This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malwarebytes Finds 2 hijack.windowsupdates files

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After it rebooted a log came up so i thought id post that aswell:

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}\ deleted successfully.
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL unregistered successfully.
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL moved successfully.
DllUnregisterServer procedure not found in C:\Program Files\mozilla firefox\plugins\NPAskSBr.dll
C:\Program Files\mozilla firefox\plugins\NPAskSBr.dll NOT unregistered.
C:\Program Files\mozilla firefox\plugins\NPAskSBr.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}\ not found.
File C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\AskSBar Uninstall not found.
========== FILES ==========
C:\Program Files\AskSBar\SrchAstt\1.bin moved successfully.
C:\Program Files\AskSBar\SrchAstt moved successfully.
C:\Program Files\AskSBar\bar\Settings moved successfully.
C:\Program Files\AskSBar\bar\History moved successfully.
C:\Program Files\AskSBar\bar\Cache moved successfully.
C:\Program Files\AskSBar\bar\1.bin moved successfully.
C:\Program Files\AskSBar\bar moved successfully.
C:\Program Files\AskSBar moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Temp\nsk46.tmp scheduled to be deleted on reboot.
->Temp folder emptied: 846093 bytes
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 2596911 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 74540922 bytes
->Apple Safari cache emptied: 0 bytes

User: All Users

User: Carol Czaplowski

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
File delete failed. C:\WINDOWS\S061C833E.tmp scheduled to be deleted on reboot.
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 164715 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 74.56 mb


OTL by OldTimer - Version 3.0.14.0 log created on 09212009_234110

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\nsk46.tmp not found!
File move failed. C:\WINDOWS\S061C833E.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot…



And here is the Quick Scan log:

OTL logfile created on: 9/21/2009 11:46:06 PM - Run 2
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 59.43% Memory free
3.10 Gb Paging File | 2.49 Gb Available in Paging File | 80.43% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 50.93 Gb Total Space | 15.15 Gb Free Space | 29.75% Space Free | Partition Type: NTFS
Drive D: | 111.55 Gb Total Space | 45.07 Gb Free Space | 40.40% Space Free | Partition Type: FAT32
Drive E: | 135.37 Gb Total Space | 22.12 Gb Free Space | 16.34% Space Free | Partition Type: NTFS
Drive F: | 76.66 Gb Total Space | 2.98 Gb Free Space | 3.88% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: XPMCE
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\System32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\SPAMfighter\sfus.exe (SPAMfighter ApS)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe (Raxco Software, Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\MsgSys.EXE (Intel Corporation)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\Program Files\WinFast\WFTVFM\WFWIZ.exe (Leadtek Research Inc.)
PRC - C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\D-Link\AirPlus G\AirGCFG.exe (D-Link)
PRC - C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Alpha Networks Inc.)
PRC - C:\Program Files\SPAMfighter\SFAgent.exe (SPAMfighter ApS)
PRC - C:\Program Files\dvd43\dvd43_tray.exe ()
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe ()
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe (ATI Technologies Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe ()
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe ()
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe ()
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\iTunes\iTunes.exe (Apple Inc.)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (ANIWZCSdService [Auto | Stopped]) – C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (Alpha Networks Inc.)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (Automatic LiveUpdate Scheduler [Auto | Running]) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (fsssvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Irmon [Auto | Running]) – C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Macromedia Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe (Macromedia)
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (Norton AntiVirus Server [Auto | Running]) – C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PDAgent [Auto | Running]) – C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.)
SRV - (PDEngine [On_Demand | Running]) – C:\Program Files\Raxco\PerfectDisk\PDEngine.exe (Raxco Software, Inc.)
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (ServiceLayer [On_Demand | Running]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SPAMfighter Update Service [Auto | Running]) – C:\Program Files\SPAMfighter\sfus.exe (SPAMfighter ApS)
SRV - (UleadBurningHelper [Auto | Running]) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (UPHClean [Auto | Running]) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (uploadmgr [Auto | Stopped]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (WebrootSpySweeperService [Auto | Running]) – C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - Reg Error: Key error. File not found
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {CDE0EC96-084E-4F0E-B5C6-8A81A5B95658}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3

FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/07 08:27:59 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{CDE0EC96-084E-4F0E-B5C6-8A81A5B95658}: C:\Documents and Settings\Administrator\Local Settings\Application Data\{CDE0EC96-084E-4F0E-B5C6-8A81A5B95658}\ [2009/08/30 14:14:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/08 13:45:53 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\mozilla firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/19 19:16:11 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\mozilla firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/21 23:41:21 | 00,000,000 | —D | M]

[2009/07/08 13:48:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions
[2008/09/19 11:45:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/08 13:48:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\[removed]
[2009/09/21 17:59:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\aa4jjpxu.default\extensions
[2009/08/07 13:51:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\aa4jjpxu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/21 17:59:15 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/09/10 21:02:12 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/09/15 22:02:25 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009/08/25 06:15:25 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/25 06:15:26 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/04/10 17:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2008/03/19 19:23:20 | 00,114,688 | —- | M] (Adobe Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/09/15 22:01:25 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/06/27 15:03:12 | 01,446,440 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/08/25 06:15:27 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/02/27 12:13:42 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/08/11 18:28:55 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/08/11 18:28:55 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/08/11 18:28:56 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/08/11 18:28:56 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/08/11 18:28:56 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/08/11 18:28:56 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/08/11 18:28:56 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/08/25 04:45:46 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/25 04:45:46 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/25 04:45:46 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/25 04:45:46 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/25 04:45:46 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/25 04:45:46 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/25 04:45:46 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS3\contributeieplugin.dll (Adobe Systems Incorporated.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (FlpLauncher Class) - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - C:\Program Files\E-Book Systems\FlipAlbum 6 Pro\FpLaunch.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS3\contributeieplugin.dll (Adobe Systems Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Alpha Networks Inc.)
O4 - HKLM..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe (D-Link)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe ()
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SPAMfighter Agent] C:\Program Files\SPAMfighter\SFAgent.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe (Leadtek Research Inc.)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 90 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = laurencenet
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\System32\NavLogon.dll ()
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - C:\WINDOWS\System32\WRLogonNTF.dll (Webroot Software, Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/28 08:31:12 | 00,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/09/23 15:56:21 | 00,000,095 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (pdboot.exe) - C:\WINDOWS\System32\pdboot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 14 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/09/21 23:41:10 | 00,000,000 | —D | C] – C:\_OTL
[2009/09/20 18:36:24 | 00,514,560 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/09/19 12:53:11 | 00,000,000 | —D | C] – C:\_OTM
[2009/09/19 12:48:45 | 00,408,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTM.exe
[2009/09/19 12:34:34 | 00,001,762 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/09/18 15:20:54 | 00,000,000 | —D | C] – C:\Program Files\ESET
[2009/09/16 22:02:26 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/09/16 22:01:16 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2009/09/16 22:00:16 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/09/16 21:56:10 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/09/16 21:55:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/09/16 21:55:48 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/09/16 21:55:09 | 00,000,000 | —D | C] – C:\Program Files\Windows Live
[2009/09/16 21:48:23 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/09/15 21:53:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\JavaRa
[2009/09/15 15:31:30 | 00,000,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/15 15:31:27 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/15 15:31:25 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/15 15:31:24 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/09/15 15:25:27 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/09/15 15:13:18 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/09/15 15:07:35 | 00,229,888 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/09/15 15:07:35 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/09/15 15:07:35 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/09/15 15:07:35 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/09/15 15:07:35 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/09/15 15:07:35 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/09/15 15:07:35 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/09/15 15:07:35 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/09/14 23:11:08 | 00,000,209 | —- | C] () – C:\Boot.bak
[2009/09/14 23:11:05 | 00,260,272 | —- | C] () – C:\cmldr
[2009/09/14 23:11:03 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/09/14 23:09:57 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/09/14 23:09:29 | 00,000,000 | —D | C] – C:\Qoobox
[2009/09/14 23:05:42 | 03,315,033 | R— | C] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2009/09/14 08:04:13 | 00,016,048 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\VET NETWORK MEETING 20 August 2009 (2).docx
[2009/09/11 19:21:34 | 03,227,298 | -H– | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2009/09/11 07:42:47 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Locktime
[2009/09/11 07:38:48 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Locktime
[2009/09/10 20:58:05 | 08,067,224 | —- | C] (Mozilla) – C:\Documents and Settings\Administrator\Desktop\Firefox Setup 3.5.3.exe

========== Files - Modified Within 14 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/09/21 23:48:30 | 00,442,094 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/09/21 23:48:29 | 00,522,378 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/09/21 23:48:29 | 00,071,728 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/09/21 23:43:42 | 00,002,278 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/09/21 23:43:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/09/21 23:43:24 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/09/21 23:43:20 | 18,774,63040 | -HS- | M] () – C:\hiberfil.sys
[2009/09/20 18:36:37 | 00,514,560 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/09/19 12:48:58 | 00,408,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTM.exe
[2009/09/19 12:34:34 | 00,001,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/09/16 22:00:02 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/09/16 21:58:23 | 00,000,960 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\My Sharing Folders.lnk
[2009/09/15 18:13:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/09/15 15:31:30 | 00,000,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/15 15:16:26 | 00,000,262 | —- | M] () – C:\WINDOWS\system.ini
[2009/09/15 15:16:11 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/09/14 23:11:08 | 00,000,279 | RHS- | M] () – C:\boot.ini
[2009/09/14 23:05:43 | 03,315,033 | R— | M] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2009/09/14 08:04:16 | 00,016,048 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\VET NETWORK MEETING 20 August 2009 (2).docx
[2009/09/14 02:12:36 | 00,229,888 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/09/11 19:21:53 | 03,227,298 | -H– | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2009/09/10 21:02:19 | 00,001,635 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/09/10 21:00:01 | 08,067,224 | —- | M] (Mozilla) – C:\Documents and Settings\Administrator\Desktop\Firefox Setup 3.5.3.exe
[2009/09/10 14:54:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/10 07:27:00 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/09/08 15:24:25 | 00,095,744 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== LOP Check ==========

[2009/09/14 23:19:49 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data
[2007/02/21 00:21:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Ahead
[2008/12/23 13:43:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ATI
[2009/09/14 12:13:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Azureus
[2009/08/28 12:53:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Cabos
[2007/06/13 14:36:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Canon
[2007/06/15 11:30:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\CoreFTP
[2007/05/15 13:02:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\COWON
[2007/04/23 18:18:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\DataLayer
[2007/03/07 05:42:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\EBookSys
[2007/02/28 10:17:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Ipswitch
[2008/01/14 00:21:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Kazaa Lite
[2009/09/11 07:42:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Locktime
[2008/01/14 00:07:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Morpheus
[2008/01/14 00:07:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Morpheus Ultra
[2007/03/06 01:29:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Musicmatch
[2007/02/25 10:39:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Netscape
[2008/01/27 17:54:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Nokia
[2008/07/03 16:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Nokia Multimedia Player
[2008/09/23 12:48:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Opera
[2007/03/15 23:08:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Orbit
[2008/01/27 16:55:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\PC Suite
[2007/03/23 15:59:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Pegasys Inc
[2007/02/25 10:39:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Photodex
[2007/03/11 18:52:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Ringjacker
[2007/04/06 16:38:16 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data\SecuROM
[2008/06/09 11:40:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Simply Super Software
[2007/03/31 16:23:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SlySoft
[2008/01/06 16:56:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SPAMfighter
[2009/05/07 16:42:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Thinstall
[2009/08/11 19:17:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\U3
[2009/06/02 15:35:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Vso
[2009/09/15 15:28:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/05/10 10:43:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/05/03 17:20:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
[2007/05/01 17:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2008/12/23 13:43:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI
[2009/08/31 11:30:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2008/01/27 15:06:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2007/05/13 19:45:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2007/06/12 16:12:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2007/03/17 19:34:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
[2007/04/20 12:57:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/01/27 17:43:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2007/02/28 10:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ipswitch
[2009/09/11 07:38:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Locktime
[2008/01/27 17:44:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nokia
[2007/06/04 17:24:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2007/02/28 09:03:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2007/02/28 08:29:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2009/04/04 16:40:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2008/05/10 22:50:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2007/02/21 01:10:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/07/12 18:56:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/02/27 13:37:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/05/10 14:27:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/09/15 18:13:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/07/21 21:17:50 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/09/21 23:43:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >
You're welcome :)

Well done! Your log appears clean! :thumbup:

——————
Step 1:
——————

We're almost done. We need to do some clean up and get you on your way.

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]
(This will remove all restore points to rid your machine of saved infected files and create a new restore point)

——————
Step 2:
——————

We need to remove all the tools that you have used. This is so that should you ever be re-infected, you will download updated versions.

  • Run OTL.exe
  • Click the Clean Up button in top right corner.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
Now delete any logs that you have left over on your desktop.


——————
Step 3:
——————

Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
Note: It is a good idea to run TFC to clear out all your temp files every now and again. This helps to keep your computer running more efficiently. It also can assist in getting rid of files that may contain malicious code that could re-infect your computer.


——————
Step 4:
——————

It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Windows Updates are constantly being revised to combat the newest hacks and threats. Microsoft releases security updates that help your computer from becoming vunerable.

Please go to Microsoft's Windows Update and download all the critical updates to help prevent possible re-infection.

It is best if you have these set to download automatically.

Automatic Updates for Windows
  • Click Start.
  • Select Settings and then Control Panel.
  • Select Automatic Updates.
  • Click Automatic (recommended)
  • Choose a day and a time when you know the computer will be on and connected to the internet.
  • Click Apply then OK.

———————————————————————————————

This is a good time to set up protection against further attacks. Read our How Did I Get Infected In The First Place?. You need an antivirus that is continually updated, a good firewall, a spyware blocker, and a real time spyware program to prevent malware intrusions. Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

———————————————————————————————

Anti Spyware

Anti Spyware helps to eliminate certain types of infections. I would recommend getting these and running the scans at least twice a month. Also a real-time protector is beneficial to stop infections before they start. SpywareGuard is an excellent choice here.
Note: If you find your system slows down after installing any of these, just uninstall it, or disable it from running at startup.

———————————————————————————————

Safer Web Browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are some good free alternatives:
All are faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these.

If you choose FireFox, here are a couple of addons that I recommend:
  • NoScript - for blocking ads and other potential website attacks
  • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must have if you do alot of Google searches.

———————————————————————————————

Other Recommendations

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.

Take Care and Happy Surfing! :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI