This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unable to run antivirus and spyware defense programs

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, about three days ago my computer was infected with what seems like a combination of a virus, spyware and malware. The first day my computer was constantly being bombarded with pop-ups for Malware Defender, but I was able to delete that. And now I'm not getting those pesky pop-ups anymore. Then on the second day my computer kept getting error messages from internet explorer, which I never use (I use Firefox), that read "Internet Explorer has stopped working" with an error of "Stackhash_1703". Along with that error I would get an error message saying that my host rundll32.exe wasn't working and had to be closed. I've been trying to get my Norton Antivirus 2010 to run to scan my computer but when I try to run the program by clicking on the desktop icon my mouse turns into an hourglass for a couple seconds like its going to load but doesn't. The same thing happens when I try to run Spybot Search and Destroy and also when I try to install and run Malwarebytes. Another thing that also happens is when I'm on the internet trying to get help on getting my computer fixed frequently when I try to click on a website I will more often than not either get redirected to a random website or it will come up with a "Server not Found" page. This happens EVERY time I try to access any page hosted by Bleeping Computer. I am currently at a lost at what to do now to get my computer cleaned up and I really need some help please. By the way the operating system is Windows Vista. Mellissa
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I am checking over your log , I will post back shortly with instructions.
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



As a Vista user, you will need to right click and choose "Run as Administrator" to run the tools we will use.


Please download exeHelper to your desktop.
Right-click on exeHelper.com then choose "Run as Administrator" to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

–Next–

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Right-click DDS icon then choose "Run as Administrator" to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on to insert the attachment into your post
Please post both DDS logs in your next reply.

–Next–

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Right-click gmer.exe then choose "Run as Administrator". The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop
To post in your next reply:
1. exeHelper log.
2. DDS logs.
3. GMER log.
Okay, I ran exeHelper and got the log. I am unable to download DDS from either of the links you provided. The first one is served on the BleepingComputer domain and I am unable to access that domain. I get a server not found page no matter how many times I try to access the page. The second one when I click on it I just get a page full of characters and script that mean nothing. Also I tried to run Gmer as an administrator but I got an error message saying "gmer.exe has stopped working." I made sure that nothing was on when I tried running the program. So I was able to do one out of three. Mellissa 📎exehelperlog.txt
Hi,

Let's try this:
  • Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text into the box under Custom Scan

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    /md5stop
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt and post it with your next reply along with the OTL fix log.

–Next–

We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.
To post in your next reply:
1. OTL log.
2. RootRepeal log.
Hi,

Are you using PermissionResearch? There site is being blocked by MVPS.
Also, according to this site (link), it is a scam, though they didn't provide much info but SiteAdvisor (link) doesn't mark their site as bad.

If you wish to remove it, you can do the following:
  • Click on Start > Control Panel and double click on Programs and Features.
  • Locate PermissionResearch and click on the Uninstall button to uninstall it.
  • Close Control Panel when done.
–Next–

You were unable to post OTL Extra.txt which can be found on your desktop. Please post the contents on your next reply.

–Next–

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right-click SystemLook.exe then choose Run as Administrator to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    C:\cf38c0e4d3e1e1b0ca3e15fbf8dbe6f3 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

–Next–

Download Combofix from either of the links below. You must rename it to Subsfix.exe before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Right click and choose Run as Administrator the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–



To post in your next reply:
1. OTL extra.txt.
2. SystemLook log.
3. Combofix log.
Okay here are the three logs you asked for. By the way it looks like after performing ComboFix Norton Antivirus now works along with Spybot Search and Destroy. Also I no longer have any annoying popups happening every 5 seconds. And finally I deleted that PermissionResearch program that somehow was installed on my computer. 📎Extras.Txt 📎SystemLook.txt 📎log.txt
Hi,

You have Limewire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall Limewire, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554

–Next–

Please do the following:

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/index.php?s=…st&p=626940

Collect::
c:\programdata\h8srtkrl32mainweq.dll
c:\programdata\h8srtkrl32mainweq.dll

File::
c:\windows\msa.exe.vir

Folder::
C:\Program Files\Zango

ADS::
C:\ProgramData\TEMP

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.



Post the result on your next reply, don't attach.
Ok here is the log:




ComboFix 10-01-21.08 - staples0286 01/22/2010 21:40:26.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.2109 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\SubsFix.exe
Command switches used :: c:\users\staples0286\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\msa.exe.vir"

file zipped: c:\programdata\h8srtkrl32mainweq.dll
.
ADS - TEMP: deleted 962 bytes in 7 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\h8srtkrl32mainweq.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-23 to 2010-01-23 )))))))))))))))))))))))))))))))
.

2010-01-23 03:46 . 2010-01-23 03:46 ——– d—–w- c:\users\staples0286\AppData\Local\temp
2010-01-23 03:46 . 2010-01-23 03:46 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-01-23 03:46 . 2010-01-23 03:46 ——– d—–w- c:\users\Guest\AppData\Local\temp
2010-01-23 03:46 . 2010-01-23 03:46 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-23 00:19 . 2010-01-22 15:05 84912 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\NAVENG.SYS
2010-01-23 00:19 . 2010-01-22 15:05 177520 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\NAVENG32.DLL
2010-01-23 00:19 . 2010-01-22 15:05 1647984 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\NAVEX32A.DLL
2010-01-23 00:19 . 2010-01-22 15:05 1323568 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\NAVEX15.SYS
2010-01-23 00:19 . 2010-01-22 15:05 371248 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\EECTRL.SYS
2010-01-23 00:19 . 2010-01-22 15:05 2747440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\CCERASER.DLL
2010-01-23 00:19 . 2010-01-22 15:05 259440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\ECMSVR32.DLL
2010-01-23 00:19 . 2010-01-22 15:05 102448 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100122.025\ERASER.SYS
2010-01-22 20:40 . 2010-01-22 20:40 ——– d—–w- c:\users\staples0286\AppData\Roaming\HPAppData
2010-01-22 15:38 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100119.001\IDSvix86.sys
2010-01-22 15:38 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100119.001\IDSXpx86.sys
2010-01-22 15:38 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100119.001\Scxpx86.dll
2010-01-22 15:38 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100119.001\IDSxpx86.dll
2010-01-22 15:38 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100119.001\IDSviA64.sys
2010-01-22 01:54 . 2009-12-16 11:44 834048 —-a-w- c:\windows\system32\wininet.dll
2010-01-22 01:54 . 2009-12-18 13:01 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-20 22:36 . 2010-01-22 20:43 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-01-20 22:36 . 2010-01-20 22:36 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-20 04:04 . 2010-01-20 04:04 ——– d—–w- C:\cf38c0e4d3e1e1b0ca3e15fbf8dbe6f3
2010-01-20 02:54 . 2010-01-20 14:34 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-20 02:54 . 2009-10-09 02:54 342576 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20090911.001\IDSVix86.sys
2010-01-20 02:54 . 2009-10-09 02:54 329080 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20090911.001\IDSxpx86.sys
2010-01-20 02:54 . 2009-10-09 02:54 466480 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20090911.001\IDSVia64.sys
2010-01-20 02:54 . 2009-10-09 02:54 732536 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20090911.001\Scxpx86.dll
2010-01-20 02:54 . 2009-10-09 02:54 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20090911.001\IDSxpx86.dll
2010-01-20 02:54 . 2009-10-01 09:19 164216 —-a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\components\IPSFFPl.dll
2010-01-20 02:54 . 2010-01-22 14:54 965488 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\OCS\hsplayer.dll
2010-01-20 02:54 . 2009-11-07 01:18 892272 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\CLT\cltLMSx.dll
2010-01-20 02:54 . 2010-01-23 03:28 ——– d—–w- c:\windows\system32\drivers\NAV
2010-01-20 02:54 . 2010-01-20 02:54 ——– d—–w- c:\program files\Norton AntiVirus
2010-01-20 02:54 . 2010-01-20 02:54 ——– d—–w- c:\program files\NortonInstaller
2010-01-20 01:01 . 2010-01-20 01:36 ——– d—–w- c:\users\staples0286\AppData\Local\Tific
2010-01-20 01:01 . 2010-01-20 01:01 ——– d—–w- c:\users\staples0286\AppData\Roaming\Tific
2010-01-19 03:27 . 2010-01-20 23:01 ——– d—–w- c:\programdata\Norton
2010-01-19 02:31 . 2010-01-19 02:31 ——– d—–w- c:\windows\Sun
2010-01-19 02:20 . 2010-01-19 02:21 23090 —-a-w- c:\windows\hpqins15.dat
2010-01-17 16:18 . 2010-01-17 16:18 ——– d—–w- c:\users\staples0286\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-01-13 18:15 . 2009-10-19 13:38 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-13 18:15 . 2009-10-19 13:35 72704 —-a-w- c:\windows\system32\fontsub.dll
2010-01-10 00:10 . 2009-05-18 20:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-10 00:10 . 2008-04-17 19:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-01-10 00:10 . 2010-01-10 00:10 ——– d—–w- c:\program files\iPod
2010-01-10 00:10 . 2010-01-10 00:10 ——– d—–w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-10 00:10 . 2010-01-10 00:10 ——– d—–w- c:\program files\iTunes
2010-01-10 00:08 . 2010-01-10 00:08 ——– d—–w- c:\program files\QuickTime
2010-01-10 00:04 . 2010-01-10 00:04 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2010-01-02 16:38 . 2010-01-02 16:38 1924744 —-a-w- c:\users\staples0286\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-12-27 09:19 . 2009-12-27 09:19 ——– d—–w- c:\program files\Windows Portable Devices
2009-12-27 09:03 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-12-27 09:03 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-12-27 09:03 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2009-12-27 09:01 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-12-27 09:01 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-12-27 09:01 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-12-25 17:32 . 2009-12-25 17:32 ——– d—–w- c:\windows\system32\ca-ES
2009-12-25 17:32 . 2009-12-25 17:32 ——– d—–w- c:\windows\system32\eu-ES
2009-12-25 17:32 . 2009-12-25 17:32 ——– d—–w- c:\windows\system32\vi-VN

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-23 03:27 . 2008-05-29 17:26 12 —-a-w- c:\windows\bthservsdp.dat
2010-01-22 15:13 . 2008-04-25 01:43 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-20 14:34 . 2010-01-20 02:54 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-20 14:34 . 2010-01-20 02:54 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-20 14:34 . 2009-01-13 14:27 ——– d—–w- c:\program files\Symantec
2010-01-20 04:10 . 2008-10-04 01:32 ——– d—–w- c:\users\staples0286\AppData\Roaming\LimeWire
2010-01-20 02:58 . 2009-05-07 03:15 ——– d—–w- c:\programdata\NortonInstaller
2010-01-20 02:53 . 2009-02-16 09:02 50161 —-a-w- c:\programdata\nvModes.dat
2010-01-20 02:34 . 2008-12-26 03:26 1356 —-a-w- c:\users\staples0286\AppData\Local\d3d9caps.dat
2010-01-20 01:31 . 2009-12-21 16:13 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-19 04:49 . 2008-05-29 17:54 ——– d—–w- c:\programdata\NVIDIA
2010-01-19 03:40 . 2009-01-30 21:02 132 —-a-w- c:\users\staples0286\AppData\Roaming\wklnhst.dat
2010-01-19 02:34 . 2008-04-25 03:01 ——– d—–w- c:\program files\Java
2010-01-19 02:20 . 2008-04-25 02:38 ——– d—–w- c:\program files\HP
2010-01-17 16:19 . 2009-09-30 13:00 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-17 16:19 . 2009-09-30 13:00 38784 —-a-w- c:\users\staples0286\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-17 16:19 . 2009-09-30 13:00 38784 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-14 17:12 . 2009-10-05 15:59 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-14 09:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-01-10 00:35 . 2008-09-15 17:18 ——– d—–w- c:\programdata\NOS
2010-01-10 00:10 . 2008-12-25 18:48 ——– d—–w- c:\program files\Common Files\Apple
2009-12-27 09:19 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-12-27 09:18 . 2009-12-27 09:18 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-25 17:32 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-12-25 17:32 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-12-25 17:32 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-12-25 17:32 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-12-25 17:32 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-12-25 17:32 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-12-05 04:54 . 2009-12-05 04:54 529456 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx86.sys
2009-12-05 04:54 . 2009-12-05 04:54 201616 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHRules.dll
2009-12-05 04:54 . 2009-12-05 04:54 1405840 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHEngine.dll
2009-12-05 04:54 . 2009-12-05 04:54 668720 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx64.sys
2009-12-05 04:54 . 2009-12-05 04:54 610704 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\bbRGen.dll
2009-12-03 16:23 . 2008-09-16 17:11 ——– d—–w- c:\program files\Yahoo! Games
2009-11-27 21:26 . 2008-04-25 01:43 ——– d—–w- c:\programdata\Symantec
2009-11-24 17:37 . 2009-05-07 14:43 ——– d—–w- c:\program files\Symantec AntiVirus
2009-11-20 03:12 . 2009-11-20 03:12 1417353 —-a-w- c:\programdata\NeoEdge Networks\Yahoo_FarmFrenzy\IAF.dll
2009-11-09 12:31 . 2009-12-14 23:14 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-14 23:14 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-14 23:14 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-11-28 09:01 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-28 22:37 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-10-28 22:37 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-10-28 22:37 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^staples0286^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\staples0286\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DagentUI]
2007-07-21 01:23 282624 —-a-w- c:\program files\Altiris\Dagent\dagentui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 —-a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-06-16 15:03 75008 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 23:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2007-10-01 23:10 1783136 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-06-02 07:55 80896 —-a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2007-09-13 15:47 480560 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 22:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-24 00:36 455968 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Download Manager{NAV_Production_94_17.1.0.19}]
2010-01-19 03:27 403352 —-a-w- c:\users\Public\Downloads\Norton\{NAV_Production_94_17.1.0.19}\NAVDownloader.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-12-04 08:42 13556256 —-a-w- c:\windows\System32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-12-04 08:42 92704 —-a-w- c:\windows\System32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
2007-09-04 20:54 554320 —-a-w- c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
2007-09-19 21:31 202032 —-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-12-20 02:27 468264 —-a-w- c:\program files\HP\QuickPlay\QPService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 05:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 10:17 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-01-18 11:31 1033512 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-08-17 06:13 218408 ——w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2007-01-08 22:53 311296 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):37,36,8f,1d,89,85,ca,01

R0 SymDS;Symantec Data Store;c:\windows\System32\drivers\NAV\1105000.07F\symds.sys [1/22/2010 10:39 AM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NAV\1105000.07F\symefa.sys [1/22/2010 10:39 AM 172592]
R1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx86.sys [12/4/2009 10:54 PM 529456]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NAV\1105000.07F\cchpx86.sys [1/22/2010 10:39 AM 501888]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100119.001\IDSvix86.sys [1/22/2010 9:38 AM 343088]
R1 SymIRON;Symantec Iron Driver;c:\windows\System32\drivers\NAV\1105000.07F\ironx86.sys [1/22/2010 10:39 AM 116272]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\drivers\NAV\1105000.07F\symtdiv.sys [1/22/2010 10:39 AM 340016]
R2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.5.0.127\ccsvchst.exe [1/22/2010 10:39 AM 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/22/2010 6:19 PM 102448]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [1/20/2010 4:36 PM 1153368]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 8:23 PM 21504]
S4 Altiris Deployment Agent;Altiris Deployment Agent;c:\program files\Altiris\Dagent\dagent.exe [7/20/2007 7:17 PM 356352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-24 00:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=81&bd;=Pavilion&pf;=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=81&bd;=Pavilion&pf;=laptop
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\staples0286\AppData\Roaming\Mozilla\Firefox\Profiles\sxjenp9w.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npraclient.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\programdata\RealArcade\npraclient.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-22 21:46
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.5.0.127\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-22 21:48:37
ComboFix-quarantined-files.txt 2010-01-23 03:48
ComboFix2.txt 2010-01-22 15:02

Pre-Run: 104,436,883,456 bytes free
Post-Run: 104,402,739,200 bytes free

- - End Of File - - 12549D0F6B923012E7531B3CC09F5D3E
Upload was successful
Hi,

See if you can browse through BleepingComputer then please post here what happens.

–Next–

Download TFC to your desktop
  • Close any open windows.
  • Right click the TFC icon then choose "Run as Administrator" to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
–Next–

Please download Malwarebytes' Anti-Malware to your desktop.
  • Right-click mbam-setup.exe then choose "Run as Administrator" and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

–Next–

Run an on-line scan with Kaspersky

Right click Internet Explorer or Firefox then choose "Run as Administrator" to run the program.

NOTE: After scanning with Kaspersky, close your browser then run it without administrator privileges for your browsing.

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
–Next–

Let's do another OTL scan please.
  • Right click OTL.exe then choose "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • There will only be a single log produced. OTL.Txt.
    Note:This log can be located in the OTL. folder on you C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
To post in your next reply:
1, Malwarebytes' log.
2. Kaspersky log.
3. OTL log.
4. How is your computer?
Hi, alright I can finally access BleepingComputer's domain and my computer is running great! Here are the MalwareBytes, Kaspersky, and OTL logs:

Malwarebytes' Anti-Malware 1.44
Database version: 3631
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

1/24/2010 8:38:37 PM
mbam-log-2010-01-24 (20-38-37).txt

Scan type: Quick Scan
Objects scanned: 109634
Time elapsed: 5 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\WS9E3IQBKY (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Guest\Desktop\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Users\Guest\Desktop\Malware Defense Support.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.



——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, January 25, 2010
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, January 25, 2010 02:44:25
Records in database: 3367412
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 200149
Threats found: 2
Infected objects found: 2
Suspicious objects found: 0
Scan duration: 03:21:42


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll.vir Infected: not-a-virus:WebToolbar.Win32.Zango.ce 1
C:\Users\staples0286\Desktop\Missy's Stuff\Incomplete\T-5859244-twisted chipmunk song.au Infected: Trojan-Downloader.WMA.GetCodec.s 1

Selected area has been scanned.


OTL logfile created on: 1/25/2010 8:36:35 AM - Run 2
OTL by OldTimer - Version 3.1.25.4 Folder = C:\Users\staples0286\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 174.47 Gb Total Space | 92.74 Gb Free Space | 53.16% Space Free | Partition Type: NTFS
Drive D: | 11.84 Gb Total Space | 2.00 Gb Free Space | 16.90% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STAPLES0286-PC
Current User Name: staples0286
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\staples0286\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\staples0286\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Altiris Deployment Agent) – File not found
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe (Symantec Corporation)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (nvsvc) – C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12) – C:\Windows\System32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – C:\Windows\System32\HPZinw12.dll (Hewlett-Packard)
SRV - (HP Health Check Service) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (QPCapSvc) QuickPlay Background Capture Service (QBCS) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
SRV - (QPSched) QuickPlay Task Scheduler (QTS) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (GameConsoleService) – C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (XAudioService) – C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (ehstart) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (hpqwmiex) – C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100124.021\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100124.021\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (ccHP) – C:\Windows\system32\drivers\NAV\1105000.07F\ccHPx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NAV\1105000.07F\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NAV\1105000.07F\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NAV\1105000.07F\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\NAV\1105000.07F\Ironx86.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\NAV\1105000.07F\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\NAV\1105000.07F\SYMDS.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100119.001\IDSvix86.sys (Symantec Corporation)
DRV - (GEARAspiWDM) – C:\Windows\System32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (USBAAPL) – C:\Windows\System32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (btwavdt) – C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwaudio) – C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (btwrchid) – C:\Windows\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpqRemHid) – C:\Windows\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (BCM43XV) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (secdrv) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (mdmxsdk) – C:\Windows\System32\drivers\mdmxsdk.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.1
FF - prefs.js..extensions.enabledItems: [removed]:4.60
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/18 20:20:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\ [2010/01/22 08:38:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/09 18:08:34 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/22 08:50:29 | 00,000,000 | —D | M]

[2008/09/15 10:06:02 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\mozilla\Extensions
[2010/01/24 22:43:32 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\mozilla\Firefox\Profiles\sxjenp9w.default\extensions
[2009/08/26 06:49:44 | 00,000,000 | —D | M] (Forecastfox) – C:\Users\staples0286\AppData\Roaming\mozilla\Firefox\Profiles\sxjenp9w.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010/01/18 20:45:29 | 00,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\staples0286\AppData\Roaming\mozilla\Firefox\Profiles\sxjenp9w.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/07/04 11:39:25 | 00,000,000 | —D | M] (IE View) – C:\Users\staples0286\AppData\Roaming\mozilla\Firefox\Profiles\sxjenp9w.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2009/05/06 20:32:49 | 00,000,247 | —- | M] () – C:\Users\staples0286\AppData\Roaming\Mozilla\FireFox\Profiles\sxjenp9w.default\searchplugins\Yoog Search.xml
[2010/01/23 22:31:07 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/04/28 11:14:21 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/03/30 16:13:54 | 00,098,304 | —- | M] (RealNetworks) – C:\Program Files\Mozilla Firefox\plugins\npraclient.dll

O1 HOSTS File: ([2010/01/22 08:54:42 | 00,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/24 20:23:11 | 00,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 09:18:54 | 00,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/24 20:42:30 | 00,000,000 | —D | C] – C:\ProgramData\Office Genuine Advantage
[2010/01/24 20:31:46 | 00,000,000 | —D | C] – C:\Users\staples0286\AppData\Roaming\Malwarebytes
[2010/01/24 20:31:39 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/24 20:31:37 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/01/24 20:31:37 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/01/24 20:31:36 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/24 20:29:51 | 05,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Users\staples0286\Desktop\mbam-setup.exe
[2010/01/24 20:19:40 | 00,439,808 | —- | C] (OldTimer Tools) – C:\Users\staples0286\Desktop\TFC.exe
[2010/01/22 21:49:21 | 00,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/01/22 21:49:17 | 00,000,000 | —D | C] – C:\Windows\temp
[2010/01/22 21:49:17 | 00,000,000 | —D | C] – C:\Users\staples0286\AppData\Local\temp
[2010/01/22 21:38:47 | 00,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/01/22 14:41:11 | 00,000,000 | —D | C] – C:\Users\staples0286\Documents\Symantec
[2010/01/22 14:40:10 | 00,000,000 | —D | C] – C:\Users\staples0286\AppData\Roaming\HPAppData
[2010/01/22 10:39:20 | 00,340,016 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1105000.07F\symtdiv.sys
[2010/01/22 10:39:19 | 00,328,752 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1105000.07F\symds.sys
[2010/01/22 10:39:19 | 00,325,168 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1105000.07F\srtsp.sys
[2010/01/22 10:39:19 | 00,172,592 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1105000.07F\symefa.sys
[2010/01/22 10:39:19 | 00,116,272 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1105000.07F\ironx86.sys
[2010/01/22 10:39:19 | 00,043,696 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1105000.07F\srtspx.sys
[2010/01/22 10:39:18 | 00,501,888 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1105000.07F\cchpx86.sys
[2010/01/22 10:39:04 | 00,000,000 | —D | C] – C:\Windows\System32\drivers\NAV\1105000.07F
[2010/01/22 08:35:08 | 00,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/01/22 08:35:08 | 00,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/01/22 08:35:08 | 00,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/01/22 08:34:59 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2010/01/22 08:34:49 | 00,000,000 | —D | C] – C:\Qoobox
[2010/01/21 20:35:45 | 00,472,064 | —- | C] ( ) – C:\Users\staples0286\Desktop\RootRepeal.exe
[2010/01/21 20:21:34 | 00,547,840 | —- | C] (OldTimer Tools) – C:\Users\staples0286\Desktop\OTL.exe
[2010/01/21 19:54:03 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/01/21 19:54:02 | 00,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/01/21 19:54:02 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/01/21 19:54:01 | 00,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/01/20 16:36:23 | 00,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/01/20 16:36:23 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/01/19 22:04:14 | 00,000,000 | —D | C] – C:\cf38c0e4d3e1e1b0ca3e15fbf8dbe6f3
[2010/01/19 22:03:29 | 10,038,728 | —- | C] (Microsoft Corporation) – C:\Users\staples0286\Desktop\windows-kb890830-v3.3.exe
[2010/01/19 21:34:43 | 00,000,000 | —D | C] – C:\Windows\pss
[2010/01/19 20:54:58 | 00,124,976 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/01/19 20:54:36 | 00,000,000 | —D | C] – C:\Program Files\Norton AntiVirus
[2010/01/19 20:54:36 | 00,000,000 | —D | C] – C:\Windows\System32\drivers\NAV
[2010/01/19 20:54:20 | 00,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2010/01/19 19:01:52 | 00,000,000 | —D | C] – C:\Users\staples0286\AppData\Local\Tific
[2010/01/19 19:01:49 | 00,000,000 | —D | C] – C:\Users\staples0286\AppData\Roaming\Tific
[2010/01/18 21:27:27 | 00,000,000 | —D | C] – C:\ProgramData\Norton
[2010/01/18 20:34:57 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/01/18 20:34:57 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/01/18 20:34:57 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/01/18 20:31:02 | 00,000,000 | —D | C] – C:\Windows\Sun
[2010/01/17 10:18:30 | 00,000,000 | —D | C] – C:\Users\staples0286\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/01/13 12:15:15 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/01/13 12:15:15 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/01/09 18:10:47 | 00,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/01/09 18:10:47 | 00,026,600 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\drivers\GEARAspiWDM.sys
[2010/01/09 18:10:02 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2010/01/09 18:10:00 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2010/01/09 18:10:00 | 00,000,000 | —D | C] – C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/01/09 18:08:10 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2009/12/27 03:19:07 | 00,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2009/12/27 03:03:15 | 03,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2009/12/27 03:03:15 | 01,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2009/12/27 03:03:15 | 00,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2009/12/27 03:02:51 | 00,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2009/12/27 03:02:50 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2009/12/27 03:02:48 | 00,974,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/12/27 03:02:48 | 00,829,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2009/12/27 03:02:48 | 00,828,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2009/12/27 03:02:48 | 00,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/12/27 03:02:48 | 00,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/12/27 03:02:48 | 00,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2009/12/27 03:02:48 | 00,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2009/12/27 03:02:48 | 00,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2009/12/27 03:02:48 | 00,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/12/27 03:02:48 | 00,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2009/12/27 03:02:48 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/12/27 03:02:47 | 01,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2009/12/27 03:02:47 | 01,064,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2009/12/27 03:02:47 | 01,030,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2009/12/27 03:02:47 | 00,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2009/12/27 03:02:47 | 00,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FntCache.dll
[2009/12/27 03:02:47 | 00,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2009/12/27 03:02:47 | 00,486,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2009/12/27 03:02:47 | 00,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2009/12/27 03:02:47 | 00,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2009/12/27 03:02:47 | 00,218,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2009/12/27 03:02:47 | 00,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2009/12/27 03:02:47 | 00,161,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2009/12/27 03:02:24 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BthMtpContextHandler.dll
[2009/12/27 03:02:24 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2009/12/27 03:02:21 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceConnectApi.dll
[2009/12/27 03:02:19 | 00,546,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2009/12/27 03:02:19 | 00,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/12/27 03:02:19 | 00,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2009/12/27 03:02:19 | 00,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2009/12/27 03:02:19 | 00,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/12/27 03:02:18 | 00,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2009/12/27 03:01:30 | 00,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2009/12/27 03:01:30 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll

========== Files - Modified Within 30 Days ==========

[2010/01/25 08:36:34 | 02,621,440 | -HS- | M] () – C:\Users\staples0286\ntuser.dat
[2010/01/25 06:41:26 | 00,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/01/25 06:41:26 | 00,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/01/25 00:36:46 | 01,868,624 | —- | M] () – C:\Windows\System32\drivers\NAV\1105000.07F\Cat.DB
[2010/01/24 20:47:25 | 00,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/01/24 20:47:25 | 00,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/01/24 20:47:25 | 00,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/01/24 20:41:27 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/01/24 20:41:23 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/01/24 20:40:55 | 31,529,28768 | -HS- | M] () – C:\hiberfil.sys
[2010/01/24 20:39:34 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/01/24 20:39:32 | 00,524,288 | -HS- | M] () – C:\Users\staples0286\ntuser.dat{b6bf0ebf-b748-11de-9c29-00218603c4a3}.TMContainer00000000000000000001.regtrans-ms
[2010/01/24 20:39:32 | 00,065,536 | -HS- | M] () – C:\Users\staples0286\ntuser.dat{b6bf0ebf-b748-11de-9c29-00218603c4a3}.TM.blf
[2010/01/24 20:39:31 | 02,391,429 | -H– | M] () – C:\Users\staples0286\AppData\Local\IconCache.db
[2010/01/24 20:31:44 | 00,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/24 20:30:24 | 05,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Users\staples0286\Desktop\mbam-setup.exe
[2010/01/24 20:20:03 | 00,439,808 | —- | M] (OldTimer Tools) – C:\Users\staples0286\Desktop\TFC.exe
[2010/01/24 18:55:22 | 00,008,192 | —- | M] () – C:\Users\staples0286\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/23 20:30:05 | 00,001,961 | —- | M] () – C:\Users\Public\Desktop\Fairy Godmother Tycoon.lnk
[2010/01/23 20:26:46 | 00,001,726 | —- | M] () – C:\Users\Public\Desktop\More Yahoo! Games.lnk
[2010/01/22 21:46:36 | 00,000,215 | —- | M] () – C:\Windows\system.ini
[2010/01/22 21:28:16 | 00,002,136 | —- | M] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2010/01/22 08:54:42 | 00,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/01/22 08:33:41 | 03,833,308 | R— | M] () – C:\Users\staples0286\Desktop\SubsFix.exe
[2010/01/22 08:30:46 | 00,100,908 | —- | M] () – C:\Users\staples0286\Desktop\SystemLook.exe
[2010/01/21 20:36:36 | 00,000,000 | —- | M] () – C:\Users\staples0286\Desktop\settings.dat
[2010/01/21 20:35:46 | 00,472,064 | —- | M] ( ) – C:\Users\staples0286\Desktop\RootRepeal.exe
[2010/01/21 20:21:35 | 00,547,840 | —- | M] (OldTimer Tools) – C:\Users\staples0286\Desktop\OTL.exe
[2010/01/20 17:15:47 | 00,290,816 | —- | M] () – C:\Users\staples0286\Desktop\exeHelper.com
[2010/01/20 17:13:36 | 00,293,376 | —- | M] () – C:\Users\staples0286\Desktop\gmer.exe
[2010/01/20 17:13:28 | 00,284,915 | —- | M] () – C:\Users\staples0286\Desktop\gmer.zip
[2010/01/20 17:01:14 | 00,000,853 | —- | M] () – C:\Users\staples0286\Desktop\Norton Installation Files.lnk
[2010/01/20 16:36:29 | 00,001,055 | —- | M] () – C:\Users\staples0286\Desktop\Spybot - Search & Destroy.lnk
[2010/01/20 08:34:13 | 00,124,976 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/01/20 08:34:13 | 00,007,443 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/01/20 08:34:13 | 00,000,805 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2010/01/19 22:03:42 | 10,038,728 | —- | M] (Microsoft Corporation) – C:\Users\staples0286\Desktop\windows-kb890830-v3.3.exe
[2010/01/19 20:53:04 | 00,050,161 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/01/19 20:53:04 | 00,050,161 | —- | M] () – C:\ProgramData\nvModes.001
[2010/01/19 20:52:59 | 00,000,258 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2010/01/19 20:34:25 | 00,001,356 | —- | M] () – C:\Users\staples0286\AppData\Local\d3d9caps.dat
[2010/01/18 21:40:33 | 00,000,132 | —- | M] () – C:\Users\staples0286\AppData\Roaming\wklnhst.dat
[2010/01/18 20:31:08 | 00,000,008 | —- | M] () – C:\ProgramData\sysReserve.ini
[2010/01/18 20:21:26 | 00,023,090 | —- | M] () – C:\Windows\hpqins15.dat
[2010/01/14 11:12:06 | 00,181,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/01/09 18:10:51 | 00,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/01/09 18:08:27 | 00,001,726 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/12/27 20:49:58 | 00,127,029 | —- | M] () – C:\Users\staples0286\Desktop\CS-Coordinator.pdf
[2009/12/27 03:18:50 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf

========== Files Created - No Company Name ==========

[2010/01/24 20:31:44 | 00,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/23 20:30:05 | 00,001,961 | —- | C] () – C:\Users\Public\Desktop\Fairy Godmother Tycoon.lnk
[2010/01/23 20:26:46 | 00,001,726 | —- | C] () – C:\Users\Public\Desktop\More Yahoo! Games.lnk
[2010/01/22 21:27:56 | 01,868,624 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\Cat.DB
[2010/01/22 10:39:20 | 00,001,473 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symnetv.inf
[2010/01/22 10:39:19 | 00,007,787 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symnetv.cat
[2010/01/22 10:39:19 | 00,007,444 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symefa.cat
[2010/01/22 10:39:19 | 00,007,442 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\srtspx.cat
[2010/01/22 10:39:19 | 00,007,438 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\srtsp.cat
[2010/01/22 10:39:19 | 00,007,438 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\iron.cat
[2010/01/22 10:39:19 | 00,007,425 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symds.cat
[2010/01/22 10:39:19 | 00,007,368 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symnet.cat
[2010/01/22 10:39:19 | 00,003,374 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symefa.inf
[2010/01/22 10:39:19 | 00,002,793 | R— | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symds.inf
[2010/01/22 10:39:19 | 00,001,445 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\symnet.inf
[2010/01/22 10:39:19 | 00,001,388 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\srtspx.inf
[2010/01/22 10:39:19 | 00,001,382 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\srtsp.inf
[2010/01/22 10:39:19 | 00,000,742 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\iron.inf
[2010/01/22 10:39:18 | 00,007,396 | R— | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\cchpx86.cat
[2010/01/22 10:39:18 | 00,001,756 | R— | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\cchpx86.inf
[2010/01/22 10:39:04 | 00,000,172 | —- | C] () – C:\Windows\System32\drivers\NAV\1105000.07F\isolate.ini
[2010/01/22 08:35:08 | 00,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010/01/22 08:35:08 | 00,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/01/22 08:35:08 | 00,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/01/22 08:35:08 | 00,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/01/22 08:35:08 | 00,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/01/22 08:33:41 | 03,833,308 | R— | C] () – C:\Users\staples0286\Desktop\SubsFix.exe
[2010/01/22 08:30:44 | 00,100,908 | —- | C] () – C:\Users\staples0286\Desktop\SystemLook.exe
[2010/01/21 20:36:36 | 00,000,000 | —- | C] () – C:\Users\staples0286\Desktop\settings.dat
[2010/01/20 17:15:47 | 00,290,816 | —- | C] () – C:\Users\staples0286\Desktop\exeHelper.com
[2010/01/20 17:13:26 | 00,284,915 | —- | C] () – C:\Users\staples0286\Desktop\gmer.zip
[2010/01/20 17:02:35 | 31,529,28768 | -HS- | C] () – C:\hiberfil.sys
[2010/01/20 16:36:29 | 00,001,055 | —- | C] () – C:\Users\staples0286\Desktop\Spybot - Search & Destroy.lnk
[2010/01/19 20:54:58 | 00,007,443 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/01/19 20:54:58 | 00,000,805 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2010/01/19 20:54:50 | 00,002,136 | —- | C] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2010/01/18 21:27:28 | 00,000,853 | —- | C] () – C:\Users\staples0286\Desktop\Norton Installation Files.lnk
[2010/01/18 20:31:08 | 00,000,008 | —- | C] () – C:\ProgramData\sysReserve.ini
[2010/01/18 20:20:42 | 00,023,090 | —- | C] () – C:\Windows\hpqins15.dat
[2010/01/09 18:10:51 | 00,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/01/09 18:08:27 | 00,001,726 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2009/12/27 20:49:57 | 00,127,029 | —- | C] () – C:\Users\staples0286\Desktop\CS-Coordinator.pdf
[2009/12/27 03:18:50 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009/10/23 10:05:19 | 00,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 00,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/02/16 03:02:50 | 00,050,161 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/02/16 03:02:50 | 00,050,161 | —- | C] () – C:\ProgramData\nvModes.001
[2009/01/30 15:02:21 | 00,000,132 | —- | C] () – C:\Users\staples0286\AppData\Roaming\wklnhst.dat
[2008/12/25 21:26:06 | 00,001,356 | —- | C] () – C:\Users\staples0286\AppData\Local\d3d9caps.dat
[2008/10/02 09:49:39 | 00,008,192 | —- | C] () – C:\Users\staples0286\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/26 21:34:41 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/09/15 20:54:14 | 00,049,273 | —- | C] () – C:\Users\staples0286\AppData\Roaming\nvModes.001
[2008/09/15 19:54:13 | 00,049,273 | —- | C] () – C:\Users\staples0286\AppData\Roaming\nvModes.dat
[2008/07/01 01:08:18 | 00,000,000 | —- | C] () – C:\Users\staples0286\AppData\Local\QSwitch.txt
[2008/07/01 01:08:18 | 00,000,000 | —- | C] () – C:\Users\staples0286\AppData\Local\DSwitch.txt
[2008/07/01 01:08:18 | 00,000,000 | —- | C] () – C:\Users\staples0286\AppData\Local\AtStart.txt
[2008/05/29 11:34:05 | 00,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2008/04/24 20:38:18 | 00,000,740 | —- | C] () – C:\ProgramData\hpzinstall.log
[2007/09/05 13:52:04 | 00,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 06:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 03:58:00 | 01,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 01,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2010/01/17 10:18:30 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/06/18 20:47:49 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\eGames
[2010/01/24 20:19:59 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\LimeWire
[2008/09/29 14:36:40 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\Magic Academy
[2009/05/20 22:14:33 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\PDF reDirect
[2009/09/24 09:31:19 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\Peace Craft
[2009/06/18 19:19:59 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\PlayFirst
[2009/06/13 20:28:19 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\Playrix Entertainment
[2009/05/02 08:24:24 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\SpinTop
[2009/01/30 15:02:21 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\Template
[2010/01/19 19:01:49 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\Tific
[2009/08/18 17:43:13 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\UClick
[2009/06/10 11:02:22 | 00,000,000 | —D | M] – C:\Users\staples0286\AppData\Roaming\Yahoo Ashtons Family Resort
[2010/01/24 20:39:35 | 00,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
Hi,

Right click OTL.exe then choose "Run as Administrator" to run the tool.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    
    :Files
    C:\Users\staples0286\Desktop\Missy's Stuff\Incomplete\T-5859244-twisted chipmunk song.au
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
To post in your next reply:
1. OTL log.
2. How is your computer?
Hi, My computer's been running great but I ran OTL again and this is what I got: All processes killed ========== OTL ========== No active process named explorer.exe was found! ========== FILES ========== C:\Users\staples0286\Desktop\Missy's Stuff\Incomplete\T-5859244-twisted chipmunk song.au moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: staples0286 ->Temp folder emptied: 37392 bytes ->Temporary Internet Files folder emptied: 141408 bytes ->Java cache emptied: 143255 bytes ->FireFox cache emptied: 82675841 bytes ->Google Chrome cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 535852 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 80.00 mb OTL by OldTimer - Version 3.1.25.4 log created on 01282010_083907 Files\Folders moved on Reboot… File\Folder C:\Windows\temp\TMP00000014AB6F3203347B5124 not found! Registry entries deleted on Reboot…
Hi,

Your computer now looks clean! :thumbup:

Please delete DDS, GMER, exeHelper, RootRepeal, Systemlook and all the logs we've created.

–Next–

Clean up with OTL:
  • Right-click OTL.exe then choose "Run as Administrator" to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
–Next–

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

[external image: Posted Image]

You can keep TFC and use it to clean your computer of some junk atleast once a week. You can also keep Malwarebytes, it is an excellent malware removal tool. Update atleast once a week then run a complete scan.

–Next–

Java
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
The latest update is Java 6 update 18

To keep your operating system up to date visit
  • Secunia Software inspector to check your program update status.
  • Microsoft Windows Update .

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

6. SpywareBlaster - Download and install SpywareBlaster. This program prevents the installation of ActiveX-based spyware and other potentially unwanted programs.

7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

8. Some excellent free firewalls. Note: Use only one firewall at a time.
Agnitum Outpost Firewall
Comodo Firewall - If you are installing this and already have an anti spyware then please do not install Comodo's anti spyware program.
Online Armor Personal Firewall

9. And finally, please read these excellent articles:
Malware: Help prevent the Infection by Sandi Hardmeier,
Preventing Malware - Tools and Practices for Safe Computing

For more safe computing tips please read the guide by Rorschach112 on how to prevent malware and about safe computing here.



Good luck, happy computing and stay clean! ^_^

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI