fce268cdbdd83b23419d1f35f42c7b1) C:\WINDOWS\system32\DRIVERS\amdk7.sys
    14:46:05.0015 0292 AmdK7 - ok
    14:46:05.0281 0292 amsint - ok
    14:46:05.0437 0292 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
    14:46:05.0437 0292 Arp1394 - ok
    14:46:05.0625 0292 asc - ok
    14:46:05.0750 0292 asc3350p - ok
    14:46:05.0968 0292 asc3550 - ok
    14:46:06.0328 0292 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    14:46:06.0328 0292 AsyncMac - ok
    14:46:06.0515 0292 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    14:46:06.0515 0292 atapi - ok
    14:46:06.0640 0292 Atdisk - ok
    14:46:06.0765 0292 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    14:46:06.0765 0292 Atmarpc - ok
    14:46:06.0968 0292 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    14:46:06.0968 0292 audstub - ok
    14:46:07.0234 0292 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    14:46:07.0250 0292 Beep - ok
    14:46:07.0546 0292 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    14:46:07.0546 0292 cbidf2k - ok
    14:46:07.0750 0292 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    14:46:07.0750 0292 CCDECODE - ok
    14:46:07.0937 0292 cd20xrnt - ok
    14:46:08.0484 0292 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    14:46:08.0500 0292 Cdaudio - ok
    14:46:08.0656 0292 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    14:46:08.0671 0292 Cdfs - ok
    14:46:09.0203 0292 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    14:46:09.0343 0292 Cdrom - ok
    14:46:09.0906 0292 Changer - ok
    14:46:10.0531 0292 CmdIde - ok
    14:46:11.0125 0292 Cpqarray - ok
    14:46:11.0296 0292 dac2w2k - ok
    14:46:11.0406 0292 dac960nt - ok
    14:46:11.0609 0292 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    14:46:11.0656 0292 Disk - ok
    14:46:11.0843 0292 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
    14:46:11.0937 0292 dmboot - ok
    14:46:12.0109 0292 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
    14:46:12.0109 0292 dmio - ok
    14:46:12.0281 0292 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    14:46:12.0281 0292 dmload - ok
    14:46:12.0500 0292 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    14:46:12.0500 0292 DMusic - ok
    14:46:12.0625 0292 dpti2o - ok
    14:46:12.0796 0292 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    14:46:12.0812 0292 drmkaud - ok
    14:46:13.0093 0292 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    14:46:13.0109 0292 Fastfat - ok
    14:46:13.0390 0292 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    14:46:13.0421 0292 Fdc - ok
    14:46:13.0578 0292 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
    14:46:13.0593 0292 Fips - ok
    14:46:13.0796 0292 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    14:46:13.0828 0292 Flpydisk - ok
    14:46:14.0203 0292 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    14:46:14.0218 0292 FltMgr - ok
    14:46:14.0515 0292 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    14:46:14.0515 0292 Fs_Rec - ok
    14:46:14.0750 0292 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    14:46:14.0765 0292 Ftdisk - ok
    14:46:15.0109 0292 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
    14:46:15.0109 0292 GEARAspiWDM - ok
    14:46:15.0640 0292 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    14:46:15.0640 0292 Gpc - ok
    14:46:15.0906 0292 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
    14:46:15.0906 0292 hamachi - ok
    14:46:16.0093 0292 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    14:46:16.0093 0292 HidUsb - ok
    14:46:16.0343 0292 hpn - ok
    14:46:16.0625 0292 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
    14:46:16.0640 0292 HPZid412 - ok
    14:46:17.0125 0292 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
    14:46:17.0156 0292 HPZipr12 - ok
    14:46:17.0531 0292 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
    14:46:17.0531 0292 HPZius12 - ok
    14:46:17.0765 0292 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    14:46:17.0796 0292 HTTP - ok
    14:46:17.0953 0292 i2omgmt - ok
    14:46:18.0093 0292 i2omp - ok
    14:46:18.0312 0292 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    14:46:18.0312 0292 i8042prt - ok
    14:46:18.0437 0292 ialm (1406d6ef4436aee970efe13193123965) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
    14:46:18.0437 0292 ialm - ok
    14:46:18.0578 0292 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    14:46:18.0578 0292 Imapi - ok
    14:46:18.0703 0292 ini910u - ok
    14:46:18.0875 0292 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys
    14:46:18.0937 0292 IntelIde - ok
    14:46:19.0093 0292 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    14:46:19.0125 0292 ip6fw - ok
    14:46:19.0328 0292 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    14:46:19.0421 0292 IpFilterDriver - ok
    14:46:19.0578 0292 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    14:46:19.0593 0292 IpInIp - ok
    14:46:19.0750 0292 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    14:46:19.0765 0292 IpNat - ok
    14:46:19.0953 0292 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    14:46:19.0953 0292 IPSec - ok
    14:46:20.0234 0292 IPVNMon (46723535d730918adb1887c7c69dbd75) C:\WINDOWS\system32\drivers\IPVNMon.sys
    14:46:20.0250 0292 IPVNMon - ok
    14:46:20.0406 0292 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    14:46:20.0406 0292 IRENUM - ok
    14:46:20.0609 0292 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    14:46:20.0609 0292 isapnp - ok
    14:46:21.0000 0292 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    14:46:21.0000 0292 Kbdclass - ok
    14:46:21.0265 0292 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
    14:46:21.0265 0292 kbdhid - ok
    14:46:21.0562 0292 kbeepm (f34795947382d8e1a515b8ef6a3b3258) C:\DOCUME~1\Owner\LOCALS~1\Temp\kbeepm.sys
    14:46:48.0859 0292 kbeepm - ok
    14:46:49.0265 0292 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    14:46:49.0265 0292 kmixer - ok
    14:46:49.0437 0292 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    14:46:49.0437 0292 KSecDD - ok
    14:46:49.0562 0292 lbrtfdc - ok
    14:46:49.0906 0292 Leapfrog-USBLAN (5cffda921fe0c9e9ebde3150d3c81594) C:\WINDOWS\system32\DRIVERS\btblan.sys
    14:46:49.0921 0292 Leapfrog-USBLAN - ok
    14:46:50.0390 0292 ltmodem5 (fa2ed4a054360f3f873c15420f1f19cc) C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
    14:46:50.0718 0292 ltmodem5 - ok
    14:46:51.0312 0292 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
    14:46:51.0312 0292 LVPr2Mon - ok
    14:46:51.0781 0292 LVRS (87ecce893d8aec5a9337b917742d339c) C:\WINDOWS\system32\DRIVERS\lvrs.sys
    14:46:51.0875 0292 LVRS - ok
    14:46:52.0078 0292 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys
    14:46:52.0093 0292 MBAMProtector - ok
    14:46:52.0484 0292 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    14:46:52.0500 0292 mnmdd - ok
    14:46:52.0968 0292 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
    14:46:52.0968 0292 Modem - ok
    14:46:53.0515 0292 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    14:46:53.0546 0292 Mouclass - ok
    14:46:54.0015 0292 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    14:46:54.0046 0292 mouhid - ok
    14:46:54.0406 0292 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    14:46:54.0406 0292 MountMgr - ok
    14:46:54.0734 0292 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
    14:46:54.0750 0292 MpFilter - ok
    14:46:54.0953 0292 MpKsl2e2f9cfb (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKsl2e2f9cfb.sys
    14:46:54.0984 0292 MpKsl2e2f9cfb - ok
    14:46:55.0375 0292 MpKsl4f9774f9 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKsl4f9774f9.sys
    14:46:55.0390 0292 MpKsl4f9774f9 - ok
    14:46:55.0671 0292 MpKslf7ed5795 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKslf7ed5795.sys
    14:46:55.0671 0292 MpKslf7ed5795 - ok
    14:46:55.0828 0292 MpKslfca545f3 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKslfca545f3.sys
    14:46:55.0875 0292 MpKslfca545f3 - ok
    14:46:56.0031 0292 mraid35x - ok
    14:46:56.0281 0292 mrtRate - ok
    14:46:56.0781 0292 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    14:46:56.0828 0292 MRxDAV - ok
    14:46:57.0765 0292 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    14:46:57.0875 0292 MRxSmb - ok
    14:46:58.0234 0292 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    14:46:58.0234 0292 Msfs - ok
    14:46:58.0500 0292 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    14:46:58.0515 0292 MSKSSRV - ok
    14:46:58.0968 0292 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    14:46:58.0968 0292 MSPCLOCK - ok
    14:46:59.0171 0292 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    14:46:59.0187 0292 MSPQM - ok
    14:46:59.0593 0292 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    14:46:59.0593 0292 mssmbios - ok
    14:46:59.0921 0292 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
    14:46:59.0921 0292 MSTEE - ok
    14:47:00.0265 0292 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
    14:47:00.0265 0292 Mup - ok
    14:47:00.0578 0292 MxlW2k (63d074073d5fda93163517c2a8f2ba5a) C:\WINDOWS\system32\drivers\MxlW2k.sys
    14:47:00.0578 0292 MxlW2k - ok
    14:47:00.0953 0292 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    14:47:00.0953 0292 NABTSFEC - ok
    14:47:01.0171 0292 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    14:47:01.0218 0292 NDIS - ok
    14:47:01.0500 0292 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    14:47:01.0515 0292 NdisIP - ok
    14:47:01.0781 0292 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    14:47:01.0796 0292 NdisTapi - ok
    14:47:02.0218 0292 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    14:47:02.0218 0292 Ndisuio - ok
    14:47:02.0750 0292 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    14:47:02.0750 0292 NdisWan - ok
    14:47:03.0109 0292 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
    14:47:03.0125 0292 NDProxy - ok
    14:47:03.0656 0292 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    14:47:03.0656 0292 NetBIOS - ok
    14:47:03.0968 0292 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    14:47:03.0984 0292 NetBT - ok
    14:47:04.0343 0292 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
    14:47:04.0343 0292 NIC1394 - ok
    14:47:04.0984 0292 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    14:47:05.0000 0292 Npfs - ok
    14:47:05.0640 0292 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    14:47:06.0078 0292 Ntfs - ok
    14:47:06.0921 0292 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    14:47:06.0937 0292 Null - ok
    14:47:07.0375 0292 nv (920d2d77a9c17dc628123d16eeea5c22) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    14:47:08.0843 0292 nv - ok
    14:47:09.0281 0292 NVENET (2afa043b0243137d0edc8cfb8305551b) C:\WINDOWS\system32\DRIVERS\NVENET.sys
    14:47:09.0296 0292 NVENET - ok
    14:47:09.0531 0292 nv_agp (29291c3a7256337327051cc37e4fc09a) C:\WINDOWS\system32\DRIVERS\nv_agp.sys
    14:47:09.0531 0292 nv_agp - ok
    14:47:09.0703 0292 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    14:47:09.0703 0292 NwlnkFlt - ok
    14:47:10.0312 0292 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    14:47:10.0390 0292 NwlnkFwd - ok
    14:47:10.0828 0292 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
    14:47:10.0875 0292 ohci1394 - ok
    14:47:12.0906 0292 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
    14:47:12.0937 0292 Parport - ok
    14:47:13.0562 0292 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    14:47:13.0625 0292 PartMgr - ok
    14:47:14.0156 0292 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    14:47:14.0171 0292 ParVdm - ok
    14:47:14.0765 0292 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
    14:47:14.0812 0292 PCI - ok
    14:47:15.0140 0292 PCIDump - ok
    14:47:15.0671 0292 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
    14:47:15.0671 0292 PCIIde - ok
    14:47:15.0984 0292 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
    14:47:16.0015 0292 Pcmcia - ok
    14:47:16.0375 0292 PDCOMP - ok
    14:47:16.0921 0292 PDFRAME - ok
    14:47:17.0281 0292 PDRELI - ok
    14:47:17.0640 0292 PDRFRAME - ok
    14:47:17.0968 0292 pepifilter (b20f958b207e6aaac5f70d04dd2c30d8) C:\WINDOWS\system32\DRIVERS\lv302af.sys
    14:47:17.0968 0292 pepifilter - ok
    14:47:18.0109 0292 perc2 - ok
    14:47:18.0437 0292 perc2hib - ok
    14:47:18.0625 0292 Pernmdd - ok
    14:47:18.0781 0292 pfc (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
    14:47:18.0781 0292 pfc - ok
    14:47:18.0984 0292 PGPdisk (91b3d4431995ee702d3d5f38ca6aecbe) C:\WINDOWS\system32\drivers\PGPdisk.sys
    14:47:18.0984 0292 PGPdisk - ok
    14:47:19.0156 0292 PGPsdkDriver (f0c4d8989acbff5ba0e8bab95cd3b480) C:\WINDOWS\system32\Drivers\PGPsdk.sys
    14:47:19.0187 0292 PGPsdkDriver - ok
    14:47:21.0546 0292 PID_PEPI (dd184d9adfe2a8a21741dbdfe9e22f5c) C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
    14:47:22.0953 0292 PID_PEPI - ok
    14:47:23.0484 0292 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    14:47:23.0484 0292 PptpMiniport - ok
    14:47:23.0906 0292 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
    14:47:23.0906 0292 Processor - ok
    14:47:24.0156 0292 Ps2 (390c204ced3785609ab24e9c52054a84) C:\WINDOWS\system32\DRIVERS\PS2.sys
    14:47:24.0171 0292 Ps2 - ok
    14:47:24.0437 0292 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    14:47:24.0437 0292 PSched - ok
    14:47:24.0687 0292 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    14:47:24.0718 0292 Ptilink - ok
    14:47:25.0000 0292 PxHelp20 (80c824c78dd1cac1833ae5dcca02b327) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
    14:47:25.0015 0292 PxHelp20 - ok
    14:47:25.0203 0292 QGKDNWIH - ok
    14:47:25.0328 0292 ql1080 - ok
    14:47:25.0531 0292 Ql10wnt - ok
    14:47:25.0812 0292 ql12160 - ok
    14:47:26.0265 0292 ql1240 - ok
    14:47:26.0578 0292 ql1280 - ok
    14:47:26.0796 0292 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    14:47:26.0843 0292 RasAcd - ok
    14:47:27.0187 0292 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    14:47:27.0203 0292 Rasl2tp - ok
    14:47:27.0421 0292 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    14:47:27.0437 0292 RasPppoe - ok
    14:47:27.0625 0292 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    14:47:27.0656 0292 Raspti - ok
    14:47:27.0859 0292 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    14:47:27.0906 0292 Rdbss - ok
    14:47:28.0078 0292 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    14:47:28.0078 0292 RDPCDD - ok
    14:47:28.0406 0292 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    14:47:28.0437 0292 RDPWD - ok
    14:47:28.0609 0292 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
    14:47:28.0625 0292 redbook - ok
    14:47:28.0796 0292 rtl8139 (2ef9c0dc26b30b2318b1fc3faa1f0ae7) C:\WINDOWS\system32\DRIVERS\R8139n51.SYS
    14:47:28.0796 0292 rtl8139 - ok
    14:47:29.0031 0292 S3Psddr (0dbcc071a268e0340a2ba6bdd98bace4) C:\WINDOWS\system32\DRIVERS\s3gnbm.sys
    14:47:29.0031 0292 S3Psddr - ok
    14:47:29.0421 0292 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    14:47:29.0437 0292 Secdrv - ok
    14:47:29.0593 0292 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    14:47:29.0593 0292 Serenum - ok
    14:47:30.0046 0292 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
    14:47:30.0062 0292 Serial - ok
    14:47:30.0531 0292 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    14:47:30.0546 0292 Sfloppy - ok
    14:47:30.0671 0292 Simbad - ok
    14:47:30.0906 0292 SiS315 (bdfef5c5d41ba377852389e8f07104ea) C:\WINDOWS\system32\DRIVERS\sisgrp.sys
    14:47:30.0937 0292 SiS315 - ok
    14:47:31.0562 0292 SISAGP (923d23638c616eecb0d811461161d0b8) C:\WINDOWS\system32\DRIVERS\SISAGPX.sys
    14:47:31.0609 0292 SISAGP - ok
    14:47:31.0765 0292 SiSkp (7e9e5823afbb5af2851abb1659ff627d) C:\WINDOWS\system32\DRIVERS\srvkp.sys
    14:47:31.0765 0292 SiSkp - ok
    14:47:31.0984 0292 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    14:47:31.0984 0292 SLIP - ok
    14:47:32.0093 0292 Sparrow - ok
    14:47:32.0265 0292 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    14:47:32.0265 0292 splitter - ok
    14:47:32.0406 0292 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
    14:47:32.0406 0292 sr - ok
    14:47:32.0562 0292 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
    14:47:32.0609 0292 Srv - ok
    14:47:32.0765 0292 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    14:47:32.0796 0292 streamip - ok
    14:47:33.0109 0292 SunkFilt (a3df1466aafdc62b21765072c5edaa9a) C:\WINDOWS\System32\Drivers\sunkfilt.sys
    14:47:33.0125 0292 SunkFilt - ok
    14:47:33.0250 0292 Sunkfiltp - ok
    14:47:33.0390 0292 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    14:47:33.0390 0292 swenum - ok
    14:47:33.0578 0292 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    14:47:33.0578 0292 swmidi - ok
    14:47:33.0703 0292 symc810 - ok
    14:47:33.0875 0292 symc8xx - ok
    14:47:34.0015 0292 SymIM - ok
    14:47:34.0265 0292 SymIMMP - ok
    14:47:34.0359 0292 sym_hi - ok
    14:47:34.0437 0292 sym_u3 - ok
    14:47:34.0578 0292 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    14:47:34.0578 0292 sysaudio - ok
    14:47:34.0781 0292 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    14:47:34.0796 0292 Tcpip - ok
    14:47:34.0984 0292 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    14:47:34.0984 0292 TDPIPE - ok
    14:47:35.0187 0292 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    14:47:35.0187 0292 TDTCP - ok
    14:47:35.0343 0292 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    14:47:35.0359 0292 TermDD - ok
    14:47:35.0578 0292 TosIde - ok
    14:47:35.0921 0292 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    14:47:35.0953 0292 Udfs - ok
    14:47:36.0375 0292 ultra - ok
    14:47:36.0796 0292 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    14:47:37.0062 0292 Update - ok
    14:47:37.0500 0292 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
    14:47:37.0515 0292 usbaudio - ok
    14:47:37.0703 0292 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    14:47:37.0718 0292 usbccgp - ok
    14:47:38.0062 0292 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    14:47:38.0062 0292 usbehci - ok
    14:47:38.0578 0292 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    14:47:38.0578 0292 usbhub - ok
    14:47:38.0843 0292 USBNET (64d91cb46928af2924eb0a98e0767c70) C:\WINDOWS\system32\DRIVERS\vnetusbl.sys
    14:47:38.0984 0292 USBNET - ok
    14:47:39.0390 0292 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
    14:47:39.0421 0292 usbohci - ok
    14:47:39.0765 0292 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    14:47:39.0796 0292 usbprint - ok
    14:47:40.0187 0292 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    14:47:40.0218 0292 usbscan - ok
    14:47:40.0500 0292 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    14:47:40.0500 0292 USBSTOR - ok
    14:47:40.0718 0292 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    14:47:40.0718 0292 usbuhci - ok
    14:47:40.0937 0292 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    14:47:40.0937 0292 VgaSave - ok
    14:47:41.0125 0292 viaagp1 (0e3e3fae3a0a58b8d936a8e841a17d16) C:\WINDOWS\system32\DRIVERS\viaagp1.sys
    14:47:41.0125 0292 viaagp1 - ok
    14:47:41.0406 0292 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
    14:47:41.0406 0292 ViaIde - ok
    14:47:41.0578 0292 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
    14:47:41.0593 0292 VolSnap - ok
    14:47:41.0921 0292 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    14:47:41.0937 0292 Wanarp - ok
    14:47:42.0312 0292 WDICA - ok
    14:47:43.0000 0292 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    14:47:43.0078 0292 wdmaud - ok
    14:47:43.0734 0292 WmBEnum (671db6a9b772b807721147c28faf760f) C:\WINDOWS\system32\drivers\WmBEnum.sys
    14:47:43.0750 0292 WmBEnum - ok
    14:47:43.0937 0292 WmFilter (cffe18db8140b00335221907a694dd01) C:\WINDOWS\system32\drivers\WmFilter.sys
    14:47:43.0937 0292 WmFilter - ok
    14:47:44.0125 0292 WmVirHid (2e17ea3b132963e3c07d50d68d2df54e) C:\WINDOWS\system32\drivers\WmVirHid.sys
    14:47:44.0125 0292 WmVirHid - ok
    14:47:44.0828 0292 WmXlCore (0ece3bb49eb9ee42c411a0f1ec39dda9) C:\WINDOWS\system32\drivers\WmXlCore.sys
    14:47:44.0875 0292 WmXlCore - ok
    14:47:45.0468 0292 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
    14:47:45.0500 0292 WpdUsb - ok
    14:47:45.0937 0292 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
    14:47:45.0953 0292 WS2IFSL - ok
    14:47:46.0187 0292 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    14:47:46.0187 0292 WSTCODEC - ok
    14:47:46.0500 0292 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    14:47:46.0578 0292 WudfPf - ok
    14:47:46.0750 0292 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    14:47:46.0765 0292 WudfRd - ok
    14:47:47.0062 0292 {6080A529-897E-4629-A488-ABA0C29B635E} (fd1f4e9cf06c71c8d73a24acf18d8296) C:\WINDOWS\system32\drivers\ialmsbw.sys
    14:47:47.0062 0292 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
    14:47:47.0390 0292 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (d4d7331d33d1fa73e588e5ce0d90a4c1) C:\WINDOWS\system32\drivers\ialmkchw.sys
    14:47:47.0437 0292 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
    14:47:47.0468 0292 MBR (0x1B8) (2519a2daa142378a32e1022f9de90da4) \Device\Harddisk0\DR0
    14:47:47.0484 0292 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
    14:47:47.0484 0292 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
    14:47:47.0500 0292 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
    14:47:47.0515 0292 \Device\Harddisk1\DR1 - ok
    14:47:47.0531 0292 Boot (0x1200) (a56480bae8f30b6cd2e30d85ede19a7b) \Device\Harddisk0\DR0\Partition0
    14:47:47.0531 0292 \Device\Harddisk0\DR0\Partition0 - ok
    14:47:47.0562 0292 Boot (0x1200) (71e9eff86efc7cbe6d2566d5399e86d2) \Device\Harddisk0\DR0\Partition1
    14:47:47.0578 0292 \Device\Harddisk0\DR0\Partition1 - ok
    14:47:47.0593 0292 Boot (0x1200) (62e8c2703f57f7c62d415472f9a3dbfd) \Device\Harddisk1\DR1\Partition0
    14:47:47.0593 0292 \Device\Harddisk1\DR1\Partition0 - ok
    14:47:47.0593 0292 ============================================================
    14:47:47.0593 0292 Scan finished
    14:47:47.0593 0292 ============================================================
    14:47:47.0671 3072 Detected object count: 1
    14:47:47.0671 3072 Actual detected object count: 1
    14:48:12.0218 3072 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
    14:48:12.0296 3072 \Device\Harddisk0\DR0 - ok
    14:48:12.0296 3072 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
    14:48:33.0046 1588 Deinitialize success
     
  7. 2012/01/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good :)

    Post new aswMBR log.

    Then...

    I can see some Norton's leftovers.
    Run this tool to remove them: https://www-secure.symantec.com/nor...&version=1&pvid=f-home&entsrc=redirect_pubweb

    Next.....

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.

    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  8. 2012/01/07
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    aswMBR version 0.9.7.675 Copyright(c) 2011 AVAST Software
    Run date: 2012-01-07 15:35:22
    -----------------------------
    15:35:22.937 OS Version: Windows 5.1.2600 Service Pack 3
    15:35:22.937 Number of processors: 1 586 0x801
    15:35:22.937 ComputerName: YOUR-XHTR8HVC4P UserName: Owner
    15:35:26.359 Initialize success
    15:35:39.890 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
    15:35:39.890 Disk 0 Vendor: ST3120022A 3.06 Size: 114473MB BusType: 3
    15:35:39.921 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
    15:35:39.921 Disk 1 Vendor: WDC_WD800JB-00JJC0 05.01C05 Size: 76319MB BusType: 3
    15:35:41.937 Disk 0 MBR read successfully
    15:35:41.937 Disk 0 MBR scan
    15:35:41.937 Disk 0 unknown MBR code
    15:35:43.953 Disk 0 scanning sectors +234420480
    15:35:43.968 Disk 0 scanning C:\WINDOWS\system32\drivers
    15:35:50.343 Service scanning
    15:35:51.750 Disk 0 trace - called modules:
    15:35:51.765 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
    15:35:51.765 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f63ab8]
    15:35:51.765 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\00000065[0x86f6ff18]
    15:35:51.765 5 ACPI.sys[f743e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x86f46940]
    15:35:51.765 Scan finished successfully
    15:36:22.171 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat "
    15:36:22.171 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR 1 2012 x2.txt "


    ---------------------------
    Ran Nortan removel, thanks

    ---------------------------

    ComboFix 12-01-06.03 - Owner 01/07/2012 16:00:47.1.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.582 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\Administrator\WINDOWS
    c:\documents and settings\Default User\WINDOWS
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{25bd20e4-9136-4e68-9895-52968b78d009}
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{25bd20e4-9136-4e68-9895-52968b78d009}\chrome.manifest
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{25bd20e4-9136-4e68-9895-52968b78d009}\chrome\xulcache.jar
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{25bd20e4-9136-4e68-9895-52968b78d009}\install.rdf
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{3140763c-a0c8-4748-b0d2-bdf74d9cd63c}
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{3140763c-a0c8-4748-b0d2-bdf74d9cd63c}\chrome.manifest
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{3140763c-a0c8-4748-b0d2-bdf74d9cd63c}\chrome\xulcache.jar
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{3140763c-a0c8-4748-b0d2-bdf74d9cd63c}\install.rdf
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{5290e661-a829-4402-a85e-e8ff3031d22f}
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{5290e661-a829-4402-a85e-e8ff3031d22f}\chrome.manifest
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{5290e661-a829-4402-a85e-e8ff3031d22f}\chrome\xulcache.jar
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{5290e661-a829-4402-a85e-e8ff3031d22f}\install.rdf
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{ae2685b6-2b97-4ba4-a536-e52e27298a2f}
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{ae2685b6-2b97-4ba4-a536-e52e27298a2f}\chrome.manifest
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{ae2685b6-2b97-4ba4-a536-e52e27298a2f}\chrome\xulcache.jar
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{ae2685b6-2b97-4ba4-a536-e52e27298a2f}\install.rdf
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{d50b427b-ce3c-4456-8661-519810830d5e}
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{d50b427b-ce3c-4456-8661-519810830d5e}\chrome.manifest
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{d50b427b-ce3c-4456-8661-519810830d5e}\chrome\xulcache.jar
    c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{d50b427b-ce3c-4456-8661-519810830d5e}\install.rdf
    c:\documents and settings\Owner\sikidjqwrm.tmp
    c:\documents and settings\Owner\WINDOWS
    c:\program files\Common Files\download
    c:\program files\Uninstall.exe
    c:\windows\dasetup.log
    c:\windows\EventSystem.log
    c:\windows\help\wmplayer.bak
    c:\windows\IA
    c:\windows\patch.exe
    c:\windows\system32\config\systemprofile\WINDOWS
    c:\windows\system32\icnfe.dll
    c:\windows\system32\mtjpgb.dll
    c:\windows\system32\mtjpgh.dll
    c:\windows\system32\ps2.bat
    D:\Autorun.inf
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_6TO4
    -------\Service_6to4
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-12-07 to 2012-01-07 )))))))))))))))))))))))))))))))
    .
    .
    2012-01-07 21:32 . 2012-01-07 21:32 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\offreg.dll
    2012-01-07 21:05 . 2012-01-07 21:05 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\PCHealth
    2012-01-05 20:08 . 2012-01-05 20:08 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKslca877dae.sys
    2012-01-05 15:46 . 2012-01-05 15:46 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKslfca545f3.sys
    2012-01-05 04:34 . 2012-01-05 04:34 -------- d-----w- c:\documents and settings\Administrator
    2012-01-04 03:02 . 2011-11-30 07:21 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\mpengine.dll
    2012-01-04 03:02 . 2011-11-15 19:29 222080 ------w- c:\windows\system32\MpSigStub.exe
    2012-01-04 02:57 . 2012-01-04 03:00 -------- d-----w- c:\program files\Microsoft Security Client
    2012-01-03 05:26 . 2012-01-03 05:26 -------- d-s---w- c:\documents and settings\LocalService\UserData
    2012-01-03 05:11 . 2012-01-03 05:11 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities
    2011-12-25 18:09 . 2011-12-25 18:09 -------- d-----w- c:\windows\9013B37099D4404B9DB9779B51CEB5FF.TMP
    2011-12-25 18:08 . 2011-12-25 18:08 -------- d-----w- c:\program files\DIFX
    2011-12-25 18:08 . 2011-11-12 16:18 33792 ----a-w- c:\windows\system32\drivers\btblan.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-12-10 20:24 . 2011-07-14 04:16 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-10-19 09:26 . 2011-06-09 12:22 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-03-02 19:26 . 2011-03-02 19:26 8593992 ----a-w- c:\program files\Firefox Setup 3.6.14.exe
    2011-01-19 08:27 . 2011-01-19 08:27 76464 ----a-w- c:\program files\fraps64.dat
    2011-01-19 08:27 . 2011-01-19 08:27 2350256 ----a-w- c:\program files\fraps.exe
    2011-01-19 08:26 . 2011-01-19 08:26 159744 ----a-w- c:\program files\frapslcd.dll
    2010-12-02 08:08 . 2010-12-02 08:08 253104 ----a-w- c:\program files\fraps32.dll
    2010-12-02 08:08 . 2010-12-02 08:08 197808 ----a-w- c:\program files\fraps64.dll
    2010-11-23 00:32 . 2010-11-23 00:32 5840851 ----a-w- c:\program files\3dfiction_v01.scr
    2010-11-23 00:32 . 2010-11-23 00:32 206754 ----a-w- c:\program files\uninstall 3dfiction_v01.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BackupNotify "= "c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 24576]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "Skype "= "c:\program files\Skype\Phone\Skype.exe" [2011-08-18 17360520]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Recguard "= "c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
    "AlcxMonitor "= "ALCXMNTR.EXE" [2004-09-07 57344]
    "IPInSightMonitor 02 "= "c:\program files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" [2003-06-11 122880]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2005-08-02 7110656]
    "Monitor "= "c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-11-12 268640]
    "HPDJ Taskbar Utility "= "c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-23 176128]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    "LogitechQuickCamRibbon "= "c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
    "LogMeIn Hamachi Ui "= "c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 1955208]
    "MSC "= "c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "DWQueuedReporting "= "c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
    .
    c:\documents and settings\Owner\Start Menu\Programs\Startup\
    OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-1-25 61440]
    .
    c:\documents and settings\Administrator\Start Menu\Programs\Startup\
    AutoTBar.exe [2003-6-18 53248]
    mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    PGPtray.lnk - c:\program files\PGP Corporation\PGP for Windows XP\PGPtray.exe [2003-11-4 331776]
    SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2004-4-30 217088]
    .
    c:\documents and settings\Default User\Start Menu\Programs\Startup\
    AutoTBar.exe [2003-6-18 53248]
    mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
    2003-02-21 10:50 40960 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @= "Service "
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe "=
    "c:\\Program Files\\Valve\\Steam\\SteamApps\\headlessrubberducky\\counter-strike source\\hl2.exe "=
    "c:\\Program Files\\AIM\\aim.exe "=
    "c:\\Program Files\\Nesticle 3.0\\NESTCL95.EXE "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\Program Files\\Quake 4\\Quake4.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe "=
    "c:\\Program Files\\Logitech\\Vid HD\\Vid.exe "=
    "c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sega classics\\SEGAGenesisClassics.exe "=
    "c:\\Program Files\\Java\\jre6\\bin\\java.exe "=
    "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe "=
    "c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\memoir '44 online\\Memoir'44 Online.exe "=
    "c:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe "=
    .
    R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [8/15/2011 3:18 PM 1361288]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/13/2011 11:16 PM 652872]
    R2 PGPsdkServ;PGPsdkService;c:\windows\system32\PGPsdkServ.exe [11/4/2003 2:10 PM 65536]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 6:15 PM 24652]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/13/2011 11:16 PM 20464]
    S1 MpKslfca545f3;MpKslfca545f3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKslfca545f3.sys [1/5/2012 10:46 AM 29904]
    S1 Pernmdd;Pernmdd;\??\c:\windows\System32\drivers\dmitcpip.sys --> c:\windows\System32\drivers\dmitcpip.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
    S2 mrtRate;mrtRate; [x]
    S2 QGKDNWIH;QGKDNWIH;\??\c:\windows\system32\qgkdnwih.tyw --> c:\windows\system32\qgkdnwih.tyw [?]
    S3 kbeepm;kbeepm;\??\c:\docume~1\Owner\LOCALS~1\Temp\kbeepm.sys --> c:\docume~1\Owner\LOCALS~1\Temp\kbeepm.sys [?]
    S3 Leapfrog-USBLAN;Leapfrog-USBLAN;c:\windows\system32\drivers\btblan.sys [12/25/2011 1:08 PM 33792]
    S3 USBNET;Instant Wireless USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\vnetusbl.sys [10/7/2007 10:32 PM 107648]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WUAUSERV
    *Deregistered* - IPVNMon
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
    .
    2012-01-07 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
    .
    2012-01-07 c:\windows\Tasks\MpIdleTask.job
    - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    mStart Page = hxxp://www.msn.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    uInternet Connection Wizard,ShellNext = hxxp://us9.hpwis.com/
    uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
    IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
    IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
    IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
    TCP: DhcpNameServer = 192.168.1.1
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: network.proxy.type - 2
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    .
    - - - - ORPHANS REMOVED - - - -
    .
    BHO-{2D45CDBE-8420-4D2E-B1C6-7FA278D50C58} - c:\documents and settings\Owner\Local Settings\Application Data\SystemCodec.dll
    HKCU-Run-IntelNotifierNotifier - (no file)
    HKLM-Run-RegSvr32 - (no file)
    HKLM-Run-PLFSetL - c:\windows\\PLFSetL.exe
    HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
    AddRemove-1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC - c:\program files\WildTangent\Apps\GameChannel\Games\1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC\Uninstall.exe
    AddRemove-342970EF-F8DF-4E9B-8477-A1A03E3E15E1 - c:\program files\WildTangent\Apps\GameChannel\Games\342970EF-F8DF-4E9B-8477-A1A03E3E15E1\Uninstall.exe
    AddRemove-357ECB62-CD36-4B63-B57E-769D0CA174F4 - c:\program files\WildTangent\Apps\GameChannel\Games\357ECB62-CD36-4B63-B57E-769D0CA174F4\Uninstall.exe
    AddRemove-36317AE4-57EC-4F3E-B828-009A3DD96BE8 - c:\program files\WildTangent\Apps\GameChannel\Games\36317AE4-57EC-4F3E-B828-009A3DD96BE8\Uninstall.exe
    AddRemove-4F0AE1FB-4082-4A27-8363-05D292D92FB0 - c:\program files\WildTangent\Apps\GameChannel\Games\4F0AE1FB-4082-4A27-8363-05D292D92FB0\Uninstall.exe
    AddRemove-53EF27E9-150C-4063-8343-61C45FC6BB98 - c:\program files\WildTangent\Apps\GameChannel\Games\53EF27E9-150C-4063-8343-61C45FC6BB98\Uninstall.exe
    AddRemove-5415BC25-6D6C-46C4-B34C-EA8470FE56D5 - c:\program files\WildTangent\Apps\GameChannel\Games\5415BC25-6D6C-46C4-B34C-EA8470FE56D5\Uninstall.exe
    AddRemove-5F804D2B-A66D-4F0A-B64E-FBDA3F52E3F8 - c:\program files\WildTangent\Apps\GameChannel\Games\5F804D2B-A66D-4F0A-B64E-FBDA3F52E3F8\Uninstall.exe
    AddRemove-62067F4C-84A9-45B9-8573-B90468B0A3EF - c:\program files\WildTangent\Apps\GameChannel\Games\62067F4C-84A9-45B9-8573-B90468B0A3EF\Uninstall.exe
    AddRemove-BFBCBAE3-8293-4215-9C4F-C2402C118EDB - c:\program files\WildTangent\Apps\GameChannel\Games\BFBCBAE3-8293-4215-9C4F-C2402C118EDB\Uninstall.exe
    AddRemove-C99127BE-FDE5-49BD-9621-BFE5DF19AA34 - c:\program files\WildTangent\Apps\GameChannel\Games\C99127BE-FDE5-49BD-9621-BFE5DF19AA34\Uninstall.exe
    AddRemove-D11F7128-8CBD-408B-8BF8-034604DEDD42 - c:\program files\WildTangent\Apps\GameChannel\Games\D11F7128-8CBD-408B-8BF8-034604DEDD42\Uninstall.exe
    AddRemove-DA44615A-C243-46A4-8E47-184CFF33CD38 - c:\program files\WildTangent\Apps\GameChannel\Games\DA44615A-C243-46A4-8E47-184CFF33CD38\Uninstall.exe
    AddRemove-DF479CEA-34C0-460F-9B56-93BCE4CD4086 - c:\program files\WildTangent\Apps\GameChannel\Games\DF479CEA-34C0-460F-9B56-93BCE4CD4086\Uninstall.exe
    AddRemove-Fraps - c:\program files\uninstall.exe
    AddRemove-HijackThis - e:\spyware\Hijackthis\HijackThis.exe
    AddRemove-UltimateBet - c:\program files\_uninstallation_info\UltimateBet\CasinoUninstall.exe
    AddRemove-UnityWebPlayer - c:\documents and settings\Owner\Local Settings\Application Data\Unity\WebPlayer\Uninstall.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-01-07 16:33
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\QGKDNWIH]
    "ImagePath "= "\??\c:\windows\system32\qgkdnwih.tyw "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\DefaultIcon]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe,0 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\shell\open\command]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe \ "%1\" "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\shell\print\command]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe /p \ "%1\" "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\shell\printto\command]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe /pt \ "%1\" \ "%2\" \ "%3\" \ "%4\" "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(740)
    c:\program files\Softex\OmniPass\opxpgina.dll
    .
    - - - - - - - > 'explorer.exe'(1436)
    c:\windows\TEMP\logishrd\LVPrcInj01.dll
    c:\windows\system32\PGPhk.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe
    c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    c:\windows\System32\nvsvc32.exe
    c:\program files\Softex\OmniPass\Omniserv.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Softex\OmniPass\OPXPApp.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\ALCXMNTR.EXE
    c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    c:\program files\OpenOffice.org 2.0\program\soffice.exe
    c:\program files\OpenOffice.org 2.0\program\soffice.BIN
    c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2012-01-07 16:46:33 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-01-07 21:46
    .
    Pre-Run: 42,415,345,664 bytes free
    Post-Run: 45,467,033,600 bytes free
    .
    - - End Of File - - 47C54369AC663B264773F39A167F1B15
     
  9. 2012/01/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Unless you installed Viewpoint Manager knowledgeably...
    Go Start>Control Panel>Add\Remove (Programs and Features in Vista), and...
    Uninstall any of the following programs associated with Viewpoint:
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ( "drive-by-install ") as it is installed without your consent through programs like AOL, AIM, Compuserve, etc.

    =============================================================

    1. Please open Notepad (Start>All Programs>Accessories>Notepad).

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\9013B37099D4404B9DB9779B51CEB5FF.TMP
    c:\windows\System32\drivers\dmitcpip.sys
    c:\windows\system32\qgkdnwih.tyw
    c:\docume~1\Owner\LOCALS~1\Temp\kbeepm.sys
    
    
    Folder::
    
    Driver::
    Pernmdd
    QGKDNWIH
    kbeepm
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
     "DisableMonitoring "=dword:00000000
    [-HKEY_LOCAL_MACHINE\System\ControlSet003\Services\QGKDNWIH]
    
    ClearJavaCache::
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  10. 2012/01/07
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    Removed the viewpoint, thanks

    ------------------------


    ComboFix 12-01-07.02 - Owner 01/07/2012 19:05:07.2.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.542 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
    AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    .
    FILE ::
    "c:\docume~1\Owner\LOCALS~1\Temp\kbeepm.sys "
    "c:\windows\9013B37099D4404B9DB9779B51CEB5FF.TMP "
    "c:\windows\System32\drivers\dmitcpip.sys "
    "c:\windows\system32\qgkdnwih.tyw "
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\system32\SET36.tmp
    c:\windows\system32\SET39.tmp
    c:\windows\system32\SET3E.tmp
    c:\windows\system32\SET45.tmp
    c:\windows\TEMP\logishrd\LVPrcInj01.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_KBEEPM
    -------\Legacy_PERNMDD
    -------\Legacy_QGKDNWIH
    -------\Service_kbeepm
    -------\Service_Pernmdd
    -------\Service_QGKDNWIH
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-12-08 to 2012-01-08 )))))))))))))))))))))))))))))))
    .
    .
    2012-01-08 00:21 . 2012-01-08 00:21 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EBBA9AE2-06D7-4550-984C-8E736E076A52}\offreg.dll
    2012-01-07 21:48 . 2011-11-30 07:21 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-01-07 21:47 . 2011-11-30 07:21 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EBBA9AE2-06D7-4550-984C-8E736E076A52}\mpengine.dll
    2012-01-07 21:05 . 2012-01-07 21:05 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\PCHealth
    2012-01-05 04:34 . 2012-01-05 04:34 -------- d-----w- c:\documents and settings\Administrator
    2012-01-04 03:02 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
    2012-01-04 02:57 . 2012-01-04 03:00 -------- d-----w- c:\program files\Microsoft Security Client
    2012-01-03 05:26 . 2012-01-03 05:26 -------- d-s---w- c:\documents and settings\LocalService\UserData
    2012-01-03 05:11 . 2012-01-03 05:11 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities
    2011-12-25 18:09 . 2011-12-25 18:09 -------- d-----w- c:\windows\9013B37099D4404B9DB9779B51CEB5FF.TMP
    2011-12-25 18:08 . 2011-12-25 18:08 -------- d-----w- c:\program files\DIFX
    2011-12-25 18:08 . 2011-11-12 16:18 33792 ----a-w- c:\windows\system32\drivers\btblan.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-12-10 20:24 . 2011-07-14 04:16 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-10-19 09:26 . 2011-06-09 12:22 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-03-02 19:26 . 2011-03-02 19:26 8593992 ----a-w- c:\program files\Firefox Setup 3.6.14.exe
    2011-01-19 08:27 . 2011-01-19 08:27 76464 ----a-w- c:\program files\fraps64.dat
    2011-01-19 08:27 . 2011-01-19 08:27 2350256 ----a-w- c:\program files\fraps.exe
    2011-01-19 08:26 . 2011-01-19 08:26 159744 ----a-w- c:\program files\frapslcd.dll
    2010-12-02 08:08 . 2010-12-02 08:08 253104 ----a-w- c:\program files\fraps32.dll
    2010-12-02 08:08 . 2010-12-02 08:08 197808 ----a-w- c:\program files\fraps64.dll
    2010-11-23 00:32 . 2010-11-23 00:32 5840851 ----a-w- c:\program files\3dfiction_v01.scr
    2010-11-23 00:32 . 2010-11-23 00:32 206754 ----a-w- c:\program files\uninstall 3dfiction_v01.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BackupNotify "= "c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 24576]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "Skype "= "c:\program files\Skype\Phone\Skype.exe" [2011-08-18 17360520]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Recguard "= "c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
    "AlcxMonitor "= "ALCXMNTR.EXE" [2004-09-07 57344]
    "IPInSightMonitor 02 "= "c:\program files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" [2003-06-11 122880]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2005-08-02 7110656]
    "Monitor "= "c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-11-12 268640]
    "HPDJ Taskbar Utility "= "c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-23 176128]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    "LogitechQuickCamRibbon "= "c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
    "LogMeIn Hamachi Ui "= "c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 1955208]
    "MSC "= "c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "DWQueuedReporting "= "c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
    .
    c:\documents and settings\Owner\Start Menu\Programs\Startup\
    OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-1-25 61440]
    .
    c:\documents and settings\Administrator\Start Menu\Programs\Startup\
    AutoTBar.exe [2003-6-18 53248]
    mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    PGPtray.lnk - c:\program files\PGP Corporation\PGP for Windows XP\PGPtray.exe [2003-11-4 331776]
    SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2004-4-30 217088]
    .
    c:\documents and settings\Default User\Start Menu\Programs\Startup\
    AutoTBar.exe [2003-6-18 53248]
    mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
    2003-02-21 10:50 40960 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @= "Service "
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe "=
    "c:\\Program Files\\Valve\\Steam\\SteamApps\\headlessrubberducky\\counter-strike source\\hl2.exe "=
    "c:\\Program Files\\AIM\\aim.exe "=
    "c:\\Program Files\\Nesticle 3.0\\NESTCL95.EXE "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\Program Files\\Quake 4\\Quake4.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe "=
    "c:\\Program Files\\Logitech\\Vid HD\\Vid.exe "=
    "c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sega classics\\SEGAGenesisClassics.exe "=
    "c:\\Program Files\\Java\\jre6\\bin\\java.exe "=
    "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe "=
    "c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\memoir '44 online\\Memoir'44 Online.exe "=
    "c:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe "=
    .
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/13/2011 11:16 PM 20464]
    S1 MpKslfca545f3;MpKslfca545f3;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKslfca545f3.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17DE866B-43D6-4D18-8A69-EE0B448D3A1B}\MpKslfca545f3.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
    S2 mrtRate;mrtRate; [x]
    S3 Leapfrog-USBLAN;Leapfrog-USBLAN;c:\windows\system32\drivers\btblan.sys [12/25/2011 1:08 PM 33792]
    S3 USBNET;Instant Wireless USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\vnetusbl.sys [10/7/2007 10:32 PM 107648]
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - IPVNMon
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
    .
    2012-01-08 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
    .
    2012-01-08 c:\windows\Tasks\MpIdleTask.job
    - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    mStart Page = hxxp://www.msn.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    uInternet Connection Wizard,ShellNext = hxxp://us9.hpwis.com/
    uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
    IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
    IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
    IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
    TCP: DhcpNameServer = 192.168.1.1
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: network.proxy.type - 2
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    .
    - - - - ORPHANS REMOVED - - - -
    .
    BHO-{2D45CDBE-8420-4D2E-B1C6-7FA278D50C58} - (no file)
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-01-07 19:23
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\DefaultIcon]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe,0 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\shell\open\command]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe \ "%1\" "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\shell\print\command]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe /p \ "%1\" "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\B*a*b*e*l*P*a*d*.*‡eöN\shell\printto\command]
    @= "c:\\PROGRA~1\\BABLEP~1\\BabelPad.exe /pt \ "%1\" \ "%2\" \ "%3\" \ "%4\" "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(736)
    c:\program files\Softex\OmniPass\opxpgina.dll
    .
    - - - - - - - > 'explorer.exe'(5132)
    c:\windows\TEMP\logishrd\LVPrcInj01.dll
    c:\windows\system32\PGPhk.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\LogMeIn Hamachi\hamachi-2.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe
    c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
    c:\windows\System32\nvsvc32.exe
    c:\program files\Softex\OmniPass\Omniserv.exe
    c:\windows\System32\PGPsdkServ.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Softex\OmniPass\OPXPApp.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\ALCXMNTR.EXE
    c:\program files\OpenOffice.org 2.0\program\soffice.exe
    c:\program files\OpenOffice.org 2.0\program\soffice.BIN
    c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2012-01-07 19:32:26 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-01-08 00:32
    ComboFix2.txt 2012-01-07 21:46
    .
    Pre-Run: 45,136,412,672 bytes free
    Post-Run: 45,127,401,472 bytes free
    .
    - - End Of File - - FCEAC660EB169197C1119724606F1D32
     
  11. 2012/01/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    How is computer doing?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  12. 2012/01/08
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    OTL Extras logfile created on: 1/8/2012 1:30:04 AM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.5512)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1023.36 Mb Total Physical Memory | 766.28 Mb Available Physical Memory | 74.88% Memory free
    2.41 Gb Paging File | 2.03 Gb Available in Paging File | 84.43% Paging File free
    Paging file location(s): C:\pagefile.sys 0 0 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 104.75 Gb Total Space | 42.05 Gb Free Space | 40.14% Space Free | Partition Type: NTFS
    Drive D: | 7.02 Gb Total Space | 2.42 Gb Free Space | 34.48% Space Free | Partition Type: FAT32
    Drive K: | 74.53 Gb Total Space | 12.58 Gb Free Space | 16.87% Space Free | Partition Type: NTFS

    Computer Name: YOUR-XHTR8HVC4P | User Name: Owner | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

    [HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]

    [HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
    "DisableMonitoring" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files\LeapFrog\LeapFrog Connect\LeapFrogConnect.exe" = C:\Program Files\LeapFrog\LeapFrog Connect\LeapFrogConnect.exe:*:Enabled:LeapFrog Connect -- (LeapFrog Enterprises, Inc.)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe" = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe:*:Disabled:BackWeb-137903 -- ()
    "C:\Program Files\Valve\Steam\SteamApps\headlessrubberducky\counter-strike source\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\headlessrubberducky\counter-strike source\hl2.exe:*:Enabled:hl2 -- ()
    "C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
    "C:\Program Files\Nesticle 3.0\NESTCL95.EXE" = C:\Program Files\Nesticle 3.0\NESTCL95.EXE:*:Enabled:NESTCL95 -- ()
    "C:\Program Files\Quake 4\Quake4.exe" = C:\Program Files\Quake 4\Quake4.exe:*:Enabled:Quake 4 -- ()
    "C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:YServer Module -- (Yahoo! Inc.)
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\Logitech\Vid HD\Vid.exe" = C:\Program Files\Logitech\Vid HD\Vid.exe:*:Enabled:Logitech Vid HD -- (Logitech Inc.)
    "C:\Program Files\Valve\Steam\SteamApps\common\sega classics\SEGAGenesisClassics.exe" = C:\Program Files\Valve\Steam\SteamApps\common\sega classics\SEGAGenesisClassics.exe:*:Enabled:SEGA Genesis & Mega Drive Classics -- ()
    "C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
    "C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
    "C:\Program Files\Valve\Steam\SteamApps\common\memoir '44 online\Memoir'44 Online.exe" = C:\Program Files\Valve\Steam\SteamApps\common\memoir '44 online\Memoir'44 Online.exe:*:Enabled:Memoir '44 Online -- (Days of Wonder)
    "C:\Program Files\LeapFrog\LeapFrog Connect\LeapFrogConnect.exe" = C:\Program Files\LeapFrog\LeapFrog Connect\LeapFrogConnect.exe:*:Enabled:LeapFrog Connect -- (LeapFrog Enterprises, Inc.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam(TM)
    "{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
    "{06040040-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Encyclopedia Standard 2006
    "{0613467F-A45E-4CB1-9ECE-1F3DD79FB927}" = Easy Internet Sign-up
    "{097346E0-6A51-11D1-AD16-00A0C95E0503}(SBC)" = Visual IP InSight(SBC)
    "{098637A9-C208-4398-8374-853151D35200}" = SkinsHP2
    "{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
    "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
    "{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
    "{1266764D-FC4F-4FA7-B63B-884D53B1680F}" = NetAssistant
    "{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
    "{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4(TM)
    "{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
    "{16F0EE77-B2B1-4417-A8CC-07E06C78CCC4}" = Matrix-ks
    "{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}" = Microsoft Works Suite Add-in for Microsoft Word
    "{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
    "{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
    "{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
    "{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
    "{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
    "{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
    "{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
    "{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3F46F8A1-75E1-4bbd-A02D-650C84422E87}" = HPImageZone
    "{42948B02-7191-40CF-92AA-4E330869B28B}" = HPIZ Fix2
    "{45B6180B-DCAB-4093-8EE8-6164457517F0}" = Photosmart 140,240,7200,7600,7700,7900 Series
    "{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4FCC384C-18EA-4E25-9281-A06AE006D219}" = Weblink
    "{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
    "{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
    "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
    "{590D4F8F-98FE-47FA-AC2B-3F22FDCF7C09}" = ShareIns
    "{5D7F0A0E-369E-46C0-9F99-FAB21A064781}" = HP Photo and Imaging 2.0 - Photosmart Cameras
    "{5D95AD35-368F-47D5-B63A-A082DDF00116}" = Microsoft Digital Image Standard 2006 Editor
    "{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
    "{62B3B82F-B9B1-4D8C-B5D1-C3DAEA1F73AA}" = PhotoGallery
    "{642B473F-2584-4C21-AB10-6D1EF28BD601}" = QuickProjects
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{686BB230-DE5B-44F4-8DB0-4F9BEE7310F7}" = OpenOffice.org 2.0
    "{691F4068-81BF-49E3-B32E-FE3E16400112}" = Microsoft Digital Image Standard 2006 Library
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
    "{6F7ECD56-E224-4263-9B7E-158E5CECC43B}" = HP Photo and Imaging 2.1 - Scanjet 2400 Series
    "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
    "{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
    "{791B20D4-AE59-4DE9-B45F-BA01F3D0A493}" = ArcSoft ShowBiz 2
    "{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
    "{7BBD57D6-09B1-4CC3-9664-A0D53EE25247}" = PSShortcutsP
    "{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}" = Zune Desktop Theme
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}" = Microsoft Streets & Trips 2006
    "{84464E93-0222-42E5-8CCE-A618F86210F3}" = SkinsHP1
    "{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
    "{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
    "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics Driver
    "{8BBB5E4C-3F5E-4C07-BFBE-33B34600783A}" = LogMeIn Hamachi
    "{8EA9B3A5-31DA-42A5-A571-E70FB1329D80}" = RolePlayingMaster
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{9013B370-99D4-404B-9DB9-779B51CEB5FF}" = LeapFrog My Pals Plugin
    "{901B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
    "{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
    "{91A5B6C0-EF4E-4830-AC7D-6761C0A9B292}" = hp deskjet 3600
    "{93EC14D5-7AAA-4EAD-BB75-013817A96598}" = Logitech Gaming Software
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = RecordNow!
    "{98386532-89B5-42FF-AC49-60C0D9DBD8B1}" = CreativeProjects
    "{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
    "{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
    "{A36BE275-BD22-406C-8D2D-ED99F9E6C0B4}" = IKEA HomePlanner Kitchen
    "{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
    "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skypeâ„¢ 5.5
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{ABDA9912-5D00-11D4-BAE7-9367CA097955}" = Macromedia Dreamweaver 4
    "{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B9266252-00CB-4140-B740-DE88FC0F7609}" = hpmdtab
    "{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
    "{C224DBAC-57F4-40FD-BB83-09DB532CCD68}" = HPSystemDiagnostics
    "{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
    "{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CFD1B282-555D-494d-8231-4175C2AF08C2}" = PrintScreen
    "{D19C4BCB-FAAE-48C1-A423-3DA40C3B7F42}" = LeapFrog Leapster Explorer Plugin
    "{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
    "{E05895C5-FE97-4334-8D73-B0089FD07CE3}" = Multimedia Card Reader
    "{E0828692-FD9D-459F-9312-C645C3CA6650}" = HP Photo and Imaging 2.0 - Deskjet Series
    "{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
    "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
    "{EFCE5837-FC21-11D6-9D24-00010240CE95}" = Java 2 Runtime Environment, SE v1.4.1_02
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
    "{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
    "{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}" = OmniPass
    "{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
    "{F9D59E62-845F-49A2-8B75-DDB00661673C}" = LeapFrog Connect
    "{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
    "8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D" = Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012)
    "Adobe Acrobat 4.0" = Adobe Acrobat 4.0
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Adobe Photoshop 5.0 Limited Edition" = Adobe Photoshop 5.0 Limited Edition
    "AOL Instant Messenger" = AOL Instant Messenger
    "Audacity_is1" = Audacity 1.2.6
    "BackWeb-137903 Uninstaller" = Updates from HP
    "BroadJump Client Foundation" = BroadJump Client Foundation
    "BSW" = BrettspielWelt
    "CDex" = CDex extraction audio
    "Coupon Printer for Windows2.0" = Coupon Printer for Windows
    "D&D35E" = D&D35E Screen Saver
    "Diablo" = Diablo
    "Diablo II" = Diablo II
    "ElectriCalm 3D Screensaver" = ElectriCalm 3D Screensaver (remove only)
    "FLV Player" = FLV Player 2.0, build 24
    "GoogleVideoPlayer" = Google Video Player
    "HeroScribe" = HeroScribe 1.0pre1
    "Hoyle Board Games 3" = Hoyle Board Games 3
    "HP Imaging Device Functions" = HP Imaging Device Functions 5.0
    "HP Photo & Imaging" = HP Photo & Imaging 3.0
    "HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
    "HP-Color LaserJet 2600n" = Color LaserJet 2600n
    "HPExtendedCapabilities" = HP Extended Capabilities 5.0
    "HPTOOLKIT" = toolkit
    "InstallShield_{0613467F-A45E-4CB1-9ECE-1F3DD79FB927}" = Easy Internet Sign-up
    "InstallShield_{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4(TM)
    "InstallShield_{E05895C5-FE97-4334-8D73-B0089FD07CE3}" = Multimedia Card Reader
    "InstallShield_{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
    "Java Web Start" = Java Web Start
    "LeapsterExplorerPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Leapster Explorer Plugin)
    "Logitech Vid" = Logitech Vid HD
    "LogMeIn Hamachi" = LogMeIn Hamachi
    "lvdrivers_12.10" = Logitech Webcam Software Driver Package
    "Macromedia Shockwave Player" = Macromedia Shockwave Player
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "Microsoft Security Client" = Microsoft Security Essentials
    "Money2006b" = Microsoft Money 2006
    "Mozilla Firefox (3.6.25)" = Mozilla Firefox (3.6.25)
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "MSN Music Assistant" = MSN Music Assistant
    "MyPalsPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)
    "Network Play System (Patching)" = Network Play System (Patching)
    "NVIDIA Drivers" = NVIDIA Drivers
    "OSS Video Decompiler_is1" = OSS Video Decompiler 5.5.0.3
    "PGP" = PGP 8.0.3
    "PictureItPrem_v11" = Microsoft Digital Image Standard 2006
    "PS2" = PS2
    "Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
    "Python 2.2.1" = Python 2.2.1
    "Quake III Arena" = Quake III Arena
    "Quake2UninstallKey" = Quake II
    "RealPlayer 6.0" = RealPlayer
    "S3Display" = S3Display
    "S3Gamma2" = S3Gamma2
    "S3Info2" = S3Info2
    "S3Overlay" = S3Overlay
    "SBC Yahoo! Applications" = SBC Yahoo! Applications
    "SBC.MCCInstall" = SBC Self Support Tool
    "SpamSubtract" = SpamSubtract
    "Spider-Man3D" = www.UselessCreations.com - The Amazing Spider-Man 3D Screensaver v1.7
    "Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
    "ST5UNST #1" = Unreal Editor
    "Steam App 105600" = Terraria
    "Steam App 108210" = Memoir '44 Online
    "Steam App 34270" = SEGA Genesis & Mega Drive Classics
    "Steam App 400" = Portal
    "TextDraw" = TextDraw v5.9 and Imagetrix v5.5
    "Upaint" = Upaint
    "UPCShell" = LeapFrog Connect
    "VC Temptresses" = VC Temptresses Screen Saver
    "Visual Basic 6.0 Working Model Edition" = Microsoft Visual Basic 6.0 Working Model Edition
    "WebPost" = Microsoft Web Publishing Wizard 1.53
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinGimp-2.0_is1" = GIMP 2.4.4
    "WinRAR archiver" = WinRAR archiver
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Works2006Setup" = Microsoft Works Suite 2006 Setup Launcher
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "Yahoo! Applications" = AT&T Yahoo! Applications
    "Yahoo! Photos Drag-Drop Uploader 1v4" = Yahoo! Photos Easy Upload Tool 1v4

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-2545756419-1434360170-1781758304-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Diablo" = Diablo
    "NetAssistant" = NetAssistant for Firefox

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 1/5/2012 2:54:44 PM | Computer Name = YOUR-XHTR8HVC4P | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
    3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
    P8 NIL, P9 NIL, P10 NIL.

    Error - 1/5/2012 4:24:14 PM | Computer Name = YOUR-XHTR8HVC4P | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
    3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
    P8 NIL, P9 NIL, P10 NIL.

    Error - 1/5/2012 4:33:23 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Application Error | ID = 1000
    Description = Faulting application , version 0.0.0.0, faulting module unknown, version
    0.0.0.0, fault address 0x00000000.

    Error - 1/5/2012 4:39:02 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Application Error | ID = 1000
    Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
    teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.

    Error - 1/5/2012 4:42:13 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Application Error | ID = 1004
    Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
    unknown, version 0.0.0.0, fault address 0x00000000.

    Error - 1/6/2012 4:12:36 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Application Error | ID = 1004
    Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
    unknown, version 0.0.0.0, fault address 0x00000000.

    Error - 1/6/2012 4:22:05 PM | Computer Name = YOUR-XHTR8HVC4P | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
    3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
    P8 NIL, P9 NIL, P10 NIL.

    Error - 1/6/2012 4:49:16 PM | Computer Name = YOUR-XHTR8HVC4P | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
    3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
    P8 NIL, P9 NIL, P10 NIL.

    Error - 1/7/2012 4:00:20 PM | Computer Name = YOUR-XHTR8HVC4P | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
    3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
    P8 NIL, P9 NIL, P10 NIL.

    Error - 1/7/2012 5:05:52 PM | Computer Name = YOUR-XHTR8HVC4P | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
    3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
    P8 NIL, P9 NIL, P10 NIL.

    [ System Events ]
    Error - 1/7/2012 5:33:04 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7000
    Description = The mrtRate service failed to start due to the following error: %%2

    Error - 1/7/2012 5:33:05 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    Pernmdd

    Error - 1/7/2012 6:35:17 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7000
    Description = The mrtRate service failed to start due to the following error: %%2

    Error - 1/7/2012 6:35:18 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    Pernmdd

    Error - 1/7/2012 8:00:12 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7034
    Description = The MBAMService service terminated unexpectedly. It has done this
    1 time(s).

    Error - 1/7/2012 8:00:18 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7031
    Description = The Microsoft Antimalware Service service terminated unexpectedly.
    It has done this 1 time(s). The following corrective action will be taken in
    15000 milliseconds: Restart the service.

    Error - 1/7/2012 8:02:14 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7034
    Description = The Process Monitor service terminated unexpectedly. It has done
    this 1 time(s).

    Error - 1/7/2012 8:04:28 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7034
    Description = The Softex OmniPass Service service terminated unexpectedly. It has
    done this 1 time(s).

    Error - 1/7/2012 8:20:16 PM | Computer Name = YOUR-XHTR8HVC4P | Source = PlugPlayManager | ID = 11
    Description = The device Root\LEGACY_KBEEPM\0000 disappeared from the system without
    first being prepared for removal.

    Error - 1/7/2012 8:22:25 PM | Computer Name = YOUR-XHTR8HVC4P | Source = Service Control Manager | ID = 7000
    Description = The mrtRate service failed to start due to the following error: %%2


    < End of report >
     
  13. 2012/01/08
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    I was shutting my pc down last night and it starting doing updates. Not sure how i missed this but u said not to install or remove anything without u saying so. I hope i havent ******* this all up. There was like 28 of them. I was sure if unplugging it would have been a good idea, thought that would have made things worse. I ran OTL BEFORE i shut down.
     
    Last edited: 2012/01/08
  14. 2012/01/08
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/01/08 01:27:27 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
    [2012/01/07 16:05:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\PCHealth
    [2012/01/07 15:57:05 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2012/01/07 15:57:05 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2012/01/07 15:57:05 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2012/01/07 15:57:05 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2012/01/07 15:56:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2012/01/07 15:56:43 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/01/07 15:46:45 | 004,374,340 | R--- | C] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
    [2012/01/05 14:17:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Real
    [2012/01/03 21:57:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
    [2012/01/03 00:20:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
    [2012/01/03 00:20:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2012/01/03 00:11:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Identities
    [2011/12/27 01:17:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\New F
    [2011/12/25 13:08:35 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
    [2011/12/25 13:08:24 | 000,033,792 | ---- | C] (Belcarra Technologies) -- C:\WINDOWS\System32\drivers\btblan.sys
    [2011/12/25 13:05:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\log
    [2011/12/14 00:20:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\tattoo learn
    [2011/08/29 21:22:23 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2uvc.dll
    [2011/03/02 14:26:19 | 008,593,992 | ---- | C] (Mozilla) -- C:\Program Files\Firefox Setup 3.6.14.exe
    [2011/01/19 03:27:48 | 000,076,464 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps64.dat
    [2011/01/19 03:27:46 | 002,350,256 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps.exe
    [2011/01/19 03:26:10 | 000,159,744 | ---- | C] (Beepa P/L) -- C:\Program Files\frapslcd.dll
    [2010/12/02 03:08:12 | 000,253,104 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps32.dll
    [2010/12/02 03:08:12 | 000,197,808 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps64.dll
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/01/08 01:30:55 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
    [2012/01/08 01:27:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
    [2012/01/07 19:27:08 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
    [2012/01/07 19:22:49 | 000,029,137 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
    [2012/01/07 19:22:39 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2012/01/07 19:21:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/01/07 19:21:54 | 1073,139,712 | -HS- | M] () -- C:\hiberfil.sys
    [2012/01/07 19:02:57 | 004,374,340 | R--- | M] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
    [2012/01/07 17:22:18 | 000,013,001 | ---- | M] () -- C:\Documents and Settings\Owner\_viminfo
    [2012/01/07 15:42:08 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe
    [2012/01/07 15:41:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2012/01/07 15:36:22 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\MBR.dat
    [2012/01/07 14:41:55 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2012/01/04 01:34:58 | 000,097,651 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\votelol.jpg
    [2012/01/03 22:00:15 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
    [2012/01/03 21:57:24 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/01/01 13:49:38 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\a glitch but beautiful.bmp
    [2011/12/30 23:06:58 | 000,037,337 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\world according to ronald reagan.jpg
    [2011/12/29 18:44:10 | 000,018,982 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\rac hill.jpg
    [2011/12/29 11:53:36 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\glitched jockey.bmp
    [2011/12/28 02:01:38 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/12/28 01:35:29 | 000,034,770 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\imag.jpg
    [2011/12/26 16:02:42 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\bg leapfrog pur.bmp
    [2011/12/26 13:31:49 | 000,001,085 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\screenshots.lnk
    [2011/12/26 13:30:49 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\screenshot data.bmp
    [2011/12/25 13:46:21 | 000,041,522 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
    [2011/12/25 13:09:49 | 000,000,651 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\LeapFrog Connect.lnk
    [2011/12/25 10:45:27 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\ste pvs Z.bmp
    [2011/12/14 00:09:27 | 000,004,013 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\sgungnir nordic.jpg
    [2011/12/14 00:08:31 | 000,006,762 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\goldenrectangle.jpg
    [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/01/07 15:57:05 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2012/01/07 15:57:05 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2012/01/07 15:57:05 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2012/01/07 15:57:05 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2012/01/07 15:57:05 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2012/01/07 15:42:07 | 000,920,384 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe
    [2012/01/07 15:36:22 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\MBR.dat
    [2012/01/05 15:13:55 | 1073,139,712 | -HS- | C] () -- C:\hiberfil.sys
    [2012/01/04 01:34:33 | 000,097,651 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\votelol.jpg
    [2012/01/03 22:05:07 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
    [2012/01/03 22:05:06 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
    [2012/01/03 22:00:15 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
    [2012/01/03 21:57:54 | 000,001,691 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
    [2012/01/01 13:49:18 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\a glitch but beautiful.bmp
    [2011/12/30 23:06:56 | 000,037,337 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\world according to ronald reagan.jpg
    [2011/12/29 18:44:08 | 000,018,982 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\rac hill.jpg
    [2011/12/29 11:52:32 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\glitched jockey.bmp
    [2011/12/28 01:35:28 | 000,034,770 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\imag.jpg
    [2011/12/26 16:02:17 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\bg leapfrog pur.bmp
    [2011/12/26 13:31:49 | 000,001,085 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\screenshots.lnk
    [2011/12/26 13:30:30 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\screenshot data.bmp
    [2011/12/25 13:09:49 | 000,000,651 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\LeapFrog Connect.lnk
    [2011/12/25 10:44:58 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\ste pvs Z.bmp
    [2011/12/14 00:09:26 | 000,004,013 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\sgungnir nordic.jpg
    [2011/12/14 00:08:30 | 000,006,762 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\goldenrectangle.jpg
    [2011/10/18 22:07:22 | 000,006,555 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\f822c248
    [2011/10/18 22:07:19 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\ef874a4d
    [2011/10/18 21:36:51 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\0f5ab5b2
    [2011/09/01 00:52:02 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/08/31 08:38:01 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
    [2011/08/30 14:36:35 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
    [2011/08/29 21:22:24 | 001,749,376 | ---- | C] () -- C:\WINDOWS\System32\snp2uvc.sys
    [2011/08/29 21:22:23 | 000,028,032 | ---- | C] () -- C:\WINDOWS\System32\sncduvc.sys
    [2011/08/29 21:22:23 | 000,000,131 | ---- | C] () -- C:\WINDOWS\System32\PidList.ini
    [2011/06/25 10:14:11 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2011/06/25 09:55:21 | 000,015,784 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2271568364
    [2011/06/25 09:52:38 | 000,019,444 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2702064725
    [2011/06/25 09:51:27 | 000,017,060 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\pslfh888qr6kqq7l08484432
    [2011/06/25 09:51:27 | 000,015,666 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\pslfh888qr6kqq7l08484432
    [2011/01/19 02:35:18 | 000,001,872 | ---- | C] () -- C:\Program Files\README.HTM
    [2010/11/22 19:32:37 | 005,840,851 | ---- | C] () -- C:\Program Files\3dfiction_v01.scr
    [2010/11/22 19:32:37 | 000,206,754 | ---- | C] () -- C:\Program Files\uninstall 3dfiction_v01.exe
    [2010/11/22 19:30:27 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
    [2010/10/21 19:59:57 | 000,005,406 | ---- | C] () -- C:\WINDOWS\DiabUnin.dat
    [2010/10/20 19:44:57 | 000,035,743 | ---- | C] () -- C:\WINDOWS\DIIUnin.dat
    [2010/02/27 14:06:13 | 000,059,808 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2009/10/07 00:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
    [2009/10/07 00:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
    [2009/03/14 06:26:56 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
    [2008/07/01 21:06:05 | 000,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
    [2008/07/01 20:58:42 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
    [2008/01/19 12:10:28 | 000,000,058 | ---- | C] () -- C:\WINDOWS\WININIT.INI
    [2007/08/11 20:14:21 | 000,000,141 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
    [2007/08/11 20:14:19 | 000,003,399 | R--- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
    [2007/08/11 20:13:37 | 000,749,568 | R--- | C] () -- C:\WINDOWS\System32\agissi.dll
    [2007/08/11 20:13:33 | 011,194,368 | R--- | C] () -- C:\WINDOWS\System32\zhhp_res.dll
    [2007/08/11 20:13:33 | 000,241,664 | R--- | C] () -- C:\WINDOWS\System32\zhhp2600.exe
    [2007/08/11 20:13:32 | 000,282,624 | R--- | C] () -- C:\WINDOWS\System32\zshp2600.exe
    [2007/08/11 20:13:31 | 000,114,688 | R--- | C] () -- C:\WINDOWS\System32\vshp2600.dll
    [2007/07/14 13:31:29 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\uccspecc.sys
    [2007/01/31 20:14:33 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
    [2006/10/19 20:38:08 | 000,078,750 | ---- | C] () -- C:\WINDOWS\hpfins05.dat.temp
    [2006/10/19 20:38:08 | 000,001,350 | ---- | C] () -- C:\WINDOWS\hpfmdl05.dat.temp
    [2006/10/19 20:29:22 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2006/07/15 18:26:45 | 000,040,960 | ---- | C] () -- C:\WINDOWS\sleun99.exe
    [2006/01/08 15:33:56 | 000,001,779 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2005/12/25 23:37:35 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [2005/12/24 15:45:52 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
    [2005/11/22 08:12:45 | 000,041,522 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
    [2005/11/22 07:39:17 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2005/09/06 22:28:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PestPatrol5.INI
    [2005/08/08 19:40:40 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
    [2005/08/02 15:35:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
    [2005/08/02 15:35:00 | 001,519,616 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
    [2005/08/02 15:35:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
    [2005/08/02 15:35:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
    [2005/08/02 15:35:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
    [2005/08/02 15:35:00 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
    [2005/08/02 15:35:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
    [2005/08/02 15:35:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
    [2005/08/02 15:35:00 | 000,393,216 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
    [2005/08/02 15:35:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
    [2005/02/25 20:21:02 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
    [2004/12/27 17:14:47 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
    [2004/09/16 20:37:18 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2004/06/08 06:26:54 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\nthst32.dll
    [2004/04/30 17:24:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
    [2004/03/01 12:25:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
    [2004/01/05 17:30:46 | 000,000,245 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
    [2003/11/22 11:53:43 | 000,054,591 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
    [2003/11/07 22:12:19 | 000,001,466 | ---- | C] () -- C:\WINDOWS\eReg.dat
    [2003/11/05 18:03:35 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
    [2003/11/05 18:03:35 | 000,040,129 | ---- | C] () -- C:\WINDOWS\iccsigs.dat
    [2003/11/05 18:03:35 | 000,000,149 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
    [2003/10/30 17:16:02 | 000,000,948 | ---- | C] () -- C:\WINDOWS\QIII.INI
    [2003/10/30 17:10:48 | 000,000,035 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
    [2003/10/30 17:02:59 | 000,010,354 | ---- | C] () -- C:\WINDOWS\hpdj3600.ini
    [2003/10/30 17:02:41 | 000,000,470 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
    [2003/10/29 19:04:49 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
    [2003/10/29 19:04:49 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
    [2003/10/29 19:04:49 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
    [2003/08/28 22:35:24 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2003/08/28 22:34:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\iAlmcoin.dll
    [2003/08/28 22:19:10 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\mshrml.ini
    [2003/08/25 16:30:53 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [2003/08/25 16:30:52 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [2003/08/25 16:25:37 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [2003/08/25 16:25:33 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [2003/08/25 15:32:34 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [2003/08/25 15:32:34 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [2003/08/25 15:32:30 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
    [2003/08/25 15:32:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
    [2003/08/25 15:32:18 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
    [2003/08/23 22:42:40 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
    [2003/08/23 22:42:12 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
    [2003/08/23 22:42:12 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
    [2003/08/23 22:36:36 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
    [2003/08/23 22:34:35 | 000,090,112 | R--- | C] () -- C:\WINDOWS\bwUnin-6.2.3.66.exe
    [2003/08/23 22:33:23 | 000,026,395 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
    [2003/08/23 22:32:54 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
    [2003/08/23 22:32:20 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
    [2003/08/23 09:25:25 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini
    [2003/08/23 09:25:15 | 000,000,626 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
    [2003/08/23 09:01:26 | 000,006,848 | ---- | C] () -- C:\WINDOWS\System32\hphmon05.dat
    [2003/08/23 09:01:21 | 000,018,403 | ---- | C] () -- C:\WINDOWS\HPHins01.dat
    [2003/08/23 09:01:21 | 000,004,308 | ---- | C] () -- C:\WINDOWS\hphmdl01.dat
    [2003/08/23 08:54:38 | 000,014,598 | ---- | C] () -- C:\WINDOWS\hpdins01.dat
    [2003/08/23 08:54:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpzmdl01.dat
    [2003/08/23 08:46:51 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
    [2003/08/23 08:37:27 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis740.bin
    [2003/08/23 08:37:27 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis650.bin
    [2003/08/23 08:11:57 | 000,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
    [2003/08/23 08:11:57 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
    [2003/08/23 08:11:35 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
    [2003/08/23 07:57:05 | 000,000,802 | ---- | C] () -- C:\WINDOWS\orun32.ini
    [2003/08/23 07:55:18 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2003/08/23 07:51:14 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2003/08/23 07:42:24 | 000,000,667 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
    [2003/08/23 07:42:05 | 000,465,046 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [2003/08/23 07:42:05 | 000,079,434 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [2003/08/23 00:46:54 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2003/08/23 00:46:00 | 000,336,256 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2003/07/24 00:56:49 | 000,000,438 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
    [2003/07/24 00:56:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
    [2003/07/14 14:30:28 | 000,197,120 | ---- | C] () -- C:\WINDOWS\patchw32.dll
    [2003/06/23 20:27:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2003/03/05 21:03:18 | 000,004,978 | ---- | C] () -- C:\WINDOWS\hpfmdl01.dat
    [2003/03/05 17:28:38 | 000,000,309 | ---- | C] () -- C:\WINDOWS\hpfins01.dat
    [2002/05/24 10:00:00 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll
    [2002/05/24 10:00:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll

    ========== LOP Check ==========

    [2003/08/28 22:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\interMute
    [2003/08/23 22:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
    [2010/06/14 21:37:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
    [2009/12/29 18:45:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Leapfrog
    [2011/08/30 13:58:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
    [2003/11/04 14:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PGP Corporation
    [2012/01/07 18:57:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2004/04/30 17:26:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Visual Networks
    [2010/06/29 17:26:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/11/06 17:46:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2003/08/28 22:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\interMute
    [2003/08/23 22:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\SampleView
    [2011/12/28 16:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\.minecraft
    [2005/10/03 19:20:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Aim
    [2010/12/27 22:20:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\BSW
    [2011/03/10 12:09:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Dropbox
    [2011/04/30 20:20:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\gtk-2.0
    [2003/08/28 22:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\interMute
    [2003/10/29 16:00:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo
    [2004/06/18 18:19:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Leadertech
    [2011/03/25 14:39:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\NetAssistant
    [2008/06/12 19:17:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Opera
    [2003/11/04 14:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PGP Corporation
    [2003/08/23 22:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SampleView
    [2007/11/02 08:09:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Snapfish
    [2003/11/05 18:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template
    [2011/03/16 23:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Unity
    [2012/01/07 19:27:08 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
    [2012/01/08 01:30:55 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2011/05/05 11:10:18 | 000,170,684 | ---- | M] () -- C:\aaw7boot.log
    [2003/08/23 07:53:27 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2003/10/29 13:56:45 | 000,000,196 | RHS- | M] () -- C:\BOOT.BAK
    [2011/06/26 00:54:33 | 000,000,315 | -HS- | M] () -- C:\boot.ini
    [2011/10/19 04:41:20 | 000,004,418 | ---- | M] () -- C:\caisslog.txt
    [2002/08/29 07:00:00 | 000,245,920 | RHS- | M] () -- C:\cmldr
    [2012/01/07 19:32:27 | 000,014,563 | ---- | M] () -- C:\ComboFix.txt
    [2003/08/23 07:53:27 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2006/12/24 18:11:20 | 000,000,696 | ---- | M] () -- C:\deltaStartup.log
    [2012/01/07 19:21:54 | 1073,139,712 | -HS- | M] () -- C:\hiberfil.sys
    [2009/12/30 15:25:45 | 000,318,176 | ---- | M] () -- C:\hpfr3600.log
    [2003/08/23 07:53:27 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2007/01/31 20:15:01 | 000,000,208 | -H-- | M] () -- C:\IPH.PH
    [2005/07/13 17:13:24 | 000,002,685 | ---- | M] () -- C:\LGSInst.Log
    [2003/08/23 07:53:27 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2005/12/26 07:02:54 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2009/04/13 19:28:43 | 000,250,048 | RHS- | M] () -- C:\ntldr
    [2012/01/07 19:21:53 | 1609,605,120 | -HS- | M] () -- C:\pagefile.sys
    [2011/07/13 23:13:36 | 000,000,561 | ---- | M] () -- C:\rkill.log
    [2012/01/07 14:48:33 | 000,060,236 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_07.01.2012_14.45.44_log.txt
    [2010/03/30 20:03:40 | 000,000,089 | ---- | M] () -- C:\UBSoftUpdate.log
    [2004/06/16 05:57:47 | 000,000,001 | ---- | M] () -- C:\version
    [2008/05/16 22:36:44 | 000,244,221 | ---- | M] () -- C:\YServer.txt

    < %systemroot%\Fonts\*.com >

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2003/08/23 07:52:59 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2005/05/10 19:48:48 | 000,067,072 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
    [2005/05/31 16:46:30 | 000,049,152 | R--- | M] (Zenographics, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2004/12/01 14:06:00 | 000,917,648 | ---- | M] () -- C:\WINDOWS\AVP.scr
    [2010/11/22 19:48:21 | 000,192,000 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\D&D35E.scr
    [2004/12/01 14:05:58 | 003,533,746 | ---- | M] () -- C:\WINDOWS\KeithArt.scr
    [2004/12/01 14:05:56 | 002,471,369 | ---- | M] () -- C:\WINDOWS\LuisRoyoArt.scr
    [2005/02/20 16:44:54 | 002,524,160 | ---- | M] (KellySoftware) -- C:\WINDOWS\Matrix_ks.SCR
    [2010/11/22 19:16:59 | 001,779,220 | ---- | M] (Comis) -- C:\WINDOWS\Resident Evil Apocalypse.scr
    [2010/11/22 19:30:47 | 000,471,040 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\VC Temptresses.scr
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2010/11/22 19:32:37 | 005,840,851 | ---- | M] () -- C:\Program Files\3dfiction_v01.scr
    [2007/12/10 08:57:40 | 000,000,132 | ---- | M] () -- C:\Program Files\ATT member.txt
    [2011/01/19 02:47:50 | 000,021,387 | ---- | M] () -- C:\Program Files\changes.txt
    [2011/03/02 14:26:19 | 008,593,992 | ---- | M] (Mozilla) -- C:\Program Files\Firefox Setup 3.6.14.exe
    [2011/01/19 03:27:46 | 002,350,256 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps.exe
    [2010/12/02 03:08:12 | 000,253,104 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps32.dll
    [2011/01/19 03:27:48 | 000,076,464 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps64.dat
    [2010/12/02 03:08:12 | 000,197,808 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps64.dll
    [2011/01/19 03:26:10 | 000,159,744 | ---- | M] (Beepa P/L) -- C:\Program Files\frapslcd.dll
    [2011/01/19 02:35:18 | 000,001,872 | ---- | M] () -- C:\Program Files\README.HTM
    [2010/11/22 19:32:37 | 000,206,754 | ---- | M] () -- C:\Program Files\uninstall 3dfiction_v01.exe

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2003/08/23 00:45:19 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
    [2003/08/23 00:45:19 | 000,602,112 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
    [2003/08/23 00:45:19 | 000,385,024 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2009/04/13 19:38:38 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini

    < %systemroot%\system32\config\systemprofile\*.dat /x >
    [2003/08/23 08:08:30 | 000,012,159 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml1.srt
    [2003/08/23 08:08:30 | 000,011,847 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml2.srt

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2009/04/13 19:57:27 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2003/08/23 07:56:52 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2012/01/07 19:02:57 | 004,374,340 | R--- | M] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
    [2011/04/30 10:42:48 | 000,270,142 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Minecraft1.exe
    [2012/01/03 21:56:26 | 008,068,864 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\mseinstall.exe
    [2012/01/07 15:42:08 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe
    [2012/01/08 01:27:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >
    [2007/01/14 15:11:50 | 000,061,440 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\5d6Roll.exe
    [2005/06/29 16:47:38 | 000,012,800 | ---- | M] (Lakeshore Vision & Robotics, LLC) -- C:\Documents and Settings\Owner\My Documents\beep.exe
    [2007/01/13 17:09:04 | 000,073,728 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\CatVsCommoner.exe
    [2007/01/13 17:10:08 | 000,073,728 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\CatVsCommoneZr.exe
    [2006/10/31 09:57:20 | 000,221,184 | ---- | M] (Bottorff Enterprises) -- C:\Documents and Settings\Owner\My Documents\Copyofcitygen[1][1].exe
    [2003/05/13 02:14:00 | 000,663,552 | R--- | M] () -- C:\Documents and Settings\Owner\My Documents\Dungeon Map Generator.exe
    [2007/01/13 17:06:38 | 000,073,728 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\FluffyVsSteve.exe
    [2007/11/14 15:26:34 | 000,020,480 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\Name Gen.exe

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >
    [2002/08/29 07:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\ADDINS\fxsext.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2009/04/13 19:57:28 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Owner\Favorites\Desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
    ElectriCalm 3D Screensaver.exe

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2012/01/08 01:25:48 | 000,606,208 | ---- | M] () -- C:\Documents and Settings\Owner\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2008/04/13 19:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2002/12/17 10:23:28 | 000,015,692 | ---- | M] () -- C:\Program Files\Messenger\license.txt
    [2002/12/17 10:23:22 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
    [2002/12/17 10:23:22 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
    [2002/12/17 10:23:28 | 000,000,807 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
    [2008/05/02 09:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2008/04/13 12:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2008/04/13 19:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2002/08/21 00:08:38 | 000,069,663 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgsin.exe
    [2002/12/17 10:23:18 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
    [2002/12/17 10:23:18 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
    [2002/12/17 10:23:18 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
    [2002/12/17 10:23:24 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
    [2004/07/17 13:41:04 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >
    [1998/05/07 18:04:38 | 000,052,736 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system\hpsysdrv.exe

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    < End of report >
     
  15. 2012/01/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    At this point your computer should be fairly clean so installing updates should be fine.

    You didn't answer my question:
    ============================================================

    OTL.txt log is incomplete.
    You did cut off the upper part.
    Please repost.
     
  16. 2012/01/10
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    Running much better



    OTL logfile created on: 1/8/2012 1:30:04 AM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.5512)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1023.36 Mb Total Physical Memory | 766.28 Mb Available Physical Memory | 74.88% Memory free
    2.41 Gb Paging File | 2.03 Gb Available in Paging File | 84.43% Paging File free
    Paging file location(s): C:\pagefile.sys 0 0 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 104.75 Gb Total Space | 42.05 Gb Free Space | 40.14% Space Free | Partition Type: NTFS
    Drive D: | 7.02 Gb Total Space | 2.42 Gb Free Space | 34.48% Space Free | Partition Type: FAT32
    Drive K: | 74.53 Gb Total Space | 12.58 Gb Free Space | 16.87% Space Free | Partition Type: NTFS

    Computer Name: YOUR-XHTR8HVC4P | User Name: Owner | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/01/08 01:27:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
    PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2011/11/12 12:04:12 | 000,268,640 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
    PRC - [2011/11/12 11:21:58 | 006,141,792 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
    PRC - [2011/08/15 15:18:14 | 001,955,208 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
    PRC - [2011/08/15 15:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
    PRC - [2011/06/15 15:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
    PRC - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    PRC - [2009/10/14 12:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    PRC - [2009/10/14 12:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
    PRC - [2009/10/07 00:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2007/08/09 02:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
    PRC - [2006/06/22 20:28:24 | 002,334,720 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
    PRC - [2006/06/22 01:03:50 | 002,478,080 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 2.0\program\soffice.bin
    PRC - [2005/07/22 21:40:43 | 000,176,128 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    PRC - [2003/10/27 11:53:44 | 000,331,776 | ---- | M] (PGP Corporation) -- C:\Program Files\PGP Corporation\PGP for Windows XP\PGPtray.exe
    PRC - [2003/10/27 11:53:32 | 000,065,536 | ---- | M] (PGP Corporation) -- C:\WINDOWS\system32\PGPsdkServ.exe
    PRC - [2003/06/11 01:52:26 | 000,122,880 | ---- | M] (Visual Networks) -- C:\Program Files\Visual Networks\Visual IP InSight\SBC\ipmon32.exe
    PRC - [2003/02/21 06:07:06 | 000,068,704 | ---- | M] () -- C:\Program Files\Softex\OmniPass\omniServ.exe
    PRC - [2003/02/21 05:50:10 | 000,053,248 | ---- | M] () -- C:\Program Files\Softex\OmniPass\OPXPApp.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/01/07 19:24:02 | 000,109,080 | ---- | M] () -- C:\WINDOWS\Temp\logishrd\LVPrcInj01.dll
    MOD - [2011/09/14 09:19:06 | 008,500,224 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtGui4.dll
    MOD - [2011/09/14 09:19:06 | 002,348,544 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtCore4.dll
    MOD - [2009/10/23 17:01:58 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2009/10/14 12:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    MOD - [2009/10/14 12:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
    MOD - [2006/05/13 05:36:58 | 000,828,416 | ---- | M] () -- C:\Program Files\OpenOffice.org 2.0\program\libxml2.dll
    MOD - [2003/02/21 06:07:06 | 000,068,704 | ---- | M] () -- C:\Program Files\Softex\OmniPass\omniServ.exe
    MOD - [2003/02/21 05:50:12 | 000,040,960 | ---- | M] () -- C:\Program Files\Softex\OmniPass\OPXPGina.dll
    MOD - [2003/02/21 05:50:10 | 000,053,248 | ---- | M] () -- C:\Program Files\Softex\OmniPass\OPXPApp.exe
    MOD - [2003/02/21 05:49:44 | 000,061,440 | ---- | M] () -- C:\Program Files\Softex\OmniPass\ginastub.dll
    MOD - [2001/10/28 15:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Disabled | Stopped] -- -- (HidServ)
    SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
    SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2011/11/12 11:21:58 | 006,141,792 | ---- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
    SRV - [2011/08/15 15:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
    SRV - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
    SRV - [2009/10/07 00:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
    SRV - [2007/08/09 02:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
    SRV - [2003/10/27 11:53:32 | 000,065,536 | ---- | M] (PGP Corporation) [Auto | Running] -- C:\WINDOWS\system32\PGPsdkServ.exe -- (PGPsdkServ)
    SRV - [2003/02/21 06:07:06 | 000,068,704 | ---- | M] () [Auto | Running] -- C:\Program Files\Softex\OmniPass\omniServ.exe -- (omniserv)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
    DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2011/11/12 11:18:10 | 000,033,792 | ---- | M] (Belcarra Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btblan.sys -- (Leapfrog-USBLAN)
    DRV - [2009/10/07 00:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
    DRV - [2009/04/30 18:01:34 | 000,265,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
    DRV - [2009/04/30 17:55:56 | 002,687,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
    DRV - [2009/04/30 17:55:32 | 000,013,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
    DRV - [2009/03/18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
    DRV - [2005/12/12 16:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
    DRV - [2005/01/28 07:03:07 | 000,043,672 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
    DRV - [2004/10/01 10:24:02 | 002,279,424 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
    DRV - [2004/08/04 00:29:51 | 000,166,912 | ---- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3gnbm.sys -- (S3Psddr)
    DRV - [2003/10/27 11:53:52 | 000,026,624 | ---- | M] (PGP Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PGPsdk.sys -- (PGPsdkDriver)
    DRV - [2003/10/27 11:51:46 | 000,170,944 | ---- | M] (PGP Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\PGPdisk.sys -- (PGPdisk)
    DRV - [2003/08/23 09:23:48 | 000,028,276 | ---- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\MxlW2k.sys -- (MxlW2k)
    DRV - [2003/08/11 12:22:54 | 000,040,228 | ---- | M] (Alcor Micro Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Sunkfilt.sys -- (SunkFilt)
    DRV - [2003/07/01 02:41:00 | 000,107,648 | R--- | M] (Cisco-Linksys LLC.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vnetusbl.sys -- (USBNET)
    DRV - [2003/05/14 12:42:56 | 000,021,216 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
    DRV - [2003/05/14 12:42:50 | 000,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
    DRV - [2003/05/14 12:42:48 | 000,005,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
    DRV - [2003/05/14 12:42:44 | 000,044,288 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
    DRV - [2003/05/06 17:34:56 | 000,394,752 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
    DRV - [2003/04/21 23:18:00 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENET.sys -- (NVENET)
    DRV - [2003/04/11 10:51:30 | 000,010,624 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
    DRV - [2003/03/31 23:29:42 | 000,625,537 | ---- | M] (LT) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ltmdmnt.sys -- (ltmodem5)
    DRV - [2003/03/20 00:51:00 | 000,018,688 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp)
    DRV - [2003/02/20 18:18:36 | 000,036,608 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\SISAGPX.sys -- (SISAGP)
    DRV - [2002/12/27 13:41:00 | 000,026,880 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys -- (viaagp1)
    DRV - [2002/10/04 19:04:10 | 000,046,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\R8139n51.sys -- (rtl8139)
    DRV - [2002/10/01 09:22:32 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html


    IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = BE CD 45 2D 20 84 2E 4D B1 C6 7F A2 78 D5 0C 58 [binary data]
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = BE CD 45 2D 20 84 2E 4D B1 C6 7F A2 78 D5 0C 58 [binary data]
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = BE CD 45 2D 20 84 2E 4D B1 C6 7F A2 78 D5 0C 58 [binary data]
    IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = BE CD 45 2D 20 84 2E 4D B1 C6 7F A2 78 D5 0C 58 [binary data]
    IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
    IE - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = BE CD 45 2D 20 84 2E 4D B1 C6 7F A2 78 D5 0C 58 [binary data]
    IE - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
    IE - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;localhost;*.local

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Yahoo "
    FF - prefs.js..browser.search.order.1: "Yahoo "
    FF - prefs.js..browser.search.order.2: " "
    FF - prefs.js..browser.search.selectedEngine: "Yahoo "
    FF - prefs.js..browser.startup.homepage: "http://www.google.com/ "
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
    FF - prefs.js..network.proxy.type: 2


    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll File not found
    FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: C:\Documents and Settings\Owner\Application Data\nprhapengine.dll File not found
    FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/23 01:14:48 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/23 01:14:48 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{1266764D-FC4F-4FA7-B63B-884D53B1680F}: C:\Documents and Settings\Owner\Application Data\NetAssistant\ [2011/03/25 14:39:32 | 000,000,000 | ---D | M]

    [2009/09/11 19:35:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
    [2012/01/07 17:15:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions
    [2011/03/25 14:38:52 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\vgens2qp.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    [2012/01/07 15:46:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2010/12/25 22:52:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    [2010/12/25 22:51:52 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
    [2010/12/25 22:51:49 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

    ========== Chrome ==========

    CHR - default_search_provider: ()
    CHR - default_search_provider: search_url =
    CHR - default_search_provider: suggest_url =

    O1 HOSTS File: ([2012/01/07 19:22:39 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O3 - HKLM\..\Toolbar: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
    O3 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\..\Toolbar\ShellBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
    O3 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\..\Toolbar\WebBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
    O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
    O4 - HKLM..\Run: [IPInSightMonitor 02] C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe (Visual Networks)
    O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
    O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
    O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
    O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
    O4 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\BackupNotify.exe ( )
    O4 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
    O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\AutoTBar.exe ()
    O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\mod_sm.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PGPtray.lnk = C:\Program Files\PGP Corporation\PGP for Windows XP\PGPtray.exe (PGP Corporation)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe (Motive Communications, Inc.)
    O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\AutoTBar.exe ()
    O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\mod_sm.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
    O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: &Yahoo! Search - C:\Program Files\Yahoo!\Common [2008/01/19 12:05:26 | 000,000,000 | ---D | M]
    O8 - Extra context menu item: Yahoo! &Dictionary - C:\Program Files\Yahoo!\Common [2008/01/19 12:05:26 | 000,000,000 | ---D | M]
    O8 - Extra context menu item: Yahoo! &Maps - C:\Program Files\Yahoo!\Common [2008/01/19 12:05:26 | 000,000,000 | ---D | M]
    O8 - Extra context menu item: Yahoo! &SMS - C:\Program Files\Yahoo!\Common [2008/01/19 12:05:26 | 000,000,000 | ---D | M]
    O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Owner\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
    O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Owner\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
    O9 - Extra Button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1135455836765 (WUWebControl Class)
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} Reg Error: Value error. (Java Plug-in 1.6.0_23)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} https://photos.riteaid.com/control/RiteAidOneHourPhotoOnline.cab (Rite Aid One Hour Photo Online Control)
    O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab (Yahoo! Photos Easy Upload Tool Class)
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Value error. (Java Plug-in 1.4.1_02)
    O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} Reg Error: Value error. (Java Plug-in 1.6.0_23)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4000BCD1-33E5-42BC-8BF0-9F783C10E2CB}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BEC2E07B-95CB-427A-91FC-A75F3FD3E784}: DhcpNameServer = 172.16.0.1
    O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
    O18 - Protocol\Handler\mhtml - No CLSID value found
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
    O20 - Winlogon\Notify\OPXPGina: DllName - (C:\Program Files\Softex\OmniPass\opxpgina.dll) - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2003/08/23 07:53:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKU\.DEFAULT\...exe [@ = exefile] -- "%1" %*
    O37 - HKU\S-1-5-18\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: AppMgmt - File not found
    NetSvcs: HidServ - File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found

    Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
    Drivers32: VIDC.I420 - C:\WINDOWS\System32\LVCodec2.dll (Logitech Inc.)
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)
    Drivers32: vidc.wmv3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/01/08 01:27:27 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
    [2012/01/07 16:05:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\PCHealth
    [2012/01/07 15:57:05 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2012/01/07 15:57:05 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2012/01/07 15:57:05 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2012/01/07 15:57:05 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2012/01/07 15:56:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2012/01/07 15:56:43 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/01/07 15:46:45 | 004,374,340 | R--- | C] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
    [2012/01/05 14:17:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Real
    [2012/01/03 21:57:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
    [2012/01/03 00:20:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
    [2012/01/03 00:20:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2012/01/03 00:11:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Identities
    [2011/12/27 01:17:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\New F
    [2011/12/25 13:08:35 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
    [2011/12/25 13:08:24 | 000,033,792 | ---- | C] (Belcarra Technologies) -- C:\WINDOWS\System32\drivers\btblan.sys
    [2011/12/25 13:05:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\log
    [2011/12/14 00:20:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\tattoo learn
    [2011/08/29 21:22:23 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2uvc.dll
    [2011/03/02 14:26:19 | 008,593,992 | ---- | C] (Mozilla) -- C:\Program Files\Firefox Setup 3.6.14.exe
    [2011/01/19 03:27:48 | 000,076,464 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps64.dat
    [2011/01/19 03:27:46 | 002,350,256 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps.exe
    [2011/01/19 03:26:10 | 000,159,744 | ---- | C] (Beepa P/L) -- C:\Program Files\frapslcd.dll
    [2010/12/02 03:08:12 | 000,253,104 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps32.dll
    [2010/12/02 03:08:12 | 000,197,808 | ---- | C] (Beepa P/L) -- C:\Program Files\fraps64.dll
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/01/08 01:30:55 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
    [2012/01/08 01:27:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
    [2012/01/07 19:27:08 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
    [2012/01/07 19:22:49 | 000,029,137 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
    [2012/01/07 19:22:39 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2012/01/07 19:21:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/01/07 19:21:54 | 1073,139,712 | -HS- | M] () -- C:\hiberfil.sys
    [2012/01/07 19:02:57 | 004,374,340 | R--- | M] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
    [2012/01/07 17:22:18 | 000,013,001 | ---- | M] () -- C:\Documents and Settings\Owner\_viminfo
    [2012/01/07 15:42:08 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe
    [2012/01/07 15:41:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2012/01/07 15:36:22 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\MBR.dat
    [2012/01/07 14:41:55 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2012/01/04 01:34:58 | 000,097,651 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\votelol.jpg
    [2012/01/03 22:00:15 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
    [2012/01/03 21:57:24 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/01/01 13:49:38 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\a glitch but beautiful.bmp
    [2011/12/30 23:06:58 | 000,037,337 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\world according to ronald reagan.jpg
    [2011/12/29 18:44:10 | 000,018,982 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\rac hill.jpg
    [2011/12/29 11:53:36 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\glitched jockey.bmp
    [2011/12/28 02:01:38 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/12/28 01:35:29 | 000,034,770 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\imag.jpg
    [2011/12/26 16:02:42 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\bg leapfrog pur.bmp
    [2011/12/26 13:31:49 | 000,001,085 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\screenshots.lnk
    [2011/12/26 13:30:49 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\screenshot data.bmp
    [2011/12/25 13:46:21 | 000,041,522 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
    [2011/12/25 13:09:49 | 000,000,651 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\LeapFrog Connect.lnk
    [2011/12/25 10:45:27 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\ste pvs Z.bmp
    [2011/12/14 00:09:27 | 000,004,013 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\sgungnir nordic.jpg
    [2011/12/14 00:08:31 | 000,006,762 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\goldenrectangle.jpg
    [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/01/07 15:57:05 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2012/01/07 15:57:05 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2012/01/07 15:57:05 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2012/01/07 15:57:05 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2012/01/07 15:57:05 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2012/01/07 15:42:07 | 000,920,384 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe
    [2012/01/07 15:36:22 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\MBR.dat
    [2012/01/05 15:13:55 | 1073,139,712 | -HS- | C] () -- C:\hiberfil.sys
    [2012/01/04 01:34:33 | 000,097,651 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\votelol.jpg
    [2012/01/03 22:05:07 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
    [2012/01/03 22:05:06 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
    [2012/01/03 22:00:15 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
    [2012/01/03 21:57:54 | 000,001,691 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
    [2012/01/01 13:49:18 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\a glitch but beautiful.bmp
    [2011/12/30 23:06:56 | 000,037,337 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\world according to ronald reagan.jpg
    [2011/12/29 18:44:08 | 000,018,982 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\rac hill.jpg
    [2011/12/29 11:52:32 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\glitched jockey.bmp
    [2011/12/28 01:35:28 | 000,034,770 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\imag.jpg
    [2011/12/26 16:02:17 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\bg leapfrog pur.bmp
    [2011/12/26 13:31:49 | 000,001,085 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\screenshots.lnk
    [2011/12/26 13:30:30 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\screenshot data.bmp
    [2011/12/25 13:09:49 | 000,000,651 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\LeapFrog Connect.lnk
    [2011/12/25 10:44:58 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\ste pvs Z.bmp
    [2011/12/14 00:09:26 | 000,004,013 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\sgungnir nordic.jpg
    [2011/12/14 00:08:30 | 000,006,762 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\goldenrectangle.jpg
    [2011/10/18 22:07:22 | 000,006,555 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\f822c248
    [2011/10/18 22:07:19 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\ef874a4d
    [2011/10/18 21:36:51 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\0f5ab5b2
    [2011/09/01 00:52:02 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/08/31 08:38:01 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
    [2011/08/30 14:36:35 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
    [2011/08/29 21:22:24 | 001,749,376 | ---- | C] () -- C:\WINDOWS\System32\snp2uvc.sys
    [2011/08/29 21:22:23 | 000,028,032 | ---- | C] () -- C:\WINDOWS\System32\sncduvc.sys
    [2011/08/29 21:22:23 | 000,000,131 | ---- | C] () -- C:\WINDOWS\System32\PidList.ini
    [2011/06/25 10:14:11 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2011/06/25 09:55:21 | 000,015,784 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2271568364
    [2011/06/25 09:52:38 | 000,019,444 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2702064725
    [2011/06/25 09:51:27 | 000,017,060 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\pslfh888qr6kqq7l08484432
    [2011/06/25 09:51:27 | 000,015,666 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\pslfh888qr6kqq7l08484432
    [2011/01/19 02:35:18 | 000,001,872 | ---- | C] () -- C:\Program Files\README.HTM
    [2010/11/22 19:32:37 | 005,840,851 | ---- | C] () -- C:\Program Files\3dfiction_v01.scr
    [2010/11/22 19:32:37 | 000,206,754 | ---- | C] () -- C:\Program Files\uninstall 3dfiction_v01.exe
    [2010/11/22 19:30:27 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
    [2010/10/21 19:59:57 | 000,005,406 | ---- | C] () -- C:\WINDOWS\DiabUnin.dat
    [2010/10/20 19:44:57 | 000,035,743 | ---- | C] () -- C:\WINDOWS\DIIUnin.dat
    [2010/02/27 14:06:13 | 000,059,808 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2009/10/07 00:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
    [2009/10/07 00:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
    [2009/03/14 06:26:56 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
    [2008/07/01 21:06:05 | 000,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
    [2008/07/01 20:58:42 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
    [2008/01/19 12:10:28 | 000,000,058 | ---- | C] () -- C:\WINDOWS\WININIT.INI
    [2007/08/11 20:14:21 | 000,000,141 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
    [2007/08/11 20:14:19 | 000,003,399 | R--- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
    [2007/08/11 20:13:37 | 000,749,568 | R--- | C] () -- C:\WINDOWS\System32\agissi.dll
    [2007/08/11 20:13:33 | 011,194,368 | R--- | C] () -- C:\WINDOWS\System32\zhhp_res.dll
    [2007/08/11 20:13:33 | 000,241,664 | R--- | C] () -- C:\WINDOWS\System32\zhhp2600.exe
    [2007/08/11 20:13:32 | 000,282,624 | R--- | C] () -- C:\WINDOWS\System32\zshp2600.exe
    [2007/08/11 20:13:31 | 000,114,688 | R--- | C] () -- C:\WINDOWS\System32\vshp2600.dll
    [2007/07/14 13:31:29 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\uccspecc.sys
    [2007/01/31 20:14:33 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
    [2006/10/19 20:38:08 | 000,078,750 | ---- | C] () -- C:\WINDOWS\hpfins05.dat.temp
    [2006/10/19 20:38:08 | 000,001,350 | ---- | C] () -- C:\WINDOWS\hpfmdl05.dat.temp
    [2006/10/19 20:29:22 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2006/07/15 18:26:45 | 000,040,960 | ---- | C] () -- C:\WINDOWS\sleun99.exe
    [2006/01/08 15:33:56 | 000,001,779 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2005/12/25 23:37:35 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [2005/12/24 15:45:52 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
    [2005/11/22 08:12:45 | 000,041,522 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
    [2005/11/22 07:39:17 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2005/09/06 22:28:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PestPatrol5.INI
    [2005/08/08 19:40:40 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
    [2005/08/02 15:35:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
    [2005/08/02 15:35:00 | 001,519,616 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
    [2005/08/02 15:35:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
    [2005/08/02 15:35:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
    [2005/08/02 15:35:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
    [2005/08/02 15:35:00 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
    [2005/08/02 15:35:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
    [2005/08/02 15:35:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
    [2005/08/02 15:35:00 | 000,393,216 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
    [2005/08/02 15:35:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
    [2005/02/25 20:21:02 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
    [2004/12/27 17:14:47 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
    [2004/09/16 20:37:18 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2004/06/08 06:26:54 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\nthst32.dll
    [2004/04/30 17:24:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
    [2004/03/01 12:25:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
    [2004/01/05 17:30:46 | 000,000,245 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
    [2003/11/22 11:53:43 | 000,054,591 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
    [2003/11/07 22:12:19 | 000,001,466 | ---- | C] () -- C:\WINDOWS\eReg.dat
    [2003/11/05 18:03:35 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
    [2003/11/05 18:03:35 | 000,040,129 | ---- | C] () -- C:\WINDOWS\iccsigs.dat
    [2003/11/05 18:03:35 | 000,000,149 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
    [2003/10/30 17:16:02 | 000,000,948 | ---- | C] () -- C:\WINDOWS\QIII.INI
    [2003/10/30 17:10:48 | 000,000,035 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
    [2003/10/30 17:02:59 | 000,010,354 | ---- | C] () -- C:\WINDOWS\hpdj3600.ini
    [2003/10/30 17:02:41 | 000,000,470 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
    [2003/10/29 19:04:49 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
    [2003/10/29 19:04:49 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
    [2003/10/29 19:04:49 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
    [2003/08/28 22:35:24 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2003/08/28 22:34:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\iAlmcoin.dll
    [2003/08/28 22:19:10 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\mshrml.ini
    [2003/08/25 16:30:53 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [2003/08/25 16:30:52 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [2003/08/25 16:25:37 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [2003/08/25 16:25:33 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [2003/08/25 15:32:34 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [2003/08/25 15:32:34 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [2003/08/25 15:32:30 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
    [2003/08/25 15:32:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
    [2003/08/25 15:32:18 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
    [2003/08/23 22:42:40 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
    [2003/08/23 22:42:12 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
    [2003/08/23 22:42:12 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
    [2003/08/23 22:36:36 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
    [2003/08/23 22:34:35 | 000,090,112 | R--- | C] () -- C:\WINDOWS\bwUnin-6.2.3.66.exe
    [2003/08/23 22:33:23 | 000,026,395 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
    [2003/08/23 22:32:54 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
    [2003/08/23 22:32:20 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
    [2003/08/23 09:25:25 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini
    [2003/08/23 09:25:15 | 000,000,626 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
    [2003/08/23 09:01:26 | 000,006,848 | ---- | C] () -- C:\WINDOWS\System32\hphmon05.dat
    [2003/08/23 09:01:21 | 000,018,403 | ---- | C] () -- C:\WINDOWS\HPHins01.dat
    [2003/08/23 09:01:21 | 000,004,308 | ---- | C] () -- C:\WINDOWS\hphmdl01.dat
    [2003/08/23 08:54:38 | 000,014,598 | ---- | C] () -- C:\WINDOWS\hpdins01.dat
    [2003/08/23 08:54:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpzmdl01.dat
    [2003/08/23 08:46:51 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
    [2003/08/23 08:37:27 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis740.bin
    [2003/08/23 08:37:27 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis650.bin
    [2003/08/23 08:11:57 | 000,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
    [2003/08/23 08:11:57 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
    [2003/08/23 08:11:35 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
    [2003/08/23 07:57:05 | 000,000,802 | ---- | C] () -- C:\WINDOWS\orun32.ini
    [2003/08/23 07:55:18 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2003/08/23 07:51:14 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2003/08/23 07:42:24 | 000,000,667 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
    [2003/08/23 07:42:05 | 000,465,046 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [2003/08/23 07:42:05 | 000,079,434 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [2003/08/23 00:46:54 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2003/08/23 00:46:00 | 000,336,256 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2003/07/24 00:56:49 | 000,000,438 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
    [2003/07/24 00:56:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
    [2003/07/14 14:30:28 | 000,197,120 | ---- | C] () -- C:\WINDOWS\patchw32.dll
    [2003/06/23 20:27:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2003/03/05 21:03:18 | 000,004,978 | ---- | C] () -- C:\WINDOWS\hpfmdl01.dat
    [2003/03/05 17:28:38 | 000,000,309 | ---- | C] () -- C:\WINDOWS\hpfins01.dat
    [2002/05/24 10:00:00 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll
    [2002/05/24 10:00:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll

    ========== LOP Check ==========

    [2003/08/28 22:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\interMute
    [2003/08/23 22:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
    [2010/06/14 21:37:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
    [2009/12/29 18:45:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Leapfrog
    [2011/08/30 13:58:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
    [2003/11/04 14:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PGP Corporation
    [2012/01/07 18:57:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2004/04/30 17:26:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Visual Networks
    [2010/06/29 17:26:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/11/06 17:46:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2003/08/28 22:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\interMute
    [2003/08/23 22:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\SampleView
    [2011/12/28 16:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\.minecraft
    [2005/10/03 19:20:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Aim
    [2010/12/27 22:20:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\BSW
    [2011/03/10 12:09:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Dropbox
    [2011/04/30 20:20:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\gtk-2.0
    [2003/08/28 22:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\interMute
    [2003/10/29 16:00:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo
    [2004/06/18 18:19:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Leadertech
    [2011/03/25 14:39:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\NetAssistant
    [2008/06/12 19:17:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Opera
    [2003/11/04 14:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PGP Corporation
    [2003/08/23 22:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SampleView
    [2007/11/02 08:09:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Snapfish
    [2003/11/05 18:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template
    [2011/03/16 23:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Unity
    [2012/01/07 19:27:08 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
    [2012/01/08 01:30:55 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job

    ========== Purity Check ==========
     
  17. 2012/01/10
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2011/05/05 11:10:18 | 000,170,684 | ---- | M] () -- C:\aaw7boot.log
    [2003/08/23 07:53:27 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2003/10/29 13:56:45 | 000,000,196 | RHS- | M] () -- C:\BOOT.BAK
    [2011/06/26 00:54:33 | 000,000,315 | -HS- | M] () -- C:\boot.ini
    [2011/10/19 04:41:20 | 000,004,418 | ---- | M] () -- C:\caisslog.txt
    [2002/08/29 07:00:00 | 000,245,920 | RHS- | M] () -- C:\cmldr
    [2012/01/07 19:32:27 | 000,014,563 | ---- | M] () -- C:\ComboFix.txt
    [2003/08/23 07:53:27 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2006/12/24 18:11:20 | 000,000,696 | ---- | M] () -- C:\deltaStartup.log
    [2012/01/07 19:21:54 | 1073,139,712 | -HS- | M] () -- C:\hiberfil.sys
    [2009/12/30 15:25:45 | 000,318,176 | ---- | M] () -- C:\hpfr3600.log
    [2003/08/23 07:53:27 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2007/01/31 20:15:01 | 000,000,208 | -H-- | M] () -- C:\IPH.PH
    [2005/07/13 17:13:24 | 000,002,685 | ---- | M] () -- C:\LGSInst.Log
    [2003/08/23 07:53:27 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2005/12/26 07:02:54 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2009/04/13 19:28:43 | 000,250,048 | RHS- | M] () -- C:\ntldr
    [2012/01/07 19:21:53 | 1609,605,120 | -HS- | M] () -- C:\pagefile.sys
    [2011/07/13 23:13:36 | 000,000,561 | ---- | M] () -- C:\rkill.log
    [2012/01/07 14:48:33 | 000,060,236 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_07.01.2012_14.45.44_log.txt
    [2010/03/30 20:03:40 | 000,000,089 | ---- | M] () -- C:\UBSoftUpdate.log
    [2004/06/16 05:57:47 | 000,000,001 | ---- | M] () -- C:\version
    [2008/05/16 22:36:44 | 000,244,221 | ---- | M] () -- C:\YServer.txt

    < %systemroot%\Fonts\*.com >

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2003/08/23 07:52:59 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2005/05/10 19:48:48 | 000,067,072 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
    [2005/05/31 16:46:30 | 000,049,152 | R--- | M] (Zenographics, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2004/12/01 14:06:00 | 000,917,648 | ---- | M] () -- C:\WINDOWS\AVP.scr
    [2010/11/22 19:48:21 | 000,192,000 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\D&D35E.scr
    [2004/12/01 14:05:58 | 003,533,746 | ---- | M] () -- C:\WINDOWS\KeithArt.scr
    [2004/12/01 14:05:56 | 002,471,369 | ---- | M] () -- C:\WINDOWS\LuisRoyoArt.scr
    [2005/02/20 16:44:54 | 002,524,160 | ---- | M] (KellySoftware) -- C:\WINDOWS\Matrix_ks.SCR
    [2010/11/22 19:16:59 | 001,779,220 | ---- | M] (Comis) -- C:\WINDOWS\Resident Evil Apocalypse.scr
    [2010/11/22 19:30:47 | 000,471,040 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\VC Temptresses.scr
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2010/11/22 19:32:37 | 005,840,851 | ---- | M] () -- C:\Program Files\3dfiction_v01.scr
    [2007/12/10 08:57:40 | 000,000,132 | ---- | M] () -- C:\Program Files\ATT member.txt
    [2011/01/19 02:47:50 | 000,021,387 | ---- | M] () -- C:\Program Files\changes.txt
    [2011/03/02 14:26:19 | 008,593,992 | ---- | M] (Mozilla) -- C:\Program Files\Firefox Setup 3.6.14.exe
    [2011/01/19 03:27:46 | 002,350,256 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps.exe
    [2010/12/02 03:08:12 | 000,253,104 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps32.dll
    [2011/01/19 03:27:48 | 000,076,464 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps64.dat
    [2010/12/02 03:08:12 | 000,197,808 | ---- | M] (Beepa P/L) -- C:\Program Files\fraps64.dll
    [2011/01/19 03:26:10 | 000,159,744 | ---- | M] (Beepa P/L) -- C:\Program Files\frapslcd.dll
    [2011/01/19 02:35:18 | 000,001,872 | ---- | M] () -- C:\Program Files\README.HTM
    [2010/11/22 19:32:37 | 000,206,754 | ---- | M] () -- C:\Program Files\uninstall 3dfiction_v01.exe

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2003/08/23 00:45:19 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
    [2003/08/23 00:45:19 | 000,602,112 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
    [2003/08/23 00:45:19 | 000,385,024 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2009/04/13 19:38:38 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini

    < %systemroot%\system32\config\systemprofile\*.dat /x >
    [2003/08/23 08:08:30 | 000,012,159 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml1.srt
    [2003/08/23 08:08:30 | 000,011,847 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml2.srt

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2009/04/13 19:57:27 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2003/08/23 07:56:52 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2012/01/07 19:02:57 | 004,374,340 | R--- | M] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
    [2011/04/30 10:42:48 | 000,270,142 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Minecraft1.exe
    [2012/01/03 21:56:26 | 008,068,864 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\mseinstall.exe
    [2012/01/07 15:42:08 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe
    [2012/01/08 01:27:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >
    [2007/01/14 15:11:50 | 000,061,440 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\5d6Roll.exe
    [2005/06/29 16:47:38 | 000,012,800 | ---- | M] (Lakeshore Vision & Robotics, LLC) -- C:\Documents and Settings\Owner\My Documents\beep.exe
    [2007/01/13 17:09:04 | 000,073,728 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\CatVsCommoner.exe
    [2007/01/13 17:10:08 | 000,073,728 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\CatVsCommoneZr.exe
    [2006/10/31 09:57:20 | 000,221,184 | ---- | M] (Bottorff Enterprises) -- C:\Documents and Settings\Owner\My Documents\Copyofcitygen[1][1].exe
    [2003/05/13 02:14:00 | 000,663,552 | R--- | M] () -- C:\Documents and Settings\Owner\My Documents\Dungeon Map Generator.exe
    [2007/01/13 17:06:38 | 000,073,728 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\FluffyVsSteve.exe
    [2007/11/14 15:26:34 | 000,020,480 | ---- | M] (LVR) -- C:\Documents and Settings\Owner\My Documents\Name Gen.exe

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >
    [2002/08/29 07:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\ADDINS\fxsext.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2009/04/13 19:57:28 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Owner\Favorites\Desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
    ElectriCalm 3D Screensaver.exe

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2012/01/08 01:25:48 | 000,606,208 | ---- | M] () -- C:\Documents and Settings\Owner\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2008/04/13 19:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2002/12/17 10:23:28 | 000,015,692 | ---- | M] () -- C:\Program Files\Messenger\license.txt
    [2002/12/17 10:23:22 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
    [2002/12/17 10:23:22 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
    [2002/12/17 10:23:28 | 000,000,807 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
    [2008/05/02 09:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2008/04/13 12:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2008/04/13 19:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2002/08/21 00:08:38 | 000,069,663 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgsin.exe
    [2002/12/17 10:23:18 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
    [2002/12/17 10:23:18 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
    [2002/12/17 10:23:18 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
    [2002/12/17 10:23:24 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
    [2004/07/17 13:41:04 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >
    [1998/05/07 18:04:38 | 000,052,736 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system\hpsysdrv.exe

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    < End of report >
     
  18. 2012/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good news :)

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
      O3 - HKU\S-1-5-21-2545756419-1434360170-1781758304-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
      O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/downlo...22/wmv9VCM.CAB (Reg Error: Key error.)
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      [2011/06/25 09:55:21 | 000,015,784 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2271568364
      [2011/06/25 09:52:38 | 000,019,444 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2702064725
      [2011/06/25 09:51:27 | 000,017,060 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\pslfh888qr6kqq7l08484432
      [2011/06/25 09:51:27 | 000,015,666 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\pslfh888qr6kqq7l08484432
      [2010/06/14 21:37:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
      [2012/01/07 18:57:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
      
      :Commands
      [purity]
      [emptytemp]
      [emptyjava]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ============================================================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.

    =============================================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.


    3. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    4. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  19. 2012/01/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still with me?
     
  20. 2012/01/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Reopened.
     
  21. 2012/01/19
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    All processes killed
    ========== OTL ==========
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully.
    Registry value HKEY_USERS\S-1-5-21-2545756419-1434360170-1781758304-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
    Starting removal of ActiveX control {33564D57-0000-0010-8000-00AA00389B71}
    C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-0000-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found.
    Starting removal of ActiveX control DirectAnimation Java Classes
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found.
    File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
    Starting removal of ActiveX control Microsoft XML Parser for Java
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
    C:\Documents and Settings\All Users\Application Data\2271568364 moved successfully.
    C:\Documents and Settings\All Users\Application Data\2702064725 moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\pslfh888qr6kqq7l08484432 moved successfully.
    C:\Documents and Settings\All Users\Application Data\pslfh888qr6kqq7l08484432 moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\spool\suspic folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\spool folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\sounds\1033 folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\sounds folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\report folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\moved folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\log folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\journal folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\integ folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\HtmlData folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\fw folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\chest folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\backup folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\arpot\TEMP folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\arpot folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5 folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Alwil Software folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint folder moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 32902 bytes

    User: LocalService
    ->Temp folder emptied: 65716 bytes
    ->Temporary Internet Files folder emptied: 16786 bytes
    ->FireFox cache emptied: 42130891 bytes
    ->Flash cache emptied: 2365 bytes

    User: NetworkService
    ->Temp folder emptied: 56864 bytes
    ->Temporary Internet Files folder emptied: 6975902 bytes
    ->Flash cache emptied: 18621 bytes

    User: Owner
    ->Temp folder emptied: 344306 bytes
    ->Temporary Internet Files folder emptied: 67581 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 120009708 bytes
    ->Google Chrome cache emptied: 312146118 bytes
    ->Opera cache emptied: 13569321 bytes
    ->Flash cache emptied: 5420957 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 497555 bytes
    %systemroot%\System32 .tmp files removed: 2577 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 32423748 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 134460690 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 119170686 bytes
    RecycleBin emptied: 2304343 bytes

    Total Files Cleaned = 753.00 mb


    [EMPTYJAVA]

    User: Administrator

    User: All Users

    User: Default User

    User: LocalService

    User: NetworkService

    User: Owner
    ->Java cache emptied: 0 bytes

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default User

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: Owner
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.31.0 log created on 01182012_120603

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.