This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Various Infections - such as rootkit

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Currently Malwarebytes will not run properly. In Safe Mode if I change mbam.exe to xxxx.exe it seem to run a little bit, but after a few minutes the computer freezes. I could get a quick scan started and then abort it after it finds 4 infections. If I let the scan run any further the computer freezes. Malwarebytes cannot remove the files straight away but suggests a reboot, however upon reboot they are still there. attached is the log for the short period I can run it. I also thought that a HiJacksthis log might help you guys as well. Thanks heaps in advance.
Hi,

Please do the following:



Download Combofix from either of the links below. You must rename it to combo.exe before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.

    ———————————————————–

  • Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–

Thank you very much for picking up the thread. The computer that has the virus currently is not connected to the internet at all so we are using a USB stick. We renamed the .exe file and put it onto the desktop of the computer with the virus. When double clicking on the .exe a small window with a progress bar appears and goes from 0 to 100%. The windows hourglass/mouse appears. A window appears to be opening as the taskbar shows combofix starting (but I never see a window) but then after a few seconds it closes and nothing more happens.
Hi, Try running ComboFix directly from the USB stick - did you rename it? that's very important rename it before saving it to the USB Try running it in safe mode also. If it still will not run…bring up your task manager (Ctrl + Alt + Del) and list out the processes for me…I'll let you know if there is anything there we can end that maybe stopping ComboFox from running
Yes I am changing the name of Combofix.exe before downloading it onto the USB.

Exactly the same thing happens irrespective of whether I start it on the desktop or usb and whether I start it in normal mode or Safe Mode.

Following on from your suggestion about processes I have also tried to remove all process first except for these

taskmgr.exe
explorer.exe
svchost.exe - a few
spoolsv.exe
lsass.exe
services.exe
winlogon.exe
csrss.exe
smss.exe
System Idle Process


There is a System in the processes which will not end as well.

combofix still does not start. After it has run the following processes are added to the above

cmd.cfxxe
pev.exe
iexplore.exe
iexplore.exe
ctfmin.exe

by the way there is a folder in C drive named 32788R22FWJFW - this seems to have many little programs in it which are running. Like iexplore.exe pev.exe and cmd.cfxxe
OK,

Let's try this program instead:

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Thank you again for replying so quickly. OTL worked. B)

OTL logfile created on: 02.02.2010 14:31:45 - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Mayte\Desktop
Windows XP Home Edition Service Pack 3, v.5657 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 16,54 Gb Free Space | 22,19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,92 Gb Total Space | 1,92 Gb Free Space | 99,72% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MAYTE-9BDDE8BE8
Current User Name: Mayte
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Mayte\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Mayte\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.3264_x-ww_d751ffbf\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\linkinfo.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (HauppaugeTVServer) – C:\Program Files\WinTV\HCWTVServer.exe (Hauppauge Computer Works)
SRV - (EPGService) – C:\Program Files\WinTV\EPG Services\System\EPGService.exe (Hauppauge Computer Works)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (USBAAPL) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (N) – C:\Program Files\NewTech Infosystems\NTI Ripper\ [2009.06.16 06:44:24 | 000,000,000 | —D | M]
DRV - (NinjaUSB) – C:\WINDOWS\system32\drivers\NinjaUSB.sys ()
DRV - (GEARAspiWDM) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (CVPNDRVA) – C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (hcw95rc) – C:\WINDOWS\system32\drivers\hcw95rc.sys (Hauppauge Computer Works, Inc.)
DRV - (hcw95bda) – C:\WINDOWS\system32\drivers\hcw95bda.sys (Hauppauge Computer Works, Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (ElbyDelay) – C:\WINDOWS\system32\drivers\ElbyDelay.sys (Elaborate Bytes AG)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (PID_08A0) QuickCam IM(PID_08A0) – C:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVEzLoader) LifeView EZ-USB FX2 FIRMWARE LOADER (LVEzLD06.sys) – C:\WINDOWS\system32\drivers\LVEzLD06.sys (Animation Technologies Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs LLC)
DRV - (cercsr6) – C:\WINDOWS\system32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000005
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..network.proxy.http: "63.148.167.30"
FF - prefs.js..network.proxy.http_port: 1080
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2010.01.14 15:20:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.01.16 11:40:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.01.16 11:40:16 | 000,000,000 | —D | M]

[2008.12.24 08:22:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Mozilla\Extensions
[2010.01.26 21:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions
[2009.06.16 09:29:43 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009.09.23 23:10:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions\[removed]
[2009.11.15 11:07:16 | 000,002,163 | —- | M] () – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\searchplugins\bing.xml
[2010.01.26 21:16:32 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008.05.25 19:07:26 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008.03.24 19:21:00 | 002,889,088 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll

O1 HOSTS File: ([2004.08.04 11:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Spy Blocker BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EPGServiceTool] C:\Program Files\WinTV\EPG Services\System\EPGClient.exe (Hauppauge Inc.)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\xxxx.exe File not found
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Password.lnk = C:\Documents and Settings\Mayte\Local Settings\Temp\Password.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr =
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.01.05 15:12:33 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008.07.29 12:34:02 | 000,000,000 | RHSD | M] - E:\AutoRun – [ FAT ]
O33 - MountPoints2\{4af5fa13-5993-11de-b4b2-00123f82a435}\Shell - "" = AutoRun
O33 - MountPoints2\{4af5fa13-5993-11de-b4b2-00123f82a435}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8c3af734-f2f9-11dc-bf8e-00123f82a435}\Shell - "" = AutoRun
O33 - MountPoints2\{8c3af734-f2f9-11dc-bf8e-00123f82a435}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.01.05 00:37:22 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error starting restore point: 31
Error closing restore point: The sequence number is invalid.

========== Files/Folders - Created Within 30 Days ==========

[2010.02.02 14:26:47 | 000,548,864 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mayte\Desktop\OTL.exe
[2010.02.02 11:13:32 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010.01.28 14:19:14 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010.01.28 11:06:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Mayte\Application Data\Malwarebytes
[2010.01.28 10:57:51 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.01.28 10:57:47 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010.01.28 10:57:47 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010.01.28 10:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.01.27 21:46:30 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\mbam-setup(2).exe
[2010.01.27 21:39:47 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\xxxx.exe
[2010.01.27 00:27:37 | 000,000,000 | —D | C] – C:\Program Files\Malware Defense
[2010.01.26 22:21:38 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010.01.26 22:21:38 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010.01.26 22:21:38 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010.01.26 22:21:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008.04.14 22:16:13 | 022,744,616 | —- | C] (Macrovision Corporation) – C:\Program Files\ElsterFormular2007-Setup.exe
[2008.03.03 12:06:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008.01.05 22:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2008.01.05 22:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intel
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.02.02 14:22:38 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mayte\Desktop\OTL.exe
[2010.02.02 14:16:27 | 000,002,447 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2010.02.02 14:15:49 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010.02.02 14:15:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010.02.02 11:20:14 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Mayte\ntuser.ini
[2010.02.02 11:20:13 | 006,029,312 | -H– | M] () – C:\Documents and Settings\Mayte\NTUSER.DAT
[2010.02.01 14:20:10 | 003,841,968 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\combo.exe
[2010.02.01 14:00:32 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010.01.28 14:19:14 | 000,001,742 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\HijackThis.lnk
[2010.01.28 10:57:55 | 000,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.28 10:48:08 | 000,001,188 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-789336058-839522115-1004UA.job
[2010.01.27 21:46:30 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\mbam-setup(2).exe
[2010.01.27 21:40:00 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\xxxx.exe
[2010.01.27 00:27:50 | 000,001,611 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk
[2010.01.27 00:27:50 | 000,000,705 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk
[2010.01.26 22:27:15 | 000,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010.01.26 21:50:23 | 000,000,008 | —- | M] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2010.01.26 21:07:32 | 000,468,864 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010.01.26 21:07:32 | 000,401,364 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010.01.26 21:07:32 | 000,061,374 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010.01.26 20:51:12 | 054,686,882 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010.01.26 20:51:12 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010.01.26 08:37:33 | 000,001,136 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-789336058-839522115-1004Core.job
[2010.01.07 16:07:14 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.01.07 16:07:04 | 000,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.02.01 14:21:41 | 003,841,968 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\combo.exe
[2010.01.28 14:19:14 | 000,001,742 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\HijackThis.lnk
[2010.01.28 10:57:55 | 000,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.27 00:27:50 | 000,001,611 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk
[2010.01.27 00:27:50 | 000,000,705 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk
[2010.01.26 21:50:10 | 000,000,008 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009.06.16 06:42:40 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIRIPPER.dll
[2009.06.16 06:32:21 | 000,024,704 | —- | C] () – C:\WINDOWS\System32\drivers\NinjaUSB.sys
[2008.07.04 00:04:14 | 011,132,416 | —- | C] () – C:\Program Files\vpnclient-win-msi-5.0.03.0530-k9.exe
[2008.05.22 00:45:33 | 003,168,683 | —- | C] () – C:\Program Files\SopCast.zip
[2008.04.17 08:08:56 | 000,197,408 | —- | C] () – C:\WINDOWS\System32\vpnapi.dll
[2008.04.17 08:08:44 | 000,193,312 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2008.03.07 22:41:04 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008.02.29 19:55:00 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\UNWISE.INI
[2008.02.29 19:51:21 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dmcrypto.dll
[2008.02.29 19:50:34 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\hcwChDB.dll
[2008.02.29 19:49:48 | 000,006,741 | —- | C] () – C:\WINDOWS\HCWPNP.INI
[2008.02.29 19:47:43 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008.01.31 05:30:58 | 000,120,320 | —- | C] () – C:\Documents and Settings\Mayte\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.31 05:25:34 | 000,029,480 | —- | C] () – C:\WINDOWS\System32\InstHelper.dll
[2008.01.11 23:35:44 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008.01.11 23:35:43 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008.01.11 07:05:42 | 000,001,751 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008.01.08 22:14:13 | 000,000,131 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008.01.05 23:19:48 | 000,009,255 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008.01.05 23:19:31 | 000,000,260 | —- | C] () – C:\WINDOWS\_delis32.ini
[2008.01.05 23:08:58 | 000,000,483 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003.01.08 00:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2008.04.14 22:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ElsterFormular
[2008.04.10 07:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FlashFXP
[2008.04.07 22:11:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fotobuch.de AG
[2008.01.08 22:46:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008.01.08 22:28:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009.11.29 22:40:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.06.17 07:20:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\EBookSys
[2008.04.07 22:11:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\fotobuch.de AG
[2008.03.07 22:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\InterVideo
[2009.06.16 00:35:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Printer Info Cache

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004.08.04 11:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2007.11.30 17:31:08 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=A42ABFAEE59A1DC0E47014E7B5D76AD6 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2007.11.30 17:31:08 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=A42ABFAEE59A1DC0E47014E7B5D76AD6 – C:\WINDOWS\system32\dllcache\agp440.sys
[2007.11.30 17:31:08 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=A42ABFAEE59A1DC0E47014E7B5D76AD6 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004.08.04 11:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2007.11.30 17:24:44 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=335BB30ED68CF3DC0EE2BDDB438B6A9B – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2007.11.30 17:24:44 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=335BB30ED68CF3DC0EE2BDDB438B6A9B – C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004.08.04 11:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2007.12.01 00:25:36 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=086FFA8479114AE3ECE616D7EB848577 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2007.12.01 00:25:36 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=086FFA8479114AE3ECE616D7EB848577 – C:\WINDOWS\system32\eventlog.dll
[2008.04.14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2004.08.04 11:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2006.05.11 17:30:52 | 000,247,808 | —- | M] (Intel Corporation) MD5=294110966CEDD127629C5BE48367C8CF – C:\WINDOWS\dell\iastor\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008.04.14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2007.12.01 00:25:48 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=327309E36308F9DFB8D4699DF384D421 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2007.12.01 00:25:48 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=327309E36308F9DFB8D4699DF384D421 – C:\WINDOWS\system32\netlogon.dll
[2004.08.04 11:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2006.03.17 01:51:32 | 000,099,840 | —- | M] (NVIDIA Corporation) MD5=B7FB72492B753930EC70A0F49D04F12F – C:\WINDOWS\dell\nvraid\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004.08.04 11:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2007.12.01 00:25:52 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=625D7B39B09AB60A683AF4B95575056E – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2007.12.01 00:25:52 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=625D7B39B09AB60A683AF4B95575056E – C:\WINDOWS\system32\scecli.dll
[2008.04.14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008.01.05 00:46:51 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008.01.05 00:46:51 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008.01.05 00:46:51 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >


OTL Extras logfile created on: 02.02.2010 14:31:45 - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Mayte\Desktop
Windows XP Home Edition Service Pack 3, v.5657 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 16,54 Gb Free Space | 22,19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,92 Gb Total Space | 1,92 Gb Free Space | 99,72% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MAYTE-9BDDE8BE8
Current User Name: Mayte
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = SafariHTML] – C:\Program Files\Safari\Safari.exe (Apple Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Safari\Safari.exe" -url "%1" (Apple Inc.)
https [open] – "C:\Program Files\Safari\Safari.exe" -url "%1" (Apple Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 – (IniCom Networks, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Joost\xulrunner\tvprunner.exe" = C:\Program Files\Joost\xulrunner\tvprunner.exe:*:Enabled:tvprunner – File not found
"C:\Program Files\dm\fotobuch.de AG\Designer 2.0\Designer.exe" = C:\Program Files\dm\fotobuch.de AG\Designer 2.0\Designer.exe:*:Designer.exe – ()
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 – (IniCom Networks, Inc.)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – (www.sopcast.com)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – File not found
"C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – File not found
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04830D0F-F980-4EC0-89F1-594F2FD2A1B5}" = ElsterFormular 2008/2009
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0DD140D3-9563-481E-AA75-BA457CBDAEF2}" = PC Inspector File Recovery
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2227E1FA-01F5-483C-AB0E-2A308E900B3D}" = InterVideo FilterSDK for Hauppauge
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4C271126-C295-4828-A901-5910AE0C258B}" = Cisco Systems VPN Client 5.0.03.0530
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6DE13770-01B7-4366-8DA6-48237793F445}" = VoiceOver Kit
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{88A785A2-3EA6-4A2D-ABEE-68E9E55A39F8}" = NTI Ripper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B480BD2A-F1BA-4FE6-8C8E-34C6111B72C9}" = ElsterFormular 2007/2008
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F04CAFE3-D52F-4EFC-A1E8-316BD4C525D6}" = NTI Shadow
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AnyDVD" = AnyDVD
"AVG8Uninstall" = AVG 8.5
"CloneDVD2" = CloneDVD2
"CloneDVDmobile" = CloneDVDmobile
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.92 Modem
"Designer 2.0_is1" = Designer 2.0
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Hauppauge English Help Files and Resources" = Hauppauge English Help Files and Resources
"Hauppauge WinTV" = Hauppauge WinTV
"Hauppauge WinTV DVB-T EPG Service" = Hauppauge WinTV DVB-T EPG Service
"Hauppauge WinTV Scheduler" = Hauppauge WinTV Scheduler
"Hauppauge WinTV TV Services" = Hauppauge WinTV TV Services
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"Malware Defense" = Malware Defense
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.17)" = Mozilla Firefox (3.0.17)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ProInst" = Intel® PROSet/Wireless Software
"QcDrv" = Logitech® Camera Driver
"RealAlt_is1" = Real Alternative 1.60
"Red Eye Remover_is1" = Red Eye Remover 2.0
"SopCast" = SopCast 3.0.3
"VLC media player" = VLC media player 0.9.9
"Web Photo Album_is1" = Web Photo Album 1.1
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xilisoft Video Converter" = Xilisoft Video Converter 3
"Xvid_is1" = Xvid 1.1.3 final uninstall
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"TS" = Total Security

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 25.01.2010 15:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 25.01.2010 16:48:00 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 25.01.2010 17:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 26.01.2010 02:48:04 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 26.01.2010 02:48:04 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 26.01.2010 16:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 26.01.2010 17:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 26.01.2010 19:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 27.01.2010 16:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 28.01.2010 05:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.

[ System Events ]
Error - 02.02.2010 09:25:14 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 02.02.2010 09:25:28 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Cisco Systems, Inc. VPN Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 02.02.2010 09:25:34 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The EPGService service terminated unexpectedly. It has done this
1 time(s).

Error - 02.02.2010 09:25:36 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Event Log service terminated unexpectedly.
It has done this 1 time(s).

Error - 02.02.2010 09:25:54 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 02.02.2010 09:26:03 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 02.02.2010 09:26:05 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The SeaPort service terminated unexpectedly. It has done this 1 time(s).

Error - 02.02.2010 09:26:11 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Bonjour-Dienst service terminated unexpectedly. It has done this
1 time(s).

Error - 02.02.2010 09:26:15 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Registry Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 02.02.2010 09:26:19 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 2 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.


< End of report >

Hi,

Please do the following:



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    [2010.01.27 00:27:37 | 000,000,000 | —D | C] – C:\Program Files\Malware Defense
    [2010.01.27 00:27:50 | 000,001,611 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk
    [2010.01.27 00:27:50 | 000,000,705 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Password.lnk = C:\Documents and Settings\Mayte\Local Settings\Temp\Password.exe File not found
    [2010.01.26 21:50:23 | 000,000,008 | —- | M] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT




Extract the file and run it.

Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)

please post the content of that log TDSSKiller
We will have to do this in baby steps unless you have a better suggestion as the computer that we are currently using that has internet access is tied down with security and it thinks that TDSSkiller.exe is a virus. So it will take a day or two to get the file onto a usb stick.

So I ran the OTL script in OTL

It prompted to reboot.
On reboot it only showed the desktop and the .txt file.
We had to reboot again so that we had full windows again.
Here is that txt file.

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully.
C:\Program Files\Malware Defense folder moved successfully.
C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk moved successfully.
C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk moved successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Password.lnk moved successfully.
C:\Documents and Settings\All Users\Application Data\sysReserve.ini moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: LocalService
->Temp folder emptied: 480 bytes
->Temporary Internet Files folder emptied: 3394134 bytes

User: Mayte
->Temp folder emptied: 892725 bytes
->Temporary Internet Files folder emptied: 102992614 bytes
->Java cache emptied: 74145925 bytes
->FireFox cache emptied: 101043551 bytes
->Apple Safari cache emptied: 34174631 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 750349 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 19383825 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1712880 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 224036 bytes

Total Files Cleaned = 323,00 mb


OTL by OldTimer - Version 3.1.27.1 log created on 02032010_111340

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\SDA62C49F.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot…

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\SDA62C49F.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot…

OK see if you can get combofix to run now if you can't get TDSSKiller downloaded. try deleting the copy of Combofix that you have, download a fresh copy - rename to Combo.com run it in safe mode. make sure all your security programs are disabled and close all open windows and hopefully it will run this time, now we have deleted a few of the bad programs. I believe you still have a rootkit onboard that computer which is interfering with ComboFix.
Ok I got TDSSkiller downloaded and run. Here is the log

09:39:47:327 1556 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
09:39:47:327 1556 ================================================================================
09:39:47:327 1556 SystemInfo:

09:39:47:327 1556 OS Version: 5.1.2600 ServicePack: 3.0
09:39:47:327 1556 Product type: Workstation
09:39:47:327 1556 ComputerName: MAYTE-9BDDE8BE8
09:39:47:327 1556 UserName: Mayte
09:39:47:327 1556 Windows directory: C:\WINDOWS
09:39:47:327 1556 Processor architecture: Intel x86
09:39:47:327 1556 Number of processors: 1
09:39:47:327 1556 Page size: 0x1000
09:39:47:327 1556 Boot type: Normal boot
09:39:47:327 1556 ================================================================================
09:39:47:337 1556 UnloadDriverW: NtUnloadDriver error 2
09:39:47:337 1556 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
09:39:47:357 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
09:39:47:447 1556 UtilityInit: KLMD drop and load success
09:39:47:447 1556 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
09:39:47:447 1556 UtilityInit: KLMD open success
09:39:47:447 1556 UtilityInit: Initialize success
09:39:47:447 1556
09:39:47:447 1556 Scanning Services …
09:39:47:447 1556 CreateRegParser: Registry parser init started
09:39:47:447 1556 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
09:39:47:447 1556 CreateRegParser: DisableWow64Redirection error
09:39:47:447 1556 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
09:39:47:447 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
09:39:47:447 1556 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
09:39:47:447 1556 wfopen_ex: Trying to KLMD file open
09:39:47:447 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
09:39:47:447 1556 wfopen_ex: File opened ok (Flags 2)
09:39:47:447 1556 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: E748F8
09:39:47:447 1556 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
09:39:47:447 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
09:39:47:447 1556 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
09:39:47:447 1556 wfopen_ex: Trying to KLMD file open
09:39:47:447 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
09:39:47:447 1556 wfopen_ex: File opened ok (Flags 2)
09:39:47:447 1556 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: E749A0
09:39:47:447 1556 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
09:39:47:447 1556 CreateRegParser: EnableWow64Redirection error
09:39:47:447 1556 CreateRegParser: RegParser init completed
09:39:47:948 1556 GetAdvancedServicesInfo: Raw services enum returned 355 services
09:39:47:948 1556 ScanTDL2Services: Exact detect H8SRTd.sys (h: 1)
09:39:47:948 1556 RegNode HKLM\SYSTEM\ControlSet001\services\H8SRTd.sys infected by TDSS rootkit … 09:39:47:958 1556 will be deleted on reboot
09:39:47:968 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:968 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:978 1556 RegNode HKLM\SYSTEM\ControlSet003\services\H8SRTd.sys infected by TDSS rootkit … 09:39:47:978 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:988 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:988 1556 File C:\WINDOWS\system32\drivers\H8SRTlhylqbdmtk.sys infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: H8SRTd. Type: 1
09:39:47:988 1556 DeleteTDL2Service: Module clone ImagePath, skipping
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: H8SRTc. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTltewcpqcvh.dll infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: H8SRTsrcr. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTkdpxwkbopj.dat infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: h8srtserf. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTyekkxuroow.dll infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: h8srtmsg. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTftypepfvvi.dll infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: Module enum: Name: h8srtbbr. Type: 1
09:39:47:998 1556 File C:\WINDOWS\system32\H8SRTlaqyqbapuf.dll infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 ScanTDL2Services: DeleteEvilService(H8SRTd.sys) success
09:39:47:998 1556 ScanTDL2Services: Exact detect UACd.sys (h: 1)
09:39:47:998 1556 RegNode HKLM\SYSTEM\ControlSet001\services\UACd.sys infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:998 1556 RegNode HKLM\SYSTEM\ControlSet003\services\UACd.sys infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:998 1556 File C:\WINDOWS\system32\drivers\UACxdkpakxymx.sys infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: Module enum: Name: UACd. Type: 1
09:39:47:998 1556 DeleteTDL2Service: Module clone ImagePath, skipping
09:39:47:998 1556 DeleteTDL2Service: Module enum: Name: UACc. Type: 1
09:39:47:998 1556 File C:\WINDOWS\system32\UACobvdjbnexm.dll infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:008 1556 DeleteTDL2Service: Module enum: Name: UACbbr. Type: 1
09:39:48:008 1556 File C:\WINDOWS\system32\UACofrqcwkrje.dll infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:008 1556 DeleteTDL2Service: Module enum: Name: UACsr. Type: 1
09:39:48:008 1556 File C:\WINDOWS\system32\UACtkyxhvpphw.dat infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:008 1556 DeleteTDL2Service: Module enum: Name: uacserf. Type: 1
09:39:48:008 1556 File C:\WINDOWS\system32\UAChkwnswewfs.dll infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:018 1556 ScanTDL2Services: DeleteEvilService(UACd.sys) success
09:39:48:018 1556 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
09:39:48:018 1556 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
09:39:48:018 1556
09:39:48:018 1556 Scanning Kernel memory …
09:39:48:018 1556 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
09:39:48:018 1556 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8A6A2910
09:39:48:018 1556 DetectCureTDL3: KLMD_GetDeviceObjectList returned 2 DevObjects
09:39:48:018 1556
09:39:48:018 1556 DetectCureTDL3: DEVICE_OBJECT: 8A6C1C68
09:39:48:018 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A6C1C68
09:39:48:018 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A6C1C68[0x38]
09:39:48:018 1556 DetectCureTDL3: DRIVER_OBJECT: 8A6A2910
09:39:48:018 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A6A2910[0xA8]
09:39:48:018 1556 KLMD_ReadMem: Trying to ReadMemory 0xE1022240[0x18]
09:39:48:018 1556 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:39:48:018 1556 DetectCureTDL3: IrpHandler (0) addr: F765DBB0
09:39:48:018 1556 DetectCureTDL3: IrpHandler (1) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (2) addr: F765DBB0
09:39:48:018 1556 DetectCureTDL3: IrpHandler (3) addr: F7657D1F
09:39:48:018 1556 DetectCureTDL3: IrpHandler (4) addr: F7657D1F
09:39:48:018 1556 DetectCureTDL3: IrpHandler (5) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (6) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (7) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (8) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (9) addr: F76582E2
09:39:48:018 1556 DetectCureTDL3: IrpHandler (10) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (11) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (12) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (13) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (14) addr: F76583BB
09:39:48:018 1556 DetectCureTDL3: IrpHandler (15) addr: F765BF28
09:39:48:018 1556 DetectCureTDL3: IrpHandler (16) addr: F76582E2
09:39:48:018 1556 DetectCureTDL3: IrpHandler (17) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (18) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (19) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (20) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (21) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (22) addr: F7659C82
09:39:48:018 1556 DetectCureTDL3: IrpHandler (23) addr: F765E99E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (24) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (25) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (26) addr: 804FA87E
09:39:48:018 1556 TDL3_FileDetect: Processing driver: Disk
09:39:48:018 1556 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:39:48:018 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:39:48:028 1556 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:39:48:028 1556
09:39:48:028 1556 DetectCureTDL3: DEVICE_OBJECT: 8A6CBAB8
09:39:48:028 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A6CBAB8
09:39:48:028 1556 DetectCureTDL3: DEVICE_OBJECT: 8A6BC9A0
09:39:48:028 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A6BC9A0
09:39:48:028 1556 DetectCureTDL3: DEVICE_OBJECT: 8A73E940
09:39:48:028 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A73E940
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A73E940[0x38]
09:39:48:028 1556 DetectCureTDL3: DRIVER_OBJECT: 8A6CA558
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A6CA558[0xA8]
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0xE17758B0[0x1A]
09:39:48:028 1556 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
09:39:48:028 1556 DetectCureTDL3: IrpHandler (0) addr: F74AC6F2
09:39:48:028 1556 DetectCureTDL3: IrpHandler (1) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (2) addr: F74AC6F2
09:39:48:028 1556 DetectCureTDL3: IrpHandler (3) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (4) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (5) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (6) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (7) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (8) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (9) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (10) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (11) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (12) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (13) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (14) addr: F74AC712
09:39:48:028 1556 DetectCureTDL3: IrpHandler (15) addr: F74A8850
09:39:48:028 1556 DetectCureTDL3: IrpHandler (16) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (17) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (18) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (19) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (20) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (21) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (22) addr: F74AC73C
09:39:48:028 1556 DetectCureTDL3: IrpHandler (23) addr: F74B3336
09:39:48:028 1556 DetectCureTDL3: IrpHandler (24) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (25) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (26) addr: 804FA87E
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0xF74A9862[0x400]
09:39:48:028 1556 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
09:39:48:028 1556 TDL3_FileDetect: Processing driver: atapi
09:39:48:028 1556 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
09:39:48:028 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
09:39:48:038 1556 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
09:39:48:038 1556 UtilityBootReinit: Reboot required for cure complete..
09:39:48:038 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmdb.sys) returned status 00000000
09:39:48:048 1556 UtilityBootReinit: KLMD drop success
09:39:48:068 1556 KLMD_ApplyPendList: Pending buffer(FB4_588F, 1904) dropped successfully
09:39:48:068 1556 UtilityBootReinit: Cure on reboot scheduled successfully
09:39:48:068 1556
09:39:48:068 1556 Completed


I am now able to run Malwarebytes in safe mode and am doing so now.

One question. In C there is a _OTL folder with moved things in there. Can this be deleted?
Here is the first log from malwarebytes

Malwarebytes' Anti-Malware 1.44
Database version: 3628
Windows 5.1.2600 Service Pack 3, v.5657 (Safe Mode)
Internet Explorer 7.0.5730.13

04.02.2010 11:25:22
mbam-log-2010-02-04 (11-25-22).txt

Scan type: Full Scan (C:\|)
Objects scanned: 173494
Time elapsed: 50 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 19

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servises (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\h8srtd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Common Files\TSUninstall (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.

Files Infected:
C:\32788R22FWJFW\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\_OTL\MovedFiles\02032010_111340\C_Program Files\Malware Defense\uninstall.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\TSUninstall\Uninstall.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense\Malware Defense Support.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense\Uninstall Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Computer Scan.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Help.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Registration.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Security Center.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Settings.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Update.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Application Data\Microsoft\Internet Explorer\Quick Launch\TS.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\h8srtshsyst.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\h8srtsrcr.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Local Settings\Temp\H8SRT962c.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.

Hi, ComboFix should now run, Please download a fresh copy and run it. Post the log. Leave the OTL folder for now. It is essentially a 'quarantine' of sorts, the files there cannot harm the computer.
here it is. I did not realise that the Recovery Console had to be downloaded. I answered NO but combofix still ran.
ComboFix 10-02-04.06 - Mayte 05.02.2010 9:50.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2030.1530 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\combo.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\h8srtkrl32mainweq.dll
c:\documents and settings\All Users\Application Data\h8srtmainqt.dll

.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.

2010-02-03 10:13 . 2010-02-03 10:13 ——– d—–w- C:\_OTL
2010-01-28 13:19 . 2010-01-28 13:19 ——– d—–w- c:\program files\Trend Micro
2010-01-28 10:06 . 2010-01-28 10:06 ——– d—–w- c:\documents and settings\Mayte\Application Data\Malwarebytes
2010-01-28 09:57 . 2010-01-07 15:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-28 09:57 . 2010-02-01 13:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-28 09:57 . 2010-01-28 09:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-28 09:57 . 2010-01-07 15:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 08:47 . 2008-01-05 22:14 ——– d—–w- c:\documents and settings\Mayte\Application Data\Skype
2010-02-04 08:46 . 2009-03-20 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-02-04 08:37 . 2010-02-04 08:37 0 –sh–w- c:\windows\SDA62C49F.tmp
2010-01-27 20:44 . 2009-05-24 07:55 ——– d—–w- c:\program files\Web Photo Album
2010-01-26 06:47 . 2009-02-26 17:52 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-17 20:52 . 2009-12-05 01:13 79488 —-a-w- c:\documents and settings\Mayte\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-29 21:34 . 2009-11-29 21:34 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-29 21:31 . 2009-11-29 21:31 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-11-15 10:05 . 2008-01-08 21:52 55272 -c–a-w- c:\documents and settings\Mayte\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-07-04 08:21 . 2008-07-03 23:04 11132416 -c–a-w- c:\program files\vpnclient-win-msi-5.0.03.0530-k9.exe
2008-05-21 23:45 . 2008-05-21 23:45 3168683 —-a-w- c:\program files\SopCast.zip
2008-04-14 21:16 . 2008-04-14 21:16 22744616 -c–a-w- c:\program files\ElsterFormular2007-Setup.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-20 221184]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-13 2043160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2008-7-15 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-20 18:53 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2007-11-15 02:45 1608640 -c–a-w- c:\program files\SlySoft\AnyDVD\AnyDVD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPGServiceTool]
2007-08-01 02:26 675840 —-a-w- c:\progra~1\WinTV\EPG Services\System\EPGClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 15:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\dm\\fotobuch.de AG\\Designer 2.0\\Designer.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/20/2009 7:59 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/20/2009 7:59 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/20/2009 7:58 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/20/2009 7:58 PM 297752]
R2 EPGService;EPGService;c:\progra~1\WinTV\EPG Services\System\EPGService.exe [2/29/2008 7:54 PM 431104]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/15/2009 10:59 AM 54752]
S0 axqp;axqp;c:\windows\system32\drivers\jjgomll.sys –> c:\windows\system32\drivers\jjgomll.sys [?]
S0 jjevmd;jjevmd;c:\windows\system32\drivers\pcqcdlbj.sys –> c:\windows\system32\drivers\pcqcdlbj.sys [?]
S0 klmdb;klmdb;c:\windows\system32\drivers\klmdb.sys –> c:\windows\system32\drivers\klmdb.sys [?]
S2 LVEzLoader;LifeView EZ-USB FX2 FIRMWARE LOADER (LVEzLD06.sys);c:\windows\system32\drivers\LVEzLD06.sys [2/24/2008 11:12 PM 15360]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\HCWTVS~1.EXE [2/29/2008 7:51 PM 815104]
S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;c:\windows\system32\drivers\hcw95bda.sys [2/29/2008 7:47 PM 487424]
S3 hcw95rc;Hauppauge MOD7700 IR Driver;c:\windows\system32\drivers\hcw95rc.sys [2/29/2008 7:47 PM 15488]
S3 N;N;\??\c:\program files\NewTech Infosystems\NTI Ripper\ –> c:\program files\NewTech Infosystems\NTI Ripper\ [?]
S3 NinjaUSB;Freecom Turbo USB 2.0;c:\windows\system32\drivers\NinjaUSB.sys [6/16/2009 6:32 AM 24704]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2009-09-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000005.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Google Update - c:\documents and settings\Mayte\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
AddRemove-TS - c:\program files\TS\tsc.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 09:55
Windows 5.1.2600 Service Pack 3, v.5657 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N]
"ImagePath"="\??\c:\program files\NewTech Infosystems\NTI Ripper\"
.
Completion time: 2010-02-05 09:57:48
ComboFix-quarantined-files.txt 2010-02-05 08:57

Pre-Run: 18.211.606.528 bytes free
Post-Run: 18.189.754.368 bytes free

- - End Of File - - 2A85F5F72215F3E129103F4C8F37ACED

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI