1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Rootkit??

Discussion in 'Malware and Virus Removal Archive' started by shammie, 2011/11/25.

  1. 2011/11/25
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    [Resolved] Rootkit??

    AVG found a rootkit. below are the log files I had to run gmer, aswmbr in safe mode as they shut created error and shut down windows.
    Thanks for the help.

    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8238

    Windows 6.0.6002 Service Pack 2 (Safe Mode)
    Internet Explorer 9.0.8112.16421

    11/25/2011 9:20:41 AM
    mbam-log-2011-11-25 (09-20-41).txt

    Scan type: Quick scan
    Objects scanned: 161521
    Time elapsed: 1 minute(s), 49 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    ********************
     
  2. 2011/11/25
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    More logs:

    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2011-11-25 08:55:34
    Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.JF10
    Running: gt9eyct0.exe; Driver: C:\Users\me\AppData\Local\Temp\pgldypoc.sys


    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74867817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [748BA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7486BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7485F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [748675E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7485E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74898395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7486DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7485FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7485FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [748571CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [748ECAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7488C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7485D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74856853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7485687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1488] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74862AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
    AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
    AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
    AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{AFCD3C5A-CA3D-46BB-935D-659AAFDC2546}\Linkage@Bind ????f,??????????????????????????????s???????el??????????????????Microsoft???????????????????????????????????*6to4mp?????????????????????????????????????????????????????7F???????????????????????N??Net???????????????????????????????????????????????????4Local Area Connection* 154????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6TO4 Adapter??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{AFCD3C5A-CA3D-46BB-935D-659AAFDC2546}\Linkage@Route ???p?A??????????????????? ???????D?????|??????????V?????????&???????????????????????????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255???????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{077B9F48-6E19-47D7-81DD-38BC9B11ECCF}] DATAGRAM 166?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????A??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{B1E6D741-D952-4BFE-89AB-8C4B3CDBC320}] SEQPACKET 161???? ???????????????????A???????? "?????????????11???????A???R???????A???????A???A????????m4?????A?A?????????????????A??? ???????????????????A??????????????&???????????????????????? ???A???????????????????????????????A????????????m??????????A???????????????????A???A??????????? ?????????????}?? ????!?? "?????p???????S ????N??A???t????Dpip??{4d36e972-e325-11ce-bfc1-08002be10318}? DA???????A???@??? ??Net
    Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{AFCD3C5A-CA3D-46BB-935D-659AAFDC2546}\Linkage@Export ???f?????????f???i???e??tunnel?C9F????<??f???6??????Microsoft 6to4 Adapter Driver???? ???????f???????????G?????????? "??? ??????e\T??? ???f???5?????FAF??tunnel?8-7??? "??f???}?????ice??ndis5_ip6_tunnel?8???????f???4??46???????f???f???h???f???????f???4?????d3E??? ???????f???????????e?!??????????????????????s-8F??? ??????????????x????????g??????????16??AUTO?f??6TO4 Adapter?4 Adapter #17?0F}???????????p???????2?????f?????f??Microsoft???nettun.inf?evi??? ???????f?????G???????#??L????????? ??????2E}?????g???g?B??? ???????f?????f???????#????????????&????????????????????4??? ???????f?????f???????#???????????????????????f????? ???????f???????????G?#???????????????????????f?????????????-??CD???????f???2??06??nettun.inf?ice??? ???f???A?????-78??6to4mp.ndi?456??? ???f???f?????f?f?????f????? ???????f?????f???????#????????????????????? ???????f???????????G?#?????????????????????????????T??ip???????f???-??7C??6to4mp.ndi?895??Microsoft???????0????2???????f??? ???f???3??????????*6to4mp??????f????????????????2Local Area Conne
    Reg HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Linkage@Bind ????????? ???????#??????????????????????$???<???????????????????????????????????*6to4mp??????????1??? ??????????????????????????????????????????????????6???? ??????????????????? ????????????????????????????????r?&????????????????????}??????????????????????????????????????Root\*6TO4MP\0036???????????????????em??TCPIP6TUNNEL?Tcpip6?????????????????????? ?????????????????????#??????????????????????????????????????????????????????TAGRAM 2?FA0??? ?????????????????????#????????.????????????????????i??ta??6to4mp.ndi??=2???????????Y???????????????1??05??????????????????????? ????????????????????????????????????.?????????????Net??H??*6to4mp?????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????.N??????????????????Microsoft????????e????X??????H???????????? ??????_???e??????????0???? ??????? ??????da??????????????????@n????z??????u??in???????????????????????????????????????????????e??*6to4mp?????????????????IS???????????o??.N???????????.??i:??????????????????????????????????????????? p??????2??????????6TO4 Ad
    Reg HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Linkage@Route ????????Net?1?????????????:????????g6.??????????????????????@n??nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp?-??????????x?????????????????????????:????????gz????????????????????????????????????????????????u???e???????????????????????????????????????????k???????????????????????????????????????u??????????????????????????????D???tunnel??????{4d36e972-e325-11ce-bfc1-08002be10318}\0338?????6to4mp.ndi???????????????D??????????????????????????????????????????????ne??Microsoft???? "??????B??????????????????????? ????<?????????????? ?????????????????????#????????????????????? ?????????????????????#?????????????????????????????????????????????????????????????????????????????????????????????????????????????0???t????.??????????????????????6??-1??6to4mp.ndi??????????_T??????????????????????????? ?????????????????????#????????????????????????????*6to4mp???????X??????t???t??*6to4mp??????????????????????????????1?????s11??nettun.inf?p????????????????? ?????????????????????#???????????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Linkage@Export ?????z?????z0????z???z?????z0????z??? ???????????????????z??????????????&????????????????????D??? ???z???6??????d4??????????46?????????????m????? ???????z?????z?????\?D???????????????z9??????z0??z1??z???z???z???z???z2??z3??z4??z5??z6??z7??z8??z9???????????????? ???????z???????????z?D???????????????????????????????m????? ???????z???????????z?D?????????????????d?????z???z?????????????z??????? ???????z?????z?????\?D?????????????????????????????????z??? ???????????????d??? ???????z???????????z?D???????????????????????????????m\m???z??? ???????z???????????z?D?????????????????d?????z???z????????????????????? ???????z?????z?????]?D????????????????????????????????s???? ???????d??????n???? ???????z???????????z?D?????????????????????z???z??????????????????? ???????z???????????z?D?????????????????d?????z???z???????????????m?z???????????4?m13??? ???????z???????????z?D???????????????????s???????z???z?????????????:?mro??? ???????D?????z?????d?D???????????????uiw????N??z?????D????{4851398C-989E-4A5D-A5BC-65B4C58CEE4C}?e???
    Reg HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Linkage@Bind ????????? ???????????????????>???????? "??????????????????????????d??????????????8???6TO4 Adapter?4 Adapter #195??????????????>??????????????? ???????1?????>???????#??L????????? ???????????? ?????????????????????#????????????&???????????????????????????????? ?????????????????????#????????????????????????????? ???????????????????<?#????????????????????????????????????????????????????????????nettun.inf??????? ??????????????????6to4mp.ndi???i??? ???????>??????????????????? ?????????????????????#????????????????????? ???????????????????=?#????????????????????????????????????????????? ???????>?????????????!?????????????????f??? ??????????????????????????????z???????????????????????????????#???Root\*6TO4MP\0182?????z?????????????????\\?\Root#*6TO4MP#0182#{cac88484-7515-4c03-82e6-71a87abac361}????????? ???????#????????????????N?????$???<????????????????????????????????2??? ??????????????????????????????????'?????????????????????????????????$?????????????????Root\*6TO4MP\0182???????????????????????????????? ?????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Linkage@Route ?????@??????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255???????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{110BAA03-7B1B-409F-A527-E0C8EC47B353}] DATAGRAM 178????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255???????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{B409AB16-030E-4FA5-8B12-EA3E2D45B7A1}] SEQPACKET 177???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255??????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Linkage@Export ????????????????? ???????????????????????????????_???????????????????????????????????u??el??{4d36e972-e325-11ce-bfc1-08002be10318}??????? ???????a?????ect??\\?\Root#*6TO4MP#0169#{cac88484-7515-4c03-82e6-71a87abac361}?1????.?????????????nettun.inf?o4m??6to4mp.ndi?? U???????????-??-2??Microsoft????????????d??????????????????????????Net?27????????????????????????????:??????-?g7C????z?????????????tunnel???M????.?????????????????????nettun.inf??????????????Microsoft???????????????????????*6to4mp???????z??????0????????????N?????????????????????un??????????????????? ??????????????????????????????????'????????????????????}???????????????????????????(??????????????*6to4mp???????X??????????t???????????}??????AC????:????????g?????????????????????????-??????????????????????????????s?????????????????????????????????F??????o???????%??????????????? ???????????????????????????????????????u??????????????????????5&3aad6ca&0?Ge???!?!?!?!?!?Y?Y?Y?Y??.I???????????m?????sey??????????????{4d36e96e-e325-11ce-bfc1-08002be10318}?00??
    Reg HKLM\SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage@Bind ???u?u??nettun.inf?w?w???u??????????????? ???????s???????????u?#?????????????????????????%???s?s?%??? ???u???&???????&??6.0.6002.18005?%?%?????u????Microsoft 6to4 Adapter?u?u??? ???????s?????u???????#????????????????????? ???????u???????????u?#???????????????????????u?????????u???&???&??6.0.6002.18005?&?&???s?u?&????:??u???&?g?&??@nettun.inf,%msft%;Microsoft?&?????u???S?????u???????u???'??????????*6to4mp??'??? ???????s?????u???????#????????????????????? ???????u???????????S?#???????????????????????u?????????????'???'???u???????u???'???'??*6to4mp??'??? ???????s?????u???????#????????????????????? ???????u???????????u?#???????????????????????u?????????????'???'???????????'???'???u?u?'??? ???????s?????u???????#????????????&????????????????????'?????u???s????? ???????u?????u???????#???????????????????????u????? ???????u???????????s?#????????z??????????????u?????????????'???'????z??u???'???'??nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp?'???????u???'???e??tunnel?'?'??? .??u???'?????'?(??Microsoft 6
    Reg HKLM\SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage@Route ???=????????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255???????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{93B37369-F264-40ED-ABA8-8E377F31B93A}] SEQPACKET 226???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255???????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{93B37369-F264-40ED-ABA8-8E377F31B93A}] DATAGRAM 226????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{45F78434-AD65-4822-AC3B-E56778F12054}] DATAGRAM 214?e???????=???p????????m5D-??MSA
    Reg HKLM\SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage@Export ??????????4Local Area Connection* 240????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6TO4 Adapter??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\netbt\Linkage@Bind ???w?????u???????????????????????t??Microsoft????u???????????????????u??????? ???????u???8???????????????A?????sBF???????u????????????:??u?????g?????u?u?u???u?u?u????X??u???f???t???????????u?u?u???????u??????????16???u?u?u??nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp?????????u???????????u?u????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter??????????????????????????u??????????6to4mp.ndi??????Microsoft????????????7?????s????*6to4mp??7???????????????e???u?u?????u?u?u??nettun.inf????????.??u??????????tunnel??????? p??u?????????????????????????????s?????????????????????????????????????????u???i??,%???????????????????????u???????????u?u?????????u???????7???u?u?u?u?u?u?u?u?u?u?????u?u????6.0.6002.18005??????????? p??u???D?????57C???u?u?????????????????????u?u4m??Net??????????u???P??????Microsoft 6to4 Adapter?8?8???????????}???}???????????????????????u???????????????u???????????u?u4m???????????7???????u?u?u????:??u???????e??????? ????????????????????????????$?N???????????{4d36e972-e325-11ce
    Reg HKLM\SYSTEM\CurrentControlSet\Services\netbt\Linkage@Route ???r?????r???????r???r???r????2Local Area Connection* 57?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6TO4 Adapter??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\netbt\Linkage@Export ???v?????v??????????????tunnel???????????v???????????????????????S??Ro???v?v?v???v??? ???????v?????q?????????????????????????0??? ???????v???????????m?????????? ???????????????Network Address?? ??? ???????v???????????n?????????? ????????????? ??v???????????????????v???????v???????v???v??????tunnel????????<??v???v??????Microsoft 6to4 Adapter Driver???? ???????v???????????n?????????? "??? ??????848??? ???v???-?????71a??? "??v???9???????v??11???????v???????v???????????v?v?v?v?v?v?v?v?v?v4m??nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp?????????????u???u???????????d??te??{4d36e972-e325-11ce-bfc1-08002be10318}?b9-??? ???v???R??????tu????X??v???u??????tunnel???????????????v??li???????v????????????N??v????????D?*6????N??v???u?????u?8????z??v???y???*???????????n??????*6to4mp??????v?v?v???v??Microsoft????????????????????????????y???y????????????????????X??v???8???????v?vNN??????#0???????????4??3-??????????? ??B ???v?vos???v?v?v??*6to4mp??????v???v?v????????????????? ????:??v???y???????????????Y?????s?y?
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Smb\Linkage@Bind ???p?#????X??j???&???&????t??i???o???????????i???????????????i???8????????$??i???b??36???????j????`??i???e?g?p???????j???????????????????????????????p?u?????~?~?~???? ??j???y???????n?p?e??6.0.6001.18000???y??monitor\default_monitor??????o?o?????i???????????B???????s???????????y???t???????????????????S???j?jto???????j??????????? "??j???0?????005?????????k???l???j?????M?????k???k????? ???????g???????????i?!??????????????????????s "?????j??{4d36e972-e325-11ce-bfc1-08002be10318}??????? ???j???????????????????????u???????????j???????????????????j??????e|??IEEE 1284.4 compatible printer???????????????i???F???j???????j???z??????Local Area Connection* 65????????j???0??0-???????????0??&D???????????i???j??oem40.inf???????????????? ???j???C??????d???int?????? ???????????????????j??????????????&???????????????????????? ???j???j???????j??Network Address??????j??text?8??6.0.6001.18000??fi??????????????????????t????? ??j???L?????d?e??tunnel???j??dot4prt.inf:D4P_Models.NTx86:Dot4Print_Inst:6.0.6001.18000:dot4\print???Dot4Pri
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Smb\Linkage@Route ???r?r????2Local Area Connection* 56?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6TO4 Adapter??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Smb\Linkage@Export ???=?=???????=???B????????mice???????=???p??????B1??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{72B244DF-F701-46E4-AFBD-17E0A397697F}] DATAGRAM 213????? ???????????????????=???????? "??????????????????????=???B????????mice???????=???p??????E1??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{807062DC-483E-4E6B-B380-B909536400BD}] SEQPACKET 212????=?=?=??5}????X??m???=???????<??????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{09E35924-B508-48A0-B6D4-F878D0082E25}] DATAGRAM 217?e??? ???????????????????=???????? "?????????????76???????=???C??????3????<?=?=???????=?????????????<08???????=??????????????????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255???????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{CA6DDABD-EBFA-40B3-8998-5C7E552606ED}] SEQPACKET 228??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30}@LeaseObtainedTime 1322231098
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30}@T1 1322231108
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30}@T2 1322231115
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30}@LeaseTerminatesTime 1322231118
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Linkage@Bind ????????????????????????????????????Microsoft 6to4 Adapter???????????????i???t????.??????f???h????X??????I???????????????b???e???????????????????a???l???????????L??????????????????????????4m??*6to4mp??????????????????????????????}??SE???????????I???e??????????????????tunnel??????????????6.0.6002.18005??k???@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????6.0.6002.18005??24???????????????????????8??18????N??????????????G??? ???????i???????????????????C??????????????????????????????????????????6TO4 Adapter?4 Adapter #283?Mi?????????????????s?????????????????????????????A??P ??????????????????????????Microsoft 6to4 Adapter?B?B???????????0??67??????????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?D4??? ???????????????????u??????????????????????????????????????? ???????B??????xe??tunnel???????????????9??????????????????????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?P6???????????????t??????????????????ll??@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????nettun.inf???2?
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Linkage@Route ???@?????>?>?>?}Ty??? ???@???@??????????????????or???@?@?@?@?@?@?@?@?@?A??????$??A???B??????????????????Net??????@??? ???????????????? ????!?? "?????p?????????????N??@????????D?????{4d36e972-e325-11ce-bfc1-08002be10318}???@???????@???u??sl??Net??@???A???A??????????????? ???????A???????????A??????????????'????????????????????}????$??A??????????????Root\*6TO4MP\0210????????A??????????????\\?\Root#*6TO4MP#0210#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{45F78434-AD65-4822-AC3B-E56778F12054}??2??? ???????????????????@??????????????&???????????????????????? ???@??????????????????????????????levice\NetBT_Tcpip6_{91BF7711-1F9E-4D5F-BAB4-989016203258}] SEQPACKET 255???????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{2D4319DA-12D2-4D27-BAA4-68F4423BCB40}] SEQPACKET 132??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Linkage@Export ?????4???????|???????????????????????e??????????????????????????????????? ???????????????????9????????????I?&????????????????????????????????i??s?????????????????????4Local Area Connection* 153????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6TO4 Adapter??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{AFCD3C5A-CA3D-46BB-935D-659AAFDC2546}\Linkage@Bind ???S?W???R???l?l?R??Root\*6TO4MP\0192????R??Root\*6TO4MP\0194????R???l?m?e???R??Local Area Connection* 67????????R??????????????????>????D??????7C??? ???????O?????8?????8??????????<??????i????? ???????R?????8????????????????????????????11?R????? ???????R???????????8?????????? ???????????????Type?????? ??R????????c?????Network Address??????? ??R??????????text?R??? ???????R???????????8?????????? ???????_T???? ??R???D????c57C???R???????????5???t???????R???R?? 5???R??? ???????D?????R??????????V?????????&????????????????????R??? ???????R??????????????????????????+??????????????????????0C2?????R????? ???R???A?????&00??{0939CE50-2A00-432E-83AE-0183176E9299}-{208D67BB-EF7E-4183-8341-580548FB2E4D}-0000???????R?R?R?R?????????????????????????O?;?O?)?O?R?R?R?R?R????? ???????O?????????????!????????????????????? ???????#?????R?????R??????????$?8?<???????????????????????????????????? ???????R???????????R??????????z??????????????R#?????$??R??????????????Root\*6TO4MP\0055?????z??R?????????????????R??????$??R???????????R??Roo
    Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{AFCD3C5A-CA3D-46BB-935D-659AAFDC2546}\Linkage@Route ???W?????????E???m?m?l?m?????W???????W??????????????Microsoft???\\?\Root#*6TO4MP#0283#{cac88484-7515-4c03-82e6-71a87abac361}??????$??W???f???????8??Root\*6TO4MP\0285?????z??W???3????????????6?????????,-??*6to4mp??W???????W??????????????????t???? ???W???W??????????6-21-2006???\\?\Root#*6TO4MP#0284#{cac88484-7515-4c03-82e6-71a87abac361}?F??\\?\Root#*6TO4MP#0285#{cac88484-7515-4c03-82e6-71a87abac361}????Root\*6TO4MP\0286????W??????????????????? ???W??????????n???6.0.6002.18005?ft ????$??W???C???????C????z??W???C???????C??\\?\Root#*6TO4MP#0286#{cac88484-7515-4c03-82e6-71a87abac361}?C????$??W????????????????z??W???????????????W???W???W???????W???r??sr??DiskDrive?????f??W???o?gte??@disk.inf,%genmanufacturer%;(Standard disk drives)?S\m???P?P?P?P?W?W?W?W?W???????W??????????????gendisk??????!?W?W?W?W?W?W?W?W??Root\*6TO4MP\0287???\\?\Root#*6TO4MP#0287#{cac88484-7515-4c03-82e6-71a87abac361}?d????$??W???G???????H??Root\*6TO4MP\0288?????z??W???H???????H??Root\*6TO4MP\0289????W???W???W?????(???(???)???(???(???(???(???(???
    Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{AFCD3C5A-CA3D-46BB-935D-659AAFDC2546}\Linkage@Export ???W?W??????????@usbstor.inf,%genericbulkonly.devicedesc%;USB Mass Storage Device???? ???W???Y??????????*PNP09FF????? ???????U?????V???????#??L????????? ??????????????U???U???W???????????3????????????? ???????$?????X???????#??L????????? ??????????????$???$???W????????? ???????W?????X???????#????????????&????????????????????r???g?g?g????? "??? "???W??????????$??W???????????????W???W???W??? ??????? "?????X???????#??L????????? ???????????? ???????W?????X???????#????????????&??????????????????????????$???$???X??????????z??W???????????????W??????????????????????????????????6????????????????????????????????????????????????????????????????????????????????????????????????W??? ???????W?????X???????#????????????&???????????????????????\\?\Root#*6TO4MP#0289#{cac88484-7515-4c03-82e6-71a87abac361}????Root\*6TO4MP\0290?????z??W??????????????\\?\Root#*6TO4MP#0290#{cac88484-7515-4c03-82e6-71a87abac361}?D????$??W???????????s???W??*6to4mp??W??? ?????????????????????#??L????????? ??????????????????W????? ???????a?????W???????#???
    Reg HKLM\SYSTEM\ControlSet003\Services\LanmanServer\Linkage@Bind ?????????????????????e??? ??????????????????????????? ?????????????????????#?????????????????????????????n??nf??????????{4d36e972-e325-11ce-bfc1-08002be10318}?2????????????? ?????????????????????#????????????????????? ?????????????????????#????????????????????????????? ???????&???????????????????d??????????tunnel????????????????????????z?????????????nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp?????????????????e??? .?????????????????????????????????????? ??????????????????? "?????????????????*6to4mp?????Microsoft 6to4 Adapter Driver???? ?????????????????????????????? "??? ?????? DA??? ???????-?????FD ??? "??????e?????Net??ndis5_ip6_tunnel?-??? ???????????????????????????E?????dT ??? ???????????????????y?!??????????????????????sB4-??? ???????y?????????????#????????????????????6to4mp.ndi??????????????????????????????????? ?????????????????????#????????????????????????????????????????????????Mi??????t?????<?????????????????????????????ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All piec
    Reg HKLM\SYSTEM\ControlSet003\Services\LanmanServer\Linkage@Route ????????Intel(R) PRO Adapter Driver??Y??p???Microsoft 6to4 Adapter???????????? ?????????p????????????%???????????%??????\\?\Root#*6TO4MP#0100#{cac88484-7515-4c03-82e6-71a87abac361}?6??? ???????#????????????????N?????$?e?<???????????????????????????????9B??? ??????????????????????????????????'????????????????????}????*??????4????????????$??????B???????e??Root\*6TO4MP\0100????????????0??????8B??\\?\Root#*6TO4MP#0100#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{B13C6A69-C310-4107-8324-0B214FA2D8FD}?D7??? ???????????????????o??????????????&??????????????????????????????????????????????????????e????srv2????????????????@nettun.inf,%msft%;Microsoft?????????????Y???????Y??System32\drivers\ecache.sys???????P??????????????????2???????????e??e???????????????????????tunnel?391??ReadyBoost Caching Driver???Mup?????PNP_TDI??+???????????????t????<??????Y?????Y?Y???????????0???????????d???????????h??????????????????????????t????????????????????????h???????????t???e??? ??????????????????????????????????&??????????????????????????
    Reg HKLM\SYSTEM\ControlSet003\Services\LanmanServer\Linkage@Export ?????????????????????????????????????????????????????????????????????????????????????n??????Network?????????????????????????????????????????????tcpip???????netlogon?lsarpc?samr?browser??Wks?TrkSvr?????????????????????????????C???????t??? ???????R????????????B????????????e?????????????????????????e??????????????p???????????????????????????Network???????????????<??????o???????????????????n???????????????????????????????t??to??%SystemRoot%\system32\srvsvc.dll????????????????p???Network?????????????????????????mrxsmb??????????????????????????????? ?????????????????????#????????z?????????????z?????????????tunnel????????????????????N?????????????????????? ???????????????????????????8??? ????????????????????????????????k?&????????????????????m????????X?????????????nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp????????????28??????? [??????????????? ????!?? "?????p????????????y?y?y?y?y?y?y?y?y?y?y?y?????y??????????system32\drivers\iastor.sys??????????????????????????????=???\??????? ??????????????d??????
    Reg HKLM\SYSTEM\ControlSet003\Services\LanmanWorkstation\Linkage@Bind ??????????(????????????e??????L????????????e????Keyboard HID Driver?????????????????p???System32\Drivers\ksecdd.sys?????????????????t????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????n??????Network?????????????????????????????????????????????tcpip???????netlogon?lsarpc?samr?browser??Wks?TrkSvr?????????????????????????????C???????t??? ???????R????????????B????????????e?????????????????????????e??????????????p???????????????????????????Network???????????????<??????o???????????????????n???????????????????????????????t??to??%SystemRoot%\system32\srvsvc.dll????????????????p???Network?????????????????????????mrxsmb??????????????????????????????? ?????????????????????#????????z?????????????z?????????????tunnel????????????????????N?????????????????????? ???????????????????????????8??? ????????????????????????????????k?&????????????????????m????????X?????????????nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp????????????28??????? [????
    Reg HKLM\SYSTEM\ControlSet003\Services\LanmanWorkstation\Linkage@Route ????????????????????t?????:???????????h?????system32\DRIVERS\msiscsi.sys?msiscsi.sys????????????????????????????????????t????????????????????????????????????????(??? ????????????????????? "??????*?6??? ????????L??????? ???????y?????????????#????????????????????????????????????????Local Area Connection* 252??????? ??????????????????????????????????&???????????????????????? ??????????????????????????????????&???????????????????????????????????p???Tcpip???????iScsiPort Driver????system32\DRIVERS\kbdclass.sys?bdclass.sys????????????????????????????????????????????????????????????????$?g?$????\????????????n????Keyboard Class????????<???????????h?????????????????t???Keyboard Port??????????????????????????????????????????????(????? ??????? ?????Ada???????????B??? ??????????????????????????????????&????????????????????3??? ??????????????????????????????????? ??????????????????????????????????&????????????????????7????F????????????e????UAC File Virtualization???????????????N??????????????????????????????????B?????????
    Reg HKLM\SYSTEM\ControlSet003\Services\LanmanWorkstation\Linkage@Export ?????????????????????????????????????(??? ????????????????????? "??????*?6??? ????????L??????? ???????y?????????????#????????????????????????????????????????Local Area Connection* 252??????? ??????????????????????????????????&???????????????????????? ??????????????????????????????????&???????????????????????????????????p???Tcpip???????iScsiPort Driver????system32\DRIVERS\kbdclass.sys?bdclass.sys????????????????????????????????????????????????????????????????$?g?$????\????????????n????Keyboard Class????????<???????????h?????????????????t???Keyboard Port??????????????????????????????????????????????(????? ??????? ?????Ada???????????B??? ??????????????????????????????????&????????????????????3??? ??????????????????????????????????? ??????????????????????????????????&????????????????????7????F????????????e????UAC File Virtualization???????????????N??????????????????????????????????B?????????????????????????????y???y??????????????-102??????? ??? ??????????????????????????????????&????????????????????@?????????????
    Reg HKLM\SYSTEM\ControlSet003\Services\NetBIOS\Linkage@Bind ?????????? ????????????e????????????????t???????W??????g?????????????????????????????????????e?????????????????????????g????????????????t???????????????????????t???Microsoft NCSI????????$????????????e?????????????????????? "?????????????????????dns.msftncsi.com????system32\drivers\nsiproxy.sys???????????????? "??????????????????23??? ?? ???????????????NSI proxy service????? "?????????????????????NSI proxy service???????????????????????????????t????????????????????????????????????????????t??in???????????e??t????????????a?gdl?????????????????????&??????????????????????????????????<???????????h??????????????y??tn?????????????????e????????????System32\DRIVERS\netbt.sys??????????????????????????????????p???????????????????????????????t????????????R????????m???????Z????????????n????www.msftncsi.com????????????????6-21-2006???? ?????????????????????#????????????????????? ?????????????????????#????????????????????????????????????????????????????????????? ??????????????????6.0.6002.18005????????????????????????.????????
    Reg HKLM\SYSTEM\ControlSet003\Services\NetBIOS\Linkage@Route ????????This service implements NetBios over TCP/IP.????????????????????????????????????????t??????????????g????PNP_TDI?????????????? ???????C???????????C?????????? ???????????? ???????C???????????C?????????? "??? ???????????? ???????D????????????????V?????????&????????????????????(??? ??????????????????????????????????+??????????????????????0????nettun.inf???t??nettun.inf??????????? ???????D????????????????V?????????&????????????????????A??? ??????????????????????????????????+??????????????????????0????? ???????????????????????????????????l??????????????????????????Net?????????????????????????????????????*6to4mp?????? ?????????????????????#????????????????????? ?????????????????????#????????????????????????????????????????????????????????????? ?????????????????????#????????????&????????????????????.???????????*??o4????z?????????????@nettun.inf,%msft%;Microsoft??????z??????4??????????????????????nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.0.6002.18005:*6to4mp?????????????????e??????? ??g??????????????????????????
    Reg HKLM\SYSTEM\ControlSet003\Services\NetBIOS\Linkage@Export ??????????$????????????n????????????????t????????????R????????m?? ??????????????????FileSystem??????????????????????????????????????????This service implements NetBios over TCP/IP.????????????????????????????????????????t??????????????g????PNP_TDI?????????????? ???????C???????????C?????????? ???????????? ???????C???????????C?????????? "??? ???????????? ???????D????????????????V?????????&????????????????????(??? ??????????????????????????????????+??????????????????????0????nettun.inf???t??nettun.inf??????????? ???????D????????????????V?????????&????????????????????A??? ??????????????????????????????????+??????????????????????0????? ???????????????????????????????????l??????????????????????????Net?????????????????????????????????????*6to4mp?????? ?????????????????????#????????????????????? ?????????????????????#????????????????????????????????????????????????????????????? ?????????????????????#????????????&????????????????????.???????????*??o4????z?????????????@nettun.inf,%msft%;Microsoft??????z??????4?????????
    Reg HKLM\SYSTEM\ControlSet003\Services\netbt\Linkage@Bind ????p???SMB MiniRedirector Wrapper and Engine???Implements the SMB 1.x (CIFS) protocol. This protocol provides connectivity to network resources on pre-Windows Vista servers???SMB 2.0 MiniRedirector?????????????????????n????system32\DRIVERS\mrxsmb20.sys????????????2??E9????<???????????h?????????????????p???????????????t???????????????? ????????????????????????????$?N?????????????????????????????????????????????????N?????????????????{5E2152B8-B866-44AA-A893-00F9BABB6114}????????????????????????????????????????????????N??????d???????????????????????????s??????????????t???????????????????Network?????? "?????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0303??????????????e??????????????????????Driver responsible with maintaining persistent drive letters and names for volumes?Tok??????Net?????ndis5_ip6_tunnel????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0113?? ??{159FEE2E-DEB6-48F4-B8E2-4CB46CC70DF7}??????????????????? ??????????????????????????????????&????????????????????4??{EEFF21C7-4D15-
    Reg HKLM\SYSTEM\ControlSet003\Services\netbt\Linkage@Route ????????????????????????system32\drivers\msisadrv.sys?????<???????????h???????????????????????2???????????h???????????????,????????????e????system32\DRIVERS\mssmbios.sys?ssmbios.sys?????????????????????????,????????????n????????????????e???????????????p???????????????????????????????????????????????????????????????????????????????? ????????????????????? "??????????!?&???????????????????????? ????????????????????? "??????*?6??? ????????????????????r??????????dl??????????? ??????????????????????????????????&???????????????????????????????? ???????s??? ???????u????????????z??????s??????????Root\*6TO4MP\0240???????????????????????? ???????.??????d?????N??????H???????????????????B???????????????????????B??????Us???????????i??????????????? ?????????????????????!??????????????????????????????????????????????????X?????????????Net?????????????? ???????S?????????????????????????????????????g????????????????? ???????D????????????????V?????????&???????????????????????@%SystemRoot%\system32\FirewallAPI.dll,-23092???WebDav
    Reg HKLM\SYSTEM\ControlSet003\Services\netbt\Linkage@Export ?????????????????M??tP???????????????R???????????????????????????????????????B??? ???????????????:??????q???????????????Local Area Connection* 113??? ??????????????????????????l????n??????????? ??????????????????????????????<??????i????? ??????????????????????????????????????????? ?????????????????????????????? ????????????????? ???????????c??????? ??????f?????????????????g?????????????????????????n?????nvi???????????G??????????????????????????????? ??????????????????????????????z?????#??+??????????????????????t?????????????$?????????????????{4d36e972-e325-11ce-bfc1-08002be10318}??????????????? ???????B?????????????!????????????????????????????????????????????????NDIS Wrapper??????????????????????3?????????????????????????????????????NDIS Proxy??????????????????????????File system???????4?????????????????system32\drivers\ndis.sys???????????????t???????????????p???????????????t???????????????t???????????System32\Drivers\mup.sys??????????????????????&????????????e????NDIS System Driver?????????????????????????
    Reg HKLM\SYSTEM\ControlSet003\Services\Smb\Linkage@Bind ????????? "??????????????????? ?????????????????????!?????????????????f??\Device\{EEFF21C7-4D15-402F-854E-5E74D582727D}??#???????#???? ??????????????????????????????????&???????????????????????????? ???????}??????dC??????????????????????? ??????????????????TCPIP6TUNNEL?Tcpip6?????????????Implements the framework for the SMB filesystem redirector??????????????????p???system32\DRIVERS\mrxsmb10.sys???????p???SMB MiniRedirector Wrapper and Engine???Implements the SMB 1.x (CIFS) protocol. This protocol provides connectivity to network resources on pre-Windows Vista servers???SMB 2.0 MiniRedirector?????????????????????n????system32\DRIVERS\mrxsmb20.sys????????????2??E9????<???????????h?????????????????p???????????????t???????????????? ????????????????????????????$?N?????????????????????????????????????????????????N?????????????????{5E2152B8-B866-44AA-A893-00F9BABB6114}????????????????????????????????????????????????N??????d???????????????????????????s??????????????t???????????????????Network?????? "????????????????
    Reg HKLM\SYSTEM\ControlSet003\Services\Smb\Linkage@Route
     

  3. to hide this advert.

  4. 2011/11/25
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    end of gmer and more logs:

    ????er??????????????t?????V????????????e????????????@%SystemRoot%\System32\drivers\pacer.sys,-101??????????????????e?????????????F??e4????????????8???????????h?????system32\DRIVERS\rasl2tp.sys???????????????????????????????????????????????g??????4?????? ??p ????J????????????e?????????????????????????????????p??????90??6.0.6002.18005??????Microsoft 6to4 Adapter??????????????????????????????*6to4mp??????????????????????????B????6?????????????? ?????????????????????#????????????????????? ?????????????????????#????????????????????6.0.6002.18005????????:????????g?{????X?????????????????????????????????????? ??????????????????????????????????&???????????????????????????95???????????i??????*6to4mp?????????text?????????????????h??e???????????? ?????????????????????#????????????????????? ?????????????????????#????????????????????6.0.6002.18005??????Microsoft 6to4 Adapter??????????????????????????????????????????t???Remote Access Auto Connection Driver??????:???????????h?????system32\DRIVERS\rdbss.sys?????????????????
    Reg HKLM\SYSTEM\ControlSet003\Services\Smb\Linkage@Export ????????????????????NDIS?b??????????????????????????????????\s????6??????????t??text?)???????????B??????????????????????????????????????????????????????????????78????8???????????h?????????????????udfs????????????t????B?B?B?B?B?B?C?C?C??????? ?????? ??????????????#????????????????????????????????z???????????????#?????N??????d??????????????????????t????????????T???????????n??Base????File Information FS MiniFilter??????????????tunnel??????? ???????y?????????????#????????????????????*6to4mp???????N????????????e?????????????????h??????????????????????????????????RDPCDD????????6??????????m??????????????????t???? ??????? ??????B???system32\drivers\fltmgr.sys?????????????????????????1???? ?????????????????????#????????????????????? ???????4??????nA??6.0.6002.18005?AGR??Microsoft 6to4 Adapter??????????????? ?????? ??????????????#????????????????????6.0.6002.18005?2e6????:??????6?g?4???????????????B??????????t?????0?????????p???Base????11??t????????????%???????C??????????0C???????????W??????system32\drivers\fileinfo.s
    Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip6\Linkage@Bind ??????????????N??????d???????????????????????????s??????????????t???????????????????Network?????? "?????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0303??????????????e??????????????????????Driver responsible with maintaining persistent drive letters and names for volumes?Tok??????Net?????ndis5_ip6_tunnel????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0113?? ??{159FEE2E-DEB6-48F4-B8E2-4CB46CC70DF7}??????????????????? ??????????????????????????????????&????????????????????4??{EEFF21C7-4D15-402F-854E-5E74D582727D}-{208D67BB-EF7E-4183-8341-580548FB2E4D}-0000????????$??????w??????????\\?\Root#*6TO4MP#0240#{cac88484-7515-4c03-82e6-71a87abac361}????????????????????????????????????? [??????#??????????????????????$???<???????????????????????????????5???????????????????{EEFF21C7-4D15-402F-854E-5E74D582727D}???f??? [??????#????????????????N?????$???<?????????????????????????????????????$?????????????????????Root\*6TO4MP\0101?????????????????????????6??????????e??@%SystemRoot%\system32\FirewallAPI.
    Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip6\Linkage@Route ????????????????????p????? ????????????e????????????????????????@%SystemRoot%\system32\tcpipcfg.dll,-50003????????????????4???????????h???????8???????????h??????????????????????????????????????e??????????????????2.??System32\drivers\tcpip.sys??????????????????????????????? ?????????????????????#????????????????????????????{43F7C1A5-2792-41C8-BDEC-68A88A3E1B1B}-{208D67BB-EF7E-4183-8341-580548FB2E4D}-0000?? 2??????int??{??? ?????????????????????#??????????????????????????????????????????????????????06A}????X?????? ?????????????????????#????????.???????????? p??????D?????576??@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter????????????????????????????????????????s?????????????????B????????????????????????4Local Area Connection* 243????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6TO4 Adapter??????????????????????????????????
    Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip6\Linkage@Export ?????????????????????????????????e??????????????????2.??System32\drivers\tcpip.sys??????????????????????????????? ?????????????????????#????????????????????????????{43F7C1A5-2792-41C8-BDEC-68A88A3E1B1B}-{208D67BB-EF7E-4183-8341-580548FB2E4D}-0000?? 2??????int??{??? ?????????????????????#??????????????????????????????????????????????????????06A}????X?????? ?????????????????????#????????.???????????? p??????D?????576??@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter????????????????????????????????????????s?????????????????B????????????????????????4Local Area Connection* 243????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6TO4 Adapter??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

    ---- EOF - GMER 1.0.15 ----

    *******************
    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-11-25 09:15:00
    -----------------------------
    09:15:00.804 OS Version: Windows 6.0.6002 Service Pack 2
    09:15:00.804 Number of processors: 2 586 0xF0D
    09:15:00.804 ComputerName: ME-PC UserName: me
    09:15:01.569 Initialize success
    09:15:12.723 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    09:15:12.723 Disk 0 Vendor: SAMSUNG_ JF10 Size: 152627MB BusType: 3
    09:15:12.738 Disk 0 MBR read successfully
    09:15:12.738 Disk 0 MBR scan
    09:15:12.754 Disk 0 unknown MBR code
    09:15:12.769 Disk 0 scanning sectors +312576705
    09:15:12.832 Disk 0 scanning C:\Windows\system32\drivers
    09:15:17.996 Service scanning
    09:15:20.772 Modules scanning
    09:15:22.660 Disk 0 trace - called modules:
    09:15:22.676 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
    09:15:22.691 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x868d4ac8]
    09:15:22.691 3 CLASSPNP.SYS[895a48b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85e44030]
    09:15:22.691 Scan finished successfully
    09:15:49.726 Disk 0 MBR has been saved successfully to "C:\Users\me\Desktop\MBR.dat "
    09:15:49.742 The log file has been saved successfully to "C:\Users\me\Desktop\aswMBR.txt "
    *********************
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft® Windows Vistaâ„¢ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 2/23/2011 11:39:30 AM
    System Uptime: 11/25/2011 9:12:09 AM (0 hours ago)
    .
    Motherboard: ASUSTek Computer INC. | | LOCKTITE
    Processor: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz | Socket 775 | 2200/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 141 GiB total, 91.302 GiB free.
    D: is FIXED (NTFS) - 8 GiB total, 1.108 GiB free.
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    .
    ==== Installed Programs ======================
    .
    32 Bit HP CIO Components Installer
    6300
    6300_Help
    6300Trb
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader X (10.1.1)
    AIO_CDB_ProductContext
    AIO_CDB_Software
    AIO_Scan
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    AVG 2012
    Bing Maps 3D
    Bonjour
    BufferChm
    CCleaner
    COMODO Internet Security
    Copy
    CustomerResearchQFolder
    Destinations
    DeviceManagementQFolder
    DocProc
    DocProcQFolder
    ESET Online Scanner v3
    eSupportQFolder
    Fax
    Google Earth Plug-in
    Google Update Helper
    Hardware Diagnostic Tools
    Hewlett-Packard Active Check
    Hewlett-Packard Asset Agent for Health Check
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Active Support Library 32 bit components
    HP Advisor
    HP Customer Experience Enhancements
    HP Customer Feedback
    HP Customer Participation Program 8.0
    HP Easy Setup - Frontend
    HP Imaging Device Functions 8.0
    HP OCR Software 8.0
    HP On-Screen Cap/Num/Scroll Lock Indicator
    HP Photosmart Essential
    HP Photosmart Essential 2.01
    HP Photosmart Essential2.01
    HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
    HP Product Assistant
    HP Solution Center 8.0
    HP Update
    HPProductAssistant
    HPSSupply
    Intel(R) Matrix Storage Manager
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 29
    Java(TM) 7 Update 1
    Java(TM) SE Development Kit 7 Update 1
    LightScribe 1.8.15.1
    Malwarebytes' Anti-Malware version 1.51.2.1300
    MarketResearch
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Silverlight
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    Mozilla Firefox 8.0 (x86 en-US)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee autoProducer 6.0
    My HP Games
    NVIDIA Drivers
    OpenOffice.org 3.3
    PSSWCORE
    Python 2.5
    QuickTime
    Realtek High Definition Audio Driver
    Rhapsody
    Rhapsody Player Engine
    Roxio Creator Audio
    Roxio Creator Basic v9
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator EasyArchive
    Roxio Creator Tools
    Roxio Express Labeler 3
    Scan
    Secunia PSI (2.0.0.3001)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Snapfish Picture Mover
    SolutionCenter
    Spybot - Search & Destroy
    SpywareBlaster 4.4
    Status
    Toolbox
    TrayApp
    Unity Web Player
    UnloadSupport
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    VideoToolkit01
    WeatherBug Gadget
    WebReg
    Windows Media Player Firefox Plugin
    WinMerge 2.12.4
    WinRAR archiver
    .
    ==== Event Viewer Messages From Past Week ========
    .
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx86 Avgmfx86 Avgtdix cmdGuard cmdHlp DfsC inspect NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr SYMTDI tdx Wanarpv6
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:13:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    11/25/2011 9:13:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    11/25/2011 9:13:10 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments " " in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
    11/25/2011 9:13:10 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments " " in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    11/25/2011 9:13:10 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments " " in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
    11/25/2011 9:13:08 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    11/25/2011 9:12:59 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments " " in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    11/25/2011 9:12:54 AM, Error: EventLog [6008] - The previous system shutdown at 9:11:07 AM on 11/25/2011 was unexpected.
    11/25/2011 9:03:17 AM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001E8C052AE0. The following error occurred: The semaphore timeout period has expired.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
    11/25/2011 9:02:14 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.100.2 for the Network Card with network address 001E8C052AE0 has been denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).
    11/25/2011 9:01:04 AM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    11/25/2011 9:01:04 AM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
    11/25/2011 9:00:41 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SYMTDI
    11/25/2011 9:00:41 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    11/25/2011 8:23:52 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx86 Avgmfx86 cmdGuard spldr SYMTDI Wanarpv6
    11/25/2011 8:22:27 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 98.168.137.12 for the Network Card with network address 001E8C052AE0 has been denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).
    11/25/2011 8:22:26 AM, Error: EventLog [6008] - The previous system shutdown at 8:20:37 AM on 11/25/2011 was unexpected.
    11/22/2011 6:54:32 AM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001E8C052AE0. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
    .
    ==== End Of File ===========================
     
  5. 2011/11/25
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    final log:
    .
    DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.1.0
    Run by me at 9:16:06 on 2011-11-25
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1577 [GMT -6:00]
    .
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
    FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\Explorer.EXE
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Bar = Preserve
    uStart Page = hxxp://www.yahoo.com/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe "
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
    mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe "
    mRun: [<NO NAME>]
    mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe "
    mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
    mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe "
    mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    StartupFolder: c:\users\me\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    TCP: Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30} : NameServer = 156.154.70.25,156.154.71.25
    TCP: Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30} : DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
    AppInit_DLLs: c:\windows\system32\guard32.dll
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\me\appdata\roaming\mozilla\firefox\profiles\06fjlzgm.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - prefs.js: network.proxy.ftp - 98.168.160.150
    FF - prefs.js: network.proxy.ftp_port - 443
    FF - prefs.js: network.proxy.socks - 98.168.160.150
    FF - prefs.js: network.proxy.socks_port - 443
    FF - prefs.js: network.proxy.ssl - 98.168.160.150
    FF - prefs.js: network.proxy.ssl_port - 443
    FF - prefs.js: network.proxy.type - 4
    FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
    FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
    FF - plugin: c:\users\me\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
    S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
    S1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
    S1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
    S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-1-6 488208]
    S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-1-6 38616]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
    S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
    S2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-2-23 21504]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-28 136176]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-2-23 1153368]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-1-10 993848]
    S2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-1-10 399416]
    S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134736]
    S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
    S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-28 136176]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2011-11-23 22:04:28 -------- d-----w- c:\users\me\appdata\roaming\AVG
    2011-11-09 14:06:58 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2011-11-09 14:06:57 707584 ----a-w- c:\program files\common files\system\wab32.dll
    2011-11-09 14:06:57 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
    2011-10-26 21:42:38 33984 ----a-w- c:\windows\system32\cmdcsr.dll
    .
    ==================== Find3M ====================
    .
    2011-10-26 22:34:44 544656 ----a-w- c:\windows\system32\deployJava1.dll
    2011-10-24 19:29:02 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-10-24 19:29:02 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2011-10-07 17:47:43 38616 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
    2011-10-07 17:47:42 488208 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
    2011-10-07 17:47:41 19600 ----a-w- c:\windows\system32\drivers\cmderd.sys
    2011-10-07 17:47:10 300200 ----a-w- c:\windows\system32\guard32.dll
    2011-10-07 11:23:48 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2011-10-04 11:21:16 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
    2011-09-29 19:58:25 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-09-13 11:30:10 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    2011-09-06 13:30:12 2043392 ----a-w- c:\windows\system32\win32k.sys
    2011-09-01 02:35:59 1798144 ----a-w- c:\windows\system32\jscript9.dll
    2011-09-01 02:28:15 1126912 ----a-w- c:\windows\system32\wininet.dll
    2011-09-01 02:22:54 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-08-31 22:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-31 04:05:04 83816 ----a-w- c:\windows\system32\dns-sd.exe
    2011-08-31 04:05:04 73064 ----a-w- c:\windows\system32\dnssd.dll
    2011-08-31 04:05:04 50536 ----a-w- c:\windows\system32\jdns_sd.dll
    2011-08-31 04:05:04 178536 ----a-w- c:\windows\system32\dnssdX.dll
    .
    ============= FINISH: 9:17:15.04 ===============
     
  6. 2011/11/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ==========================================================

    Any more info?

    Any particular reason why MBAM and DDS were run from safe mode?
     
  7. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    broni, thanks for the help. The GMER and the aswMBR both caused windows to shut down, I would get a blue screen I think about a fatal error, when I would restart in safe mode I would get a message about windows has recovered? I can try to repeat and get exact message if I need to.
     
  8. 2011/11/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's fine but can you run MBAM and DDS in normal mode?
     
  9. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    Yes, here are the logs:
    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8248

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 9.0.8112.16421

    11/26/2011 11:45:41 AM
    mbam-log-2011-11-26 (11-45-41).txt

    Scan type: Quick scan
    Objects scanned: 162503
    Time elapsed: 3 minute(s), 9 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    ***************
    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.1.0
    Run by me at 11:36:45 on 2011-11-26
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1021 [GMT -6:00]
    .
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
    FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Secunia\PSI\PSIA.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\AVG\AVG2012\avgnsx.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\AVG\AVG2012\avgemcx.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\Windows\RtHDVCpl.exe
    C:\Windows\system32\schtasks.exe
    C:\Program Files\AVG\AVG2012\avgtray.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Secunia\PSI\psi_tray.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\system32\jusched.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.bin
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\Program Files\Secunia\PSI\sua.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Bar = Preserve
    uStart Page = hxxp://www.yahoo.com/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe "
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
    mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe "
    mRun: [<NO NAME>]
    mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe "
    mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
    mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe "
    mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    StartupFolder: c:\users\me\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    TCP: Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30} : NameServer = 156.154.70.25,156.154.71.25
    TCP: Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30} : DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
    AppInit_DLLs: c:\windows\system32\guard32.dll
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\me\appdata\roaming\mozilla\firefox\profiles\06fjlzgm.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - prefs.js: network.proxy.ftp - 98.168.160.150
    FF - prefs.js: network.proxy.ftp_port - 443
    FF - prefs.js: network.proxy.socks - 98.168.160.150
    FF - prefs.js: network.proxy.socks_port - 443
    FF - prefs.js: network.proxy.ssl - 98.168.160.150
    FF - prefs.js: network.proxy.ssl_port - 443
    FF - prefs.js: network.proxy.type - 4
    FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
    FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
    FF - plugin: c:\users\me\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
    R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-1-6 488208]
    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-1-6 38616]
    R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
    R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-2-23 21504]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-2-23 1153368]
    R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-1-10 993848]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-1-10 399416]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134736]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
    R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-28 136176]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-28 136176]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2011-11-23 22:04:28 -------- d-----w- c:\users\me\appdata\roaming\AVG
    2011-11-09 14:06:58 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2011-11-09 14:06:57 707584 ----a-w- c:\program files\common files\system\wab32.dll
    2011-11-09 14:06:57 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
    .
    ==================== Find3M ====================
    .
    2011-10-26 22:34:44 544656 ----a-w- c:\windows\system32\deployJava1.dll
    2011-10-24 19:29:02 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-10-24 19:29:02 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2011-10-07 17:47:43 38616 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
    2011-10-07 17:47:42 488208 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
    2011-10-07 17:47:41 19600 ----a-w- c:\windows\system32\drivers\cmderd.sys
    2011-10-07 17:47:11 33984 ----a-w- c:\windows\system32\cmdcsr.dll
    2011-10-07 17:47:10 300200 ----a-w- c:\windows\system32\guard32.dll
    2011-10-07 11:23:48 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2011-10-04 11:21:16 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
    2011-09-29 19:58:25 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-09-13 11:30:10 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    2011-09-06 13:30:12 2043392 ----a-w- c:\windows\system32\win32k.sys
    2011-09-01 02:35:59 1798144 ----a-w- c:\windows\system32\jscript9.dll
    2011-09-01 02:28:15 1126912 ----a-w- c:\windows\system32\wininet.dll
    2011-09-01 02:22:54 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-08-31 22:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-31 04:05:04 83816 ----a-w- c:\windows\system32\dns-sd.exe
    2011-08-31 04:05:04 73064 ----a-w- c:\windows\system32\dnssd.dll
    2011-08-31 04:05:04 50536 ----a-w- c:\windows\system32\jdns_sd.dll
    2011-08-31 04:05:04 178536 ----a-w- c:\windows\system32\dnssdX.dll
    .
    ============= FINISH: 11:37:54.07 ===============
    ******
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft® Windows Vistaâ„¢ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 2/23/2011 11:39:30 AM
    System Uptime: 11/26/2011 9:30:37 AM (2 hours ago)
    .
    Motherboard: ASUSTek Computer INC. | | LOCKTITE
    Processor: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz | Socket 775 | 2200/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 141 GiB total, 89.608 GiB free.
    D: is FIXED (NTFS) - 8 GiB total, 1.108 GiB free.
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP337: 11/16/2011 7:48:55 AM - Scheduled Checkpoint
    RP338: 11/16/2011 10:47:59 AM - Installed iTunes
    RP339: 11/17/2011 3:03:31 PM - Scheduled Checkpoint
    RP340: 11/18/2011 11:32:54 AM - Scheduled Checkpoint
    RP341: 11/19/2011 12:48:40 PM - Scheduled Checkpoint
    RP342: 11/20/2011 10:04:22 AM - Scheduled Checkpoint
    RP343: 11/21/2011 7:41:26 AM - Scheduled Checkpoint
    RP344: 11/22/2011 8:13:18 AM - Scheduled Checkpoint
    RP345: 11/23/2011 11:51:48 AM - Scheduled Checkpoint
    RP346: 11/24/2011 9:06:55 AM - Scheduled Checkpoint
    RP347: 11/25/2011 1:24:47 PM - Scheduled Checkpoint
    RP348: 11/26/2011 11:09:15 AM - Scheduled Checkpoint
    .
    ==== Installed Programs ======================
    .
    32 Bit HP CIO Components Installer
    6300
    6300_Help
    6300Trb
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader X (10.1.1)
    AIO_CDB_ProductContext
    AIO_CDB_Software
    AIO_Scan
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    AVG 2012
    Bing Maps 3D
    Bonjour
    BufferChm
    CCleaner
    COMODO Internet Security
    Copy
    CustomerResearchQFolder
    Destinations
    DeviceManagementQFolder
    DocProc
    DocProcQFolder
    ESET Online Scanner v3
    eSupportQFolder
    Fax
    Google Earth Plug-in
    Google Update Helper
    Hardware Diagnostic Tools
    Hewlett-Packard Active Check
    Hewlett-Packard Asset Agent for Health Check
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Active Support Library 32 bit components
    HP Advisor
    HP Customer Experience Enhancements
    HP Customer Feedback
    HP Customer Participation Program 8.0
    HP Easy Setup - Frontend
    HP Imaging Device Functions 8.0
    HP OCR Software 8.0
    HP On-Screen Cap/Num/Scroll Lock Indicator
    HP Photosmart Essential
    HP Photosmart Essential 2.01
    HP Photosmart Essential2.01
    HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
    HP Product Assistant
    HP Solution Center 8.0
    HP Update
    HPProductAssistant
    HPSSupply
    Intel(R) Matrix Storage Manager
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 29
    Java(TM) 7 Update 1
    Java(TM) SE Development Kit 7 Update 1
    LightScribe 1.8.15.1
    Malwarebytes' Anti-Malware version 1.51.2.1300
    MarketResearch
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Silverlight
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    Mozilla Firefox 8.0 (x86 en-US)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee autoProducer 6.0
    My HP Games
    NVIDIA Drivers
    OpenOffice.org 3.3
    PSSWCORE
    Python 2.5
    QuickTime
    Realtek High Definition Audio Driver
    Rhapsody
    Rhapsody Player Engine
    Roxio Creator Audio
    Roxio Creator Basic v9
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator EasyArchive
    Roxio Creator Tools
    Roxio Express Labeler 3
    Scan
    Secunia PSI (2.0.0.3001)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Snapfish Picture Mover
    SolutionCenter
    Spybot - Search & Destroy
    SpywareBlaster 4.4
    Status
    Toolbox
    TrayApp
    Unity Web Player
    UnloadSupport
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    VideoToolkit01
    WeatherBug Gadget
    WebReg
    Windows Media Player Firefox Plugin
    WinMerge 2.12.4
    WinRAR archiver
    .
    ==== Event Viewer Messages From Past Week ========
    .
    11/26/2011 9:39:14 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.100.2 for the Network Card with network address 001E8C052AE0 has been denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).
    11/26/2011 9:31:24 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SYMTDI
    11/26/2011 9:31:24 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    11/25/2011 9:22:42 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 98.168.137.12 for the Network Card with network address 001E8C052AE0 has been denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx86 Avgmfx86 Avgtdix cmdGuard cmdHlp DfsC inspect NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr SYMTDI tdx Wanarpv6
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/25/2011 9:14:09 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
    11/25/2011 9:13:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    11/25/2011 9:13:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    11/25/2011 9:13:10 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments " " in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
    11/25/2011 9:13:10 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments " " in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    11/25/2011 9:13:10 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments " " in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
    11/25/2011 9:13:08 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    11/25/2011 9:12:59 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments " " in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    11/25/2011 9:12:54 AM, Error: EventLog [6008] - The previous system shutdown at 9:11:07 AM on 11/25/2011 was unexpected.
    11/25/2011 9:03:17 AM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001E8C052AE0. The following error occurred: The semaphore timeout period has expired.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
    11/25/2011 9:01:04 AM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    11/25/2011 9:01:04 AM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
    11/25/2011 8:23:52 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx86 Avgmfx86 cmdGuard spldr SYMTDI Wanarpv6
    11/25/2011 8:22:26 AM, Error: EventLog [6008] - The previous system shutdown at 8:20:37 AM on 11/25/2011 was unexpected.
    11/22/2011 6:54:32 AM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001E8C052AE0. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
    .
    ==== End Of File ===========================
     
  10. 2011/11/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download Bootkit Remover to your Desktop.

    • Unzip downloaded file to your Desktop.
    • Double-click on boot_cleaner.exe to run the program (Vista/7 users,right click on boot_cleaner.exe and click Run As Administrator).
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.

    =========================================================

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  11. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    logs:

    Bootkit Remover
    (c) 2009 Esage Lab
    www.esagelab.com

    Program version: 1.2.0.1
    OS Version: Microsoft Windows Vista Home Premium Edition Service Pack 2 (build 6
    002), 32-bit

    System volume is \\.\C:
    \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00007e00
    Boot sector MD5 is: ce8901d28a2b8c635e22b4216ab678c2

    Size Device Name MBR Status
    --------------------------------------------
    149 GB \\.\PhysicalDrive0 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Done;
    Press any key to quit...
    **************************
    ComboFix 11-11-26.04 - me 11/26/2011 14:38:35.1.2 - x86
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.1.1033.18.2046.846 [GMT -6:00]
    Running from: c:\users\me\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
    SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files\WinPCap
    c:\users\me\AppData\Roaming\EurekaLog
    c:\users\me\AppData\Roaming\EurekaLog\EurekaLog.ini
    c:\windows\system32\jucheck.exe
    c:\windows\system32\jusched.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-10-26 to 2011-11-26 )))))))))))))))))))))))))))))))
    .
    .
    2011-11-26 20:44 . 2011-11-26 20:44 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-11-23 22:04 . 2011-11-23 22:04 -------- d-----w- c:\users\me\AppData\Roaming\AVG
    2011-11-09 14:06 . 2011-09-20 21:02 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2011-11-09 14:06 . 2011-10-17 11:41 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
    2011-11-09 14:06 . 2011-09-30 15:57 707584 ----a-w- c:\program files\Common Files\System\wab32.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-10-26 22:34 . 2011-02-23 17:42 544656 ----a-w- c:\windows\system32\deployJava1.dll
    2011-10-24 19:29 . 2011-10-24 19:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-10-24 19:29 . 2011-10-24 19:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2011-10-07 17:47 . 2011-01-06 23:36 82400 ----a-w- c:\windows\system32\drivers\inspect.sys
    2011-10-07 17:47 . 2011-01-06 23:36 38616 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
    2011-10-07 17:47 . 2011-01-06 23:36 488208 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
    2011-10-07 17:47 . 2011-01-06 23:36 19600 ----a-w- c:\windows\system32\drivers\cmderd.sys
    2011-10-07 17:47 . 2011-10-26 21:42 33984 ----a-w- c:\windows\system32\cmdcsr.dll
    2011-10-07 17:47 . 2010-12-29 07:42 300200 ----a-w- c:\windows\system32\guard32.dll
    2011-10-07 11:23 . 2011-10-07 11:23 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2011-10-04 11:21 . 2011-10-04 11:21 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
    2011-09-29 19:58 . 2011-05-17 12:23 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-09-13 11:30 . 2011-09-13 11:30 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    2011-09-06 13:30 . 2011-10-13 17:07 2043392 ----a-w- c:\windows\system32\win32k.sys
    2011-09-01 02:35 . 2011-10-13 18:39 1798144 ----a-w- c:\windows\system32\jscript9.dll
    2011-09-01 02:28 . 2011-10-13 18:39 1126912 ----a-w- c:\windows\system32\wininet.dll
    2011-09-01 02:22 . 2011-10-13 18:39 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-08-31 22:00 . 2011-05-23 16:48 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-31 04:05 . 2011-08-31 04:05 83816 ----a-w- c:\windows\system32\dns-sd.exe
    2011-08-31 04:05 . 2011-08-31 04:05 73064 ----a-w- c:\windows\system32\dnssd.dll
    2011-08-31 04:05 . 2011-08-31 04:05 50536 ----a-w- c:\windows\system32\jdns_sd.dll
    2011-08-31 04:05 . 2011-08-31 04:05 178536 ----a-w- c:\windows\system32\dnssdX.dll
    2011-11-09 14:51 . 2011-04-17 13:35 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WMPNSCFG "= "c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv "= "c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
    "OsdMaestro "= "c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
    "RtHDVCpl "= "RtHDVCpl.exe" [2007-09-19 4702208]
    "HP Health Check Scheduler "= "c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
    "SunJavaUpdateReg "= "c:\windows\system32\jureg.exe" [2007-04-07 54936]
    "AVG_TRAY "= "c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
    "COMODO Internet Security "= "c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 2497352]
    "NvSvc "= "c:\windows\system32\nvsvc.dll" [2007-08-09 86016]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2007-08-09 8466432]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2007-08-09 81920]
    "HP Software Update "= "c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "APSDaemon "= "c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736]
    "IAAnotif "= "c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2008-06-03 178712]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "Launcher "= "c:\windows\SMINST\launcher.exe" [2007-04-03 44168]
    .
    c:\users\me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
    Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-1-10 291896]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle "= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs "=c:\windows\System32\guard32.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001
    .
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-28 136176]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-28 136176]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
    S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
    S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
    S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
    S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-10-07 488208]
    S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-10-07 38616]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-01-10 993848]
    S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2011-01-10 399416]
    S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736]
    S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
    S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
    S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - aswMBR
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-11-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-28 15:54]
    .
    2011-11-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-28 15:54]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    TCP: Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30}: NameServer = 156.154.70.25,156.154.71.25
    FF - ProfilePath - c:\users\me\AppData\Roaming\Mozilla\Firefox\Profiles\06fjlzgm.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - prefs.js: network.proxy.ftp - 98.168.160.150
    FF - prefs.js: network.proxy.ftp_port - 443
    FF - prefs.js: network.proxy.socks - 98.168.160.150
    FF - prefs.js: network.proxy.socks_port - 443
    FF - prefs.js: network.proxy.ssl - 98.168.160.150
    FF - prefs.js: network.proxy.ssl_port - 443
    FF - prefs.js: network.proxy.type - 4
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-11-26 14:44
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    detected NTDLL code modification:
    ZwClose
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(996)
    c:\windows\system32\guard32.dll
    .
    - - - - - - - > 'lsass.exe'(1024)
    c:\windows\system32\guard32.dll
    .
    Completion time: 2011-11-26 14:47:43
    ComboFix-quarantined-files.txt 2011-11-26 20:47
    .
    Pre-Run: 95,923,163,136 bytes free
    Post-Run: 95,797,374,976 bytes free
    .
    - - End Of File - - C3BA5EDFDA409D2E9C9D384C74ED3A4C
     
  12. 2011/11/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good now.

    How is computer doing?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  13. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    Computer seems to be fine. Scan logs:
    OTL logfile created on: 11/26/2011 3:11:57 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\me\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.28% Memory free
    4.23 Gb Paging File | 2.87 Gb Available in Paging File | 67.81% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 140.76 Gb Total Space | 89.31 Gb Free Space | 63.45% Space Free | Partition Type: NTFS
    Drive D: | 8.29 Gb Total Space | 1.11 Gb Free Space | 13.36% Space Free | Partition Type: NTFS

    Computer Name: ME-PC | User Name: me | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011/11/26 15:09:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\me\Desktop\OTL.exe
    PRC - [2011/11/26 15:07:35 | 000,000,000 | ---D | M] -- C:\Program Files\Secunia\PSI\SUA
    PRC - [2011/10/24 19:29:16 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
    PRC - [2011/10/20 05:58:40 | 002,497,352 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    PRC - [2011/10/18 05:14:54 | 001,229,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
    PRC - [2011/10/12 05:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
    PRC - [2011/10/10 05:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
    PRC - [2011/10/07 11:47:13 | 001,883,328 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    PRC - [2011/09/08 19:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
    PRC - [2011/08/15 05:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    PRC - [2011/08/02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    PRC - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2011/01/17 18:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
    PRC - [2011/01/17 18:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
    PRC - [2011/01/10 08:24:20 | 000,993,848 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\PSIA.exe
    PRC - [2011/01/10 08:24:20 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psi_tray.exe
    PRC - [2009/04/11 00:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
    PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    PRC - [2008/06/02 18:50:34 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    PRC - [2008/06/02 18:50:32 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    PRC - [2007/09/19 08:50:44 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
    PRC - [2007/04/18 09:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
    PRC - [2007/02/15 05:59:00 | 000,118,784 | ---- | M] (OsdMaestro) -- C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe


    ========== Modules (No Company Name) ==========

    MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/02/23 21:00:10 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
    MOD - [2010/03/15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
    MOD - [2006/12/10 21:51:08 | 000,077,824 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll
    MOD - [2006/12/10 21:51:08 | 000,065,536 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Unknown | Stopped] -- -- (MSDTC)
    SRV - [2011/10/12 05:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
    SRV - [2011/10/07 11:47:13 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
    SRV - [2011/08/02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
    SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2011/01/10 08:24:20 | 000,993,848 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
    SRV - [2011/01/10 08:24:20 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
    SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
    SRV - [2008/06/02 18:50:34 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe -- (IAANTMON) Intel(R)
    SRV - [2008/01/19 01:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


    ========== Driver Services (SafeList) ==========

    DRV - [2011/10/07 11:47:45 | 000,082,400 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\inspect.sys -- (inspect)
    DRV - [2011/10/07 11:47:43 | 000,038,616 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\cmdhlp.sys -- (cmdHlp)
    DRV - [2011/10/07 11:47:42 | 000,488,208 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard)
    DRV - [2011/10/07 05:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
    DRV - [2011/10/04 05:21:16 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
    DRV - [2011/09/13 05:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
    DRV - [2011/08/08 05:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
    DRV - [2011/07/11 00:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
    DRV - [2011/07/11 00:14:02 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
    DRV - [2011/07/11 00:14:00 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
    DRV - [2011/07/11 00:13:58 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
    DRV - [2010/09/01 02:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\psi_mf.sys -- (PSI)
    DRV - [2007/08/09 04:30:00 | 007,572,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-647472551-2445054320-2577051558-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    IE - HKU\S-1-5-21-647472551-2445054320-2577051558-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-647472551-2445054320-2577051558-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..browser.search.suggest.enabled: false
    FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/ "
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
    FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.7.1
    FF - prefs.js..extensions.enabledItems: seodoctor@prelovac.com:1.5.2
    FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
    FF - prefs.js..extensions.enabledItems: senseo@nicosteiner.de:1.5.5
    FF - prefs.js..extensions.enabledItems: foxyseotool@foxyseotool.com:0.8.5
    FF - prefs.js..extensions.enabledItems: {8BCA0E8A-E57B-425b-A05B-CD3868EB577E}:0.2
    FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319
    FF - prefs.js..network.proxy.ftp: "98.168.160.150 "
    FF - prefs.js..network.proxy.ftp_port: 443
    FF - prefs.js..network.proxy.share_proxy_settings: true
    FF - prefs.js..network.proxy.socks: "98.168.160.150 "
    FF - prefs.js..network.proxy.socks_port: 443
    FF - prefs.js..network.proxy.socks_version: 4
    FF - prefs.js..network.proxy.ssl: "98.168.160.150 "
    FF - prefs.js..network.proxy.ssl_port: 443
    FF - prefs.js..network.proxy.type: 4

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2011/06/01 14:27:47 | 000,000,000 | ---D | M]
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\me\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/11/21 22:07:20 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 08:51:10 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/28 16:27:33 | 000,000,000 | ---D | M]

    [2011/02/23 15:56:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Extensions
    [2011/11/22 17:12:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\06fjlzgm.default\extensions
    [2011/02/23 21:15:19 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\06fjlzgm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}(105)
    [2011/03/18 15:54:40 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\06fjlzgm.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
    [2011/10/24 07:59:48 | 000,000,000 | ---D | M] (WebRank Toolbar) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\06fjlzgm.default\extensions\webrank-toolbar@probcomp(263).com
    [2011/11/10 06:35:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2011/10/26 13:33:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
    [2011/10/26 07:45:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}(183)
    [2011/10/26 16:34:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
    () (No name found) -- C:\USERS\ME\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\06FJLZGM.DEFAULT\EXTENSIONS\INSPECTOR@MOZILLA.ORG.XPI
    () (No name found) -- C:\USERS\ME\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\06FJLZGM.DEFAULT\EXTENSIONS\NETEXPORT@GETFIREBUG.COM.XPI
    [2011/11/09 08:51:10 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2011/10/26 16:34:44 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
    [2011/10/06 18:20:54 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2011/11/09 08:51:10 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gcswf32.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
    CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
    CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\pdf.dll
    CHR - plugin: AVG Internet Security (Enabled) = C:\Users\me\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
    CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: Unity Player (Enabled) = C:\Users\me\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
    CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    CHR - plugin: Default Plug-in (Enabled) = default_plugin
    CHR - Extension: AVG Safe Search = C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1829_0\

    O1 HOSTS File: ([2011/11/26 14:44:40 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
    O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
    O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
    O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
    O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
    O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
    O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\launcher.exe (soft thinks)
    O4 - Startup: C:\Users\me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-647472551-2445054320-2577051558-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-647472551-2445054320-2577051558-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
    O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30}: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7018D27D-B57C-4C46-9A6B-A78955327F30}: NameServer = 156.154.70.25,156.154.71.25
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O20 - AppInit_DLLs: (C:\Windows\System32\guard32.dll) -C:\Windows\System32\guard32.dll (COMODO)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img35.jpg
    O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img35.jpg
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2011/02/23 12:01:41 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: FastUserSwitchingCompatibility - File not found
    NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
    NetSvcs: Nla - File not found
    NetSvcs: Ntmssvc - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: SRService - File not found
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: LogonHours - File not found
    NetSvcs: PCAudit - File not found
    NetSvcs: helpsvc - File not found
    NetSvcs: uploadmgr - File not found

    Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/11/26 15:09:05 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\me\Desktop\OTL.exe
    [2011/11/26 14:47:47 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2011/11/26 14:47:45 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2011/11/26 14:37:19 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2011/11/26 14:37:19 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2011/11/26 14:37:19 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2011/11/26 14:37:02 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
    [2011/11/26 14:27:56 | 004,309,325 | R--- | C] (Swearware) -- C:\Users\me\Desktop\ComboFix.exe
    [2011/11/26 14:27:24 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\me\Desktop\boot_cleaner.exe
    [2011/11/25 09:10:09 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\me\Desktop\dds.scr
    [2011/11/25 09:09:44 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\me\Desktop\aswMBR.exe
    [2011/11/25 08:22:14 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
    [2011/11/23 16:04:28 | 000,000,000 | ---D | C] -- C:\Users\me\AppData\Roaming\AVG
    [2011/11/19 17:22:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) Matrix Storage Manager
    [2011/11/18 08:38:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2011/11/16 10:50:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2011/10/31 14:42:18 | 000,000,000 | ---D | C] -- C:\Users\me\Documents\Love's
    [2011/10/31 14:41:56 | 000,000,000 | ---D | C] -- C:\Users\me\Desktop\Love's
    [2011/10/28 16:27:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime

    ========== Files - Modified Within 30 Days ==========

    [2011/11/26 15:09:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\me\Desktop\OTL.exe
    [2011/11/26 14:44:40 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
    [2011/11/26 14:37:00 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/11/26 14:27:58 | 004,309,325 | R--- | M] (Swearware) -- C:\Users\me\Desktop\ComboFix.exe
    [2011/11/26 13:37:06 | 110,786,882 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
    [2011/11/26 13:31:06 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/11/26 13:31:06 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/11/26 11:41:54 | 000,000,512 | ---- | M] () -- C:\Users\me\Desktop\MBR.dat
    [2011/11/26 09:35:48 | 000,604,264 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/11/26 09:35:48 | 000,103,964 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/11/26 09:31:10 | 000,000,874 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/11/26 09:31:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/11/26 09:30:51 | 2145,898,496 | -HS- | M] () -- C:\hiberfil.sys
    [2011/11/25 09:10:10 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\me\Desktop\dds.scr
    [2011/11/25 09:09:49 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\me\Desktop\aswMBR.exe
    [2011/11/23 16:36:53 | 000,882,291 | ---- | M] () -- C:\Users\me\Desktop\6401 Avalon Flyer-Shanbour.pdf
    [2011/11/22 07:08:27 | 000,137,570 | ---- | M] () -- C:\Users\me\Documents\cc_20111122_070820.reg
    [2011/11/21 22:07:20 | 000,000,844 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk
    [2011/11/16 10:50:14 | 000,001,666 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011/11/08 17:15:16 | 000,064,077 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavichjg.avm
    [2011/10/31 10:12:47 | 000,000,858 | ---- | M] () -- C:\Users\me\AppData\Roaming\wklnhst.dat
    [2011/10/28 16:27:27 | 000,001,728 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk

    ========== Files Created - No Company Name ==========

    [2011/11/26 14:37:19 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2011/11/26 14:37:19 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2011/11/26 14:37:19 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2011/11/26 14:37:19 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2011/11/26 14:37:19 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2011/11/25 09:22:26 | 2145,898,496 | -HS- | C] () -- C:\hiberfil.sys
    [2011/11/25 09:15:49 | 000,000,512 | ---- | C] () -- C:\Users\me\Desktop\MBR.dat
    [2011/11/23 16:36:53 | 000,882,291 | ---- | C] () -- C:\Users\me\Desktop\6401 Avalon Flyer-Shanbour.pdf
    [2011/11/22 07:08:23 | 000,137,570 | ---- | C] () -- C:\Users\me\Documents\cc_20111122_070820.reg
    [2011/11/16 10:50:14 | 000,001,666 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011/10/28 16:27:27 | 000,001,728 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
    [2011/03/27 07:26:24 | 000,000,000 | ---- | C] () -- C:\Users\me\AppData\Local\prvlcl.dat
    [2011/03/03 15:18:00 | 000,148,904 | ---- | C] () -- C:\Windows\hpoins19.dat
    [2011/03/03 15:17:46 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
    [2011/02/24 16:43:21 | 000,000,858 | ---- | C] () -- C:\Users\me\AppData\Roaming\wklnhst.dat
    [2011/02/23 19:01:08 | 000,014,848 | ---- | C] () -- C:\Users\me\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/02/23 16:58:45 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
    [2011/02/23 16:55:27 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
    [2011/02/23 16:55:27 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
    [2011/02/23 11:59:29 | 000,107,026 | ---- | C] () -- C:\Windows\hpqins13.dat
    [2011/02/23 11:45:02 | 000,061,440 | ---- | C] () -- C:\Windows\System32\OsdRemove.exe
    [2011/02/23 11:42:59 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
    [2011/02/23 11:42:59 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
    [2011/02/23 11:35:54 | 000,000,680 | ---- | C] () -- C:\Users\me\AppData\Local\d3d9caps.dat
    [2007/07/19 09:07:52 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
    [2006/12/14 01:01:36 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
    [2006/12/14 01:01:36 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
    [2006/11/02 09:12:52 | 000,217,088 | ---- | C] () -- C:\Windows\System32\missouri.dll
    [2006/11/02 06:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2006/11/02 06:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
    [2006/11/02 04:33:01 | 000,604,264 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2006/11/02 04:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2006/11/02 04:33:01 | 000,103,964 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2006/11/02 04:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2006/11/02 04:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2006/11/02 02:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2006/11/02 02:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2006/11/02 01:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
    [2006/11/02 01:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2002/08/09 07:18:44 | 000,036,864 | ---- | C] () -- C:\Windows\System32\pandoras.dll

    ========== LOP Check ==========

    [2011/11/23 16:04:32 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\AVG
    [2011/09/29 10:10:59 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\AVG2012
    [2011/08/01 09:04:51 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\Downloaded Installations
    [2011/05/18 14:52:58 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\IBP
    [2011/02/24 16:43:36 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\OpenOffice.org
    [2011/02/23 11:09:37 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\Snapfish
    [2011/03/29 15:40:52 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\Template
    [2011/05/13 19:10:32 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\Unity
    [2011/02/24 11:38:32 | 000,000,000 | ---D | M] -- C:\Users\me\AppData\Roaming\WinBatch
    [2011/11/25 22:25:16 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2011/02/18 10:12:54 | 000,270,496 | ---- | M] () -- C:\aaw7boot.log
    [2011/02/23 12:01:41 | 000,000,074 | ---- | M] () -- C:\autoexec.bat
    [2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
    [2011/02/23 11:20:09 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
    [2011/11/26 14:47:43 | 000,011,431 | ---- | M] () -- C:\ComboFix.txt
    [2006/09/18 15:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
    [2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
    [2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
    [2011/05/10 11:06:34 | 000,000,250 | ---- | M] () -- C:\FINIS_IT.TXT
    [2009/11/01 09:04:52 | 000,000,068 | ---- | M] () -- C:\hcwclear.txt
    [2011/11/26 09:30:51 | 2145,898,496 | -HS- | M] () -- C:\hiberfil.sys
    [2011/10/26 15:57:54 | 000,167,205 | ---- | M] () -- C:\JavaRa.log
    [2010/05/18 07:59:20 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
    [2009/03/27 07:27:30 | 000,000,000 | ---- | M] () -- C:\OrbPVR.db
    [2011/11/26 09:30:49 | 2459,709,440 | -HS- | M] () -- C:\pagefile.sys
    [2008/04/11 13:40:54 | 000,000,477 | ---- | M] () -- C:\RHDSetup.log
    [2011/02/11 09:16:02 | 000,123,586 | ---- | M] () -- C:\TDSSKiller.2.4.17.0_11.02.2011_09.15.06_log.txt
    [2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
    [2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab

    < %systemroot%\Fonts\*.com >
    [2006/11/02 06:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2006/11/02 06:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2006/11/02 06:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2011/02/23 17:26:26 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2006/09/18 15:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2008/01/19 01:34:28 | 000,089,600 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
    [2006/11/02 06:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2011/02/23 15:38:49 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2006/11/02 04:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
    [2006/11/02 04:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
    [2006/11/02 04:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
    [2006/11/02 04:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
    [2006/11/02 04:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2011/04/12 17:33:35 | 000,000,286 | -HS- | M] () -- C:\Users\me\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2011/11/25 09:09:49 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\me\Desktop\aswMBR.exe
    [2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\me\Desktop\boot_cleaner.exe
    [2011/11/26 14:27:58 | 004,309,325 | R--- | M] (Swearware) -- C:\Users\me\Desktop\ComboFix.exe
    [2011/11/26 15:09:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\me\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2011/02/23 11:09:17 | 000,000,402 | -HS- | M] () -- C:\Users\me\Favorites\desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2011/03/03 15:33:12 | 000,001,525 | ---- | M] () -- C:\ProgramData\hpzinstall.log

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
    @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4

    < End of report >
     
  14. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    OTL Extras logfile created on: 11/26/2011 3:11:57 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\me\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.28% Memory free
    4.23 Gb Paging File | 2.87 Gb Available in Paging File | 67.81% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 140.76 Gb Total Space | 89.31 Gb Free Space | 63.45% Space Free | Partition Type: NTFS
    Drive D: | 8.29 Gb Total Space | 1.11 Gb Free Space | 13.36% Space Free | Partition Type: NTFS

    Computer Name: ME-PC | User Name: me | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
    .html [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found

    [HKEY_USERS\S-1-5-21-647472551-2445054320-2577051558-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    htmlfile [edit] -- Reg Error: Key error.
    https [open] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.)


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0276AC8E-65DA-4FED-82E8-65319A67EC09}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
    "{24C43B23-DDB6-490C-A8BE-03883AB25526}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
    "{35C75FC6-0464-43B0-A315-E43F97A2A06C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{3EF52B62-3532-4EE0-9608-B6E7225A52D7}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
    "{50316DAB-6496-46C2-ABA1-CEEA1A8CAFCC}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
    "{559198CD-F3C9-4495-A430-66B224B12CDA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{568393DD-1270-4A60-A3A4-08CF6CCAAB8D}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
    "{62497161-B22C-426E-9D1F-994ACF295FC4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
    "{6EFDD634-DACB-42F8-BE4E-2C7DB4A992E1}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
    "{8BAA7679-0301-4DF5-9AE1-BCCDBADFDB4A}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
    "{92CC1E7C-37DB-4886-9133-985E393DA854}" = dir=in | app=c:\program files\itunes\itunes.exe |
    "{9C0CEE52-1784-484C-BBAB-1FC863C20F21}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
    "{9CDA174E-E55A-4430-98F2-435E68039E91}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
    "{A3074B09-E514-4F6B-8CEA-DA89BB8DA715}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
    "{ACCC8199-8A5A-4E62-972C-F81EE1CB67EB}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
    "{E2E668BB-8174-49E2-BD16-9591C50ED344}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
    "{F24673B9-992D-48A1-BD81-9DD82BBED7F1}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
    "{F44FEE56-C50E-4A85-9DB4-9B034F0CE2A6}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
    "{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
    "{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
    "{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}" = HP Active Support Library
    "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
    "{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
    "{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
    "{14AF024E-2E3B-49D0-A175-D1C1A06B155A}" = muvee autoProducer 6.0
    "{17271AB7-D7EC-4a95-9861-FAFE5A4664AD}" = 6300Trb
    "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
    "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
    "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
    "{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29
    "{26A24AE4-039D-4CA4-87B4-2F83217001FF}" = Java(TM) 7 Update 1
    "{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
    "{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
    "{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
    "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
    "{3127F76D-5335-4AC7-BD1E-2F5247A23C24}" = iTunes
    "{32A3A4F4-B792-11D6-A78A-00B0D0170010}" = Java(TM) SE Development Kit 7 Update 1
    "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
    "{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
    "{41F4B3D2-3CC8-41B5-99B8-3A9C1BCDEA0A}" = AVG 2012
    "{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
    "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
    "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
    "{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
    "{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
    "{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
    "{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
    "{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
    "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
    "{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
    "{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
    "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
    "{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
    "{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
    "{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe 1.8.15.1
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{BDEDBDD9-C97B-4333-B7BE-6979A34F6F74}" = 6300_Help
    "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
    "{C716522C-3731-4667-8579-40B098294500}" = Toolbox
    "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
    "{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
    "{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
    "{E2CB21A2-FD45-4353-888B-FFD071270F35}" = 6300
    "{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
    "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
    "{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
    "{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security
    "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
    "{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "AVG" = AVG 2012
    "CCleaner" = CCleaner
    "ESET Online Scanner" = ESET Online Scanner v3
    "HP Imaging Device Functions" = HP Imaging Device Functions 8.0
    "HP Photosmart Essential" = HP Photosmart Essential 2.01
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
    "HPExtendedCapabilities" = HP Customer Participation Program 8.0
    "HPOCR" = HP OCR Software 8.0
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
    "NVIDIA Drivers" = NVIDIA Drivers
    "OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
    "PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
    "Rhapsody" = Rhapsody
    "Secunia PSI" = Secunia PSI (2.0.0.3001)
    "SpywareBlaster_is1" = SpywareBlaster 4.4
    "WildTangent hp Master Uninstall" = My HP Games
    "WinMerge_is1" = WinMerge 2.12.4
    "WinRAR archiver" = WinRAR archiver

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-647472551-2445054320-2577051558-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "UnityWebPlayer" = Unity Web Player

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 10/18/2011 6:32:24 PM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/18/2011 7:27:10 PM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/18/2011 10:30:14 PM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/18/2011 10:30:23 PM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/19/2011 9:01:05 AM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/19/2011 9:01:06 AM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/19/2011 9:01:06 AM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/19/2011 9:01:06 AM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/19/2011 9:01:06 AM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 10/19/2011 9:01:11 AM | Computer Name = me-PC | Source = Windows Search Service | ID = 3013
    Description =

    [ System Events ]
    Error - 11/25/2011 11:22:42 AM | Computer Name = me-PC | Source = Dhcp | ID = 1002
    Description = The IP address lease 98.168.137.12 for the Network Card with network
    address 001E8C052AE0 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 11/25/2011 11:23:00 AM | Computer Name = me-PC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 11/25/2011 11:23:01 AM | Computer Name = me-PC | Source = Service Control Manager | ID = 7026
    Description =

    Error - 11/25/2011 11:25:53 AM | Computer Name = me-PC | Source = Dhcp | ID = 1002
    Description = The IP address lease 192.168.100.2 for the Network Card with network
    address 001E8C052AE0 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 11/26/2011 11:31:24 AM | Computer Name = me-PC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 11/26/2011 11:31:24 AM | Computer Name = me-PC | Source = Service Control Manager | ID = 7026
    Description =

    Error - 11/26/2011 11:39:14 AM | Computer Name = me-PC | Source = Dhcp | ID = 1002
    Description = The IP address lease 192.168.100.2 for the Network Card with network
    address 001E8C052AE0 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 11/26/2011 4:38:21 PM | Computer Name = me-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 11/26/2011 4:41:52 PM | Computer Name = me-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 11/26/2011 4:44:48 PM | Computer Name = me-PC | Source = Service Control Manager | ID = 7030
    Description =


    < End of report >
     
  15. 2011/11/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good news :)

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
      @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ===========================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  16. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    Fix results and checkup.txt, running TFC and eset scan now. Thanks.

    All processes killed
    Error: Unable to interpret <Code:> in the current context!
    ========== OTL ==========
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\Windows\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    ADS C:\ProgramData\TEMP:5C321E34 deleted successfully.
    ADS C:\ProgramData\TEMP:0B4227B4 deleted successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: me
    ->Temp folder emptied: 48216 bytes
    ->Temporary Internet Files folder emptied: 68517 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 37627057 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Flash cache emptied: 470 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 620 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 36.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: me
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.31.0 log created on 11262011_153748

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
    ***********
    Results of screen317's Security Check version 0.99.24
    Windows Vista Service Pack 2 x86 (UAC is enabled)
    Internet Explorer 9
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Disabled!
    AVG 2012
    ESET Online Scanner v3
    COMODO Internet Security
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 29
    Java(TM) 7 Update 1
    Java(TM) SE Development Kit 7 Update 1
    Out of date Java installed!
    Adobe Flash Player ( 10.3.183.10) Flash Player Out of Date!
    Adobe Reader X (10.1.1)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Spybot Teatimer.exe is disabled!
    AVG avgwdsvc.exe
    AVG avgtray.exe
    AVG avgrsx.exe
    AVG avgnsx.exe
    AVG avgemc.exe
    Comodo Firewall cmdagent.exe
    Comodo Firewall cfp.exe
    ``````````End of Log````````````
     
  17. 2011/11/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  18. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    Eset was clean.
    Updated flash using link
    uninstalled
    Java(TM) 7 Update 1
    Java(TM) SE Development Kit 7 Update 1
    using control panel
     
  19. 2011/11/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     
  20. 2011/11/26
    shammie

    shammie Well-Known Member Thread Starter

    Joined:
    2004/05/29
    Messages:
    195
    Likes Received:
    0
    Thanks for all your help. I appreciated all your effort. Log file:
    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: me
    ->Temp folder emptied: 16384 bytes
    ->Temporary Internet Files folder emptied: 32902 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 11412674 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Flash cache emptied: 291 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    RecycleBin emptied: 7563584 bytes

    Total Files Cleaned = 18.00 mb


    [EMPTYFLASH]

    User: All Users
     
  21. 2011/11/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Way to go!! [​IMG]
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.