This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] google redirect, etc

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have problem with search engines redirecting web pages. I did the Are You infected steps but my computer locked up when I tried to save the gmer.log. lsass.exe had taken over my computer. Here are the other logs. Malwarebytes' Anti-Malware 1.44 Database version: 3510 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 2/13/2010 11:05:06 AM mbam-log-2010-02-13 (11-05-06).txt Scan type: Quick Scan Objects scanned: 130003 Time elapsed: 9 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 6 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.Exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe (Security.Hijack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe (Security.Hijack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe (Security.Hijack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe (Security.Hijack) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 7:15:44.90 on Sun 02/14/2010 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.365 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\svchost.exe -k NetworkService svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\system32\gearsec.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Lexmark 4300 Series\lxcemon.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Lexmark 4300 Series\ezprint.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Verizon\McciTrayApp.exe C:\WINDOWS\system32\lxcecoms.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe C:\Program Files\palmOne\LifeDriveMgrTray.exe C:\PROGRA~1\palmOne\PALMON~2.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\GUILLERMO\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ig?hl=en uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uInternet Settings,ProxyOverride = 127.0.0.1;*.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll uURLSearchHooks: H - No File BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [VAIO Recovery] c:\windows\sonysys\vaio recovery\PartSeal.exe mRun: [SonyPowerCfg] c:\program files\sony\vaio power management\SPMgr.exe mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe mRun: [VAIOCameraUtility] "c:\program files\sony\vaio camera utility\VCUServe.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe" mRun: [LXCECATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCEtime.dll,_RunDLLEntry@16 mRun: [lxcemon.exe] "c:\program files\lexmark 4300 series\lxcemon.exe" mRun: [EzPrint] "c:\program files\lexmark 4300 series\ezprint.exe" mRun: [FaxCenterServer] "c:\program files\lexmark fax solutions\fm3032.exe" /s mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u mRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe mRun: [Verizon_McciTrayApp] c:\program files\verizon\McciTrayApp.exe mRun: [VAIO Update 3] "c:\program files\sony\vaio update 3\VAIOUpdt.exe" /Stationary mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe StartupFolder: c:\docume~1\guille~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\guille~1\startm~1\programs\startup\lifedr~1.lnk - c:\program files\palmone\LifeDriveMgrTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se for sd\CameraMonitor.exe mPolicies-system: EnableLUA = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL Trusted Zone: usaa.com\www DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} - hxxp://esupport.sony.com/VaioInfo.CAB DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} - file://e:\components\hidinputmonitorx.ocx DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxp://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader.cab DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} - file://e:\components\A9.ocx DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} - hxxp://calshare.calibresys.com/intra/Portal/resources/msddsc.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1159490702250 DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://69.20.169.101/activex/AxisCamControl.ocx DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: NameServer = 93.188.163.32,93.188.166.77 TCP: {995B2984-AE24-4ED3-A899-6AC19F27219D} = 93.188.163.32,93.188.166.77 TCP: {A2119B51-5C2F-4094-90BE-C995E5101680} = 93.188.163.32,93.188.166.77 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll Notify: WRNotifier - WRLogonNTF.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-27 333192] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-3-12 28424] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-4 285392] R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [2003-12-1 53248] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -svaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -sVAIO_VEDB [?] R3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [2007-10-27 513152] R3 MusCVideo32;MusCVideo32;c:\windows\system32\drivers\MusCVideo32.sys [2007-10-27 2688] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-3-15 226304] S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-27 360584] S2 OracleDBConsoledb101;OracleDBConsoledb101;c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe –> c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe [?] S3 palmmdm;Palm Modem;c:\windows\system32\drivers\palmmdm.sys [2007-9-20 9728] S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2006-3-15 29184] S3 SoundMovieServer;SoundMovieServer;c:\windows\system32\snmvtsvc.exe [2007-10-27 184320] S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.exe -i vaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.EXE -i VAIO_VEDB [?] =============== Created Last 30 ================ 2010-02-12 22:14 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-12 22:14 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-02-12 22:14 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-02-12 22:13 5,115,824 a——- C:\new_prog.exe 2010-02-12 22:05 –d—– c:\windows\pss 2010-02-12 21:58 401,720 a——- C:\HiJackThis.exe 2010-02-12 18:51 –d—– c:\docume~1\guille~1\applic~1\Malwarebytes 2010-02-12 18:50 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes ==================== Find3M ==================== 2010-01-24 10:11 360,584 a——- c:\windows\system32\drivers\avgtdix.sys 2010-01-05 05:00 832,512 a——- c:\windows\system32\wininet.dll 2010-01-05 05:00 78,336 a——- c:\windows\system32\ieencode.dll 2010-01-05 05:00 17,408 a——- c:\windows\system32\corpol.dll 2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll 2008-06-15 12:10 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008061520080616\index.dat ============= FINISH: 7:17:08.56 ===============
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 10-02-12.01 - GUILLERMO 02/14/2010 8:23.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.433 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\GUILLE~1\LOCALS~1\Temp\tmp2.tmp
c:\recycler\S-1-5-21-1409082233-1604221776-725345543-500
c:\recycler\S-1-5-21-3042144386-38634818-1214478158-500
c:\recycler\S-1-5-21-481110767-1992948612-544039527-500
c:\recycler\S-1-5-21-511144305-880782294-3526584436-500
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\EventSystem.log
c:\windows\setup.exe
c:\windows\system32\Cache
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((( Files Created from 2010-01-14 to 2010-02-14 )))))))))))))))))))))))))))))))
.

2010-02-13 15:51 . 2010-02-13 15:52 ——– d—–w- c:\program files\ERUNT
2010-02-13 03:14 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-13 03:14 . 2010-02-13 03:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-13 03:14 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-13 03:13 . 2010-02-13 03:13 5115824 —-a-w- C:\new_prog.exe
2010-02-13 02:58 . 2010-02-13 02:58 401720 —-a-w- C:\HiJackThis.exe
2010-02-12 23:51 . 2010-02-12 23:51 ——– d—–w- c:\documents and settings\GUILLERMO\Application Data\Malwarebytes
2010-02-12 23:50 . 2010-02-12 23:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-28 02:53 . 2010-01-18 23:22 1260800 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-28 02:53 . 2010-01-18 23:22 3777280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-17 03:40 . 2010-02-12 23:28 201328 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 11:42 . 2007-10-21 16:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-11 22:44 . 2006-10-12 23:45 ——– d—–w- c:\program files\Lx_cats
2010-01-24 15:11 . 2008-05-28 02:56 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-05 10:00 . 2006-03-15 23:56 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-03-15 23:55 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-03-15 23:55 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-15 11:29 . 2009-12-15 11:29 79488 —-a-w- c:\documents and settings\GUILLERMO\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-21 15:51 . 2006-03-15 23:55 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2007-11-29 02:50 . 2007-08-17 21:14 24 –sh–w- c:\windows\S526DADDD.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2009-10-19 3087296]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-17 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-17 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-17 118784]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-18 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-12-14 217088]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-07 7557120]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-11-24 167936]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512]
"EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
"VAIO Update 3"="c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe" [2007-05-16 551032]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-19 185896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

c:\documents and settings\GUILLERMO\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
LifeDriveT Manager.lnk - c:\program files\palmOne\LifeDriveMgrTray.exe [2005-4-28 86016]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
ImageMixer 3 SE Camera Monitor for SD.lnk - c:\program files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe [2009-1-1 253952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-05 03:19 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-21 01:42 73728 —-a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Sony\\Click to DVD 2\\CtoDvd.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"c:\\Program Files\\palmOne\\Hotsync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Sony\\VAIO Media 5.0\\Vc.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\MSPUB.EXE"=
"c:\\Program Files\\burst\\core-new1.1.3\\btdownloadheadless.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/27/2008 9:56 PM 333192]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/4/2009 10:18 PM 285392]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [12/1/2003 2:27 PM 53248]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [10/27/2007 8:22 PM 513152]
R3 MusCVideo32;MusCVideo32;c:\windows\system32\drivers\MusCVideo32.sys [10/27/2007 8:22 PM 2688]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [3/15/2006 6:57 PM 226304]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/27/2008 9:56 PM 360584]
S2 OracleDBConsoledb101;OracleDBConsoledb101;c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe –> c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe [?]
S3 palmmdm;Palm Modem;c:\windows\system32\drivers\palmmdm.sys [9/20/2007 2:59 PM 9728]
S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [3/15/2006 6:57 PM 29184]
S3 SoundMovieServer;SoundMovieServer;c:\windows\system32\snmvtsvc.exe [10/27/2007 8:22 PM 184320]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
.
Contents of the 'Scheduled Tasks' folder

2010-02-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]

2010-02-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-21 00:34]

2010-02-14 c:\windows\Tasks\User_Feed_Synchronization-{D6D2C90A-97D3-4EE9-8110-36A71DAA1F5A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 15:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: usaa.com\www
TCP: {995B2984-AE24-4ED3-A899-6AC19F27219D} = 93.188.163.32,93.188.166.77
TCP: {A2119B51-5C2F-4094-90BE-C995E5101680} = 93.188.163.32,93.188.166.77
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} - hxxp://calshare.calibresys.com/intra/Portal/resources/msddsc.cab
.
- - - - ORPHANS REMOVED - - - -

AddRemove-AOL Search Enhancement - c:\program files\AOL\AOL Search Enhancement\uninst.exe
AddRemove-HijackThis - c:\documents and settings\GUILLERMO\Local Settings\Temporary Internet Files\Content.IE5\E6JR7HFX\HijackThis.exe
AddRemove-Yahoo! Photos Easy Upload Tool - c:\program files\Yahoo!\Common\ydropper_uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-14 08:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll AnyDVD.sys atapi.sys >>UNKNOWN [0x873788C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7622f28
\Driver\ACPI -> ACPI.sys @ 0xf7495cb8
\Driver\atapi -> AnyDVD.sys @ 0xf696ea7e
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel® PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf7312bb0
PacketIndicateHandler -> NDIS.sys @ 0xf731fa21
SendHandler -> NDIS.sys @ 0xf72fd87b
user & kernel MBR OK

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\VESWinlogon.dll
.
Completion time: 2010-02-14 08:42:08
ComboFix-quarantined-files.txt 2010-02-14 13:41

Pre-Run: 24,386,654,208 bytes free
Post-Run: 25,076,973,568 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 88F2B0C6F16DF134906D50162CFEAF27
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
c:\windows\S526DADDD.tmp

DDS::
TCP: {995B2984-AE24-4ED3-A899-6AC19F27219D} = 93.188.163.32,93.188.166.77
TCP: {A2119B51-5C2F-4094-90BE-C995E5101680} = 93.188.163.32,93.188.166.77
Trusted Zone: usaa.com\www

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT



Extract the file and run it.

Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)

please post the content of that log TDSSKiller
ComboFix 10-02-12.01 - GUILLERMO 02/14/2010 9:38.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.430 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\GUILLERMO\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\S526DADDD.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\S526DADDD.tmp

.
((((((((((((((((((((((((( Files Created from 2010-01-14 to 2010-02-14 )))))))))))))))))))))))))))))))
.

2010-02-13 15:51 . 2010-02-13 15:52 ——– d—–w- c:\program files\ERUNT
2010-02-13 03:14 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-13 03:14 . 2010-02-13 03:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-13 03:14 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-13 03:13 . 2010-02-13 03:13 5115824 —-a-w- C:\new_prog.exe
2010-02-13 02:58 . 2010-02-13 02:58 401720 —-a-w- C:\HiJackThis.exe
2010-02-12 23:51 . 2010-02-12 23:51 ——– d—–w- c:\documents and settings\GUILLERMO\Application Data\Malwarebytes
2010-02-12 23:50 . 2010-02-12 23:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-28 02:53 . 2010-01-18 23:22 1260800 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-28 02:53 . 2010-01-18 23:22 3777280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-17 03:40 . 2010-02-12 23:28 201328 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 11:42 . 2007-10-21 16:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-11 22:44 . 2006-10-12 23:45 ——– d—–w- c:\program files\Lx_cats
2010-01-24 15:11 . 2008-05-28 02:56 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-05 10:00 . 2006-03-15 23:56 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-03-15 23:55 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-03-15 23:55 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-15 11:29 . 2009-12-15 11:29 79488 —-a-w- c:\documents and settings\GUILLERMO\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-21 15:51 . 2006-03-15 23:55 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2009-10-19 3087296]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-17 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-17 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-17 118784]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-18 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-12-14 217088]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-07 7557120]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-11-24 167936]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512]
"EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
"VAIO Update 3"="c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe" [2007-05-16 551032]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-19 185896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

c:\documents and settings\GUILLERMO\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
LifeDriveT Manager.lnk - c:\program files\palmOne\LifeDriveMgrTray.exe [2005-4-28 86016]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
ImageMixer 3 SE Camera Monitor for SD.lnk - c:\program files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe [2009-1-1 253952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-05 03:19 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-21 01:42 73728 —-a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Sony\\Click to DVD 2\\CtoDvd.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"c:\\Program Files\\palmOne\\Hotsync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Sony\\VAIO Media 5.0\\Vc.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\MSPUB.EXE"=
"c:\\Program Files\\burst\\core-new1.1.3\\btdownloadheadless.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/27/2008 9:56 PM 333192]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/4/2009 10:18 PM 285392]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [12/1/2003 2:27 PM 53248]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [10/27/2007 8:22 PM 513152]
R3 MusCVideo32;MusCVideo32;c:\windows\system32\drivers\MusCVideo32.sys [10/27/2007 8:22 PM 2688]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [3/15/2006 6:57 PM 226304]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/27/2008 9:56 PM 360584]
S2 OracleDBConsoledb101;OracleDBConsoledb101;c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe –> c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe [?]
S3 palmmdm;Palm Modem;c:\windows\system32\drivers\palmmdm.sys [9/20/2007 2:59 PM 9728]
S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [3/15/2006 6:57 PM 29184]
S3 SoundMovieServer;SoundMovieServer;c:\windows\system32\snmvtsvc.exe [10/27/2007 8:22 PM 184320]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
.
Contents of the 'Scheduled Tasks' folder

2010-02-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]

2010-02-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-21 00:34]

2010-02-14 c:\windows\Tasks\User_Feed_Synchronization-{D6D2C90A-97D3-4EE9-8110-36A71DAA1F5A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 15:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} - hxxp://calshare.calibresys.com/intra/Portal/resources/msddsc.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-14 09:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll AnyDVD.sys atapi.sys >>UNKNOWN [0x873788C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7622f28
\Driver\ACPI -> ACPI.sys @ 0xf7495cb8
\Driver\atapi -> AnyDVD.sys @ 0xf696ea7e
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel® PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf7312bb0
PacketIndicateHandler -> NDIS.sys @ 0xf731fa21
SendHandler -> NDIS.sys @ 0xf72fd87b
user & kernel MBR OK

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\VESWinlogon.dll
.
Completion time: 2010-02-14 10:03:23
ComboFix-quarantined-files.txt 2010-02-14 15:03
ComboFix2.txt 2010-02-14 13:42

Pre-Run: 25,101,193,216 bytes free
Post-Run: 25,077,088,256 bytes free

- - End Of File - - 232D24D61185FB518DF805F8EA8F31E5

10:06:59:545 3028 TDSS rootkit removing tool 2.2.3 Feb 4 2010 14:34:00
10:06:59:545 3028 ================================================================================
10:06:59:545 3028 SystemInfo:

10:06:59:545 3028 OS Version: 5.1.2600 ServicePack: 3.0
10:06:59:545 3028 Product type: Workstation
10:06:59:545 3028 ComputerName: SONYLAPTOP
10:06:59:545 3028 UserName: GUILLERMO
10:06:59:545 3028 Windows directory: C:\WINDOWS
10:06:59:545 3028 Processor architecture: Intel x86
10:06:59:545 3028 Number of processors: 2
10:06:59:545 3028 Page size: 0x1000
10:06:59:545 3028 Boot type: Normal boot
10:06:59:545 3028 ================================================================================
10:06:59:545 3028 UnloadDriverW: NtUnloadDriver error 2
10:06:59:545 3028 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
10:06:59:545 3028 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
10:06:59:560 3028 UtilityInit: KLMD drop and load success
10:06:59:560 3028 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)
10:06:59:560 3028 UtilityInit: KLMD open success
10:06:59:560 3028 UtilityInit: Initialize success
10:06:59:560 3028
10:06:59:560 3028 Scanning Services …
10:06:59:560 3028 CreateRegParser: Registry parser init started
10:06:59:560 3028 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
10:06:59:560 3028 CreateRegParser: DisableWow64Redirection error
10:06:59:560 3028 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
10:06:59:560 3028 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
10:06:59:560 3028 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:06:59:560 3028 wfopen_ex: Trying to KLMD file open
10:06:59:560 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
10:06:59:560 3028 wfopen_ex: File opened ok (Flags 2)
10:06:59:560 3028 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 384B88
10:06:59:560 3028 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
10:06:59:560 3028 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
10:06:59:560 3028 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:06:59:560 3028 wfopen_ex: Trying to KLMD file open
10:06:59:560 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
10:06:59:560 3028 wfopen_ex: File opened ok (Flags 2)
10:06:59:560 3028 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 384C30
10:06:59:560 3028 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
10:06:59:560 3028 CreateRegParser: EnableWow64Redirection error
10:06:59:560 3028 CreateRegParser: RegParser init completed
10:07:00:201 3028 GetAdvancedServicesInfo: Raw services enum returned 412 services
10:07:00:201 3028 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
10:07:00:201 3028 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
10:07:00:201 3028
10:07:00:201 3028 Scanning Kernel memory …
10:07:00:201 3028 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
10:07:00:201 3028 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8737DA60
10:07:00:201 3028 DetectCureTDL3: KLMD_GetDeviceObjectList returned 7 DevObjects
10:07:00:201 3028
10:07:00:201 3028 DetectCureTDL3: DEVICE_OBJECT: 864F54E8
10:07:00:201 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 864F54E8
10:07:00:201 3028 KLMD_ReadMem: Trying to ReadMemory 0x864F54E8[0x38]
10:07:00:201 3028 DetectCureTDL3: DRIVER_OBJECT: 8737DA60
10:07:00:201 3028 KLMD_ReadMem: Trying to ReadMemory 0x8737DA60[0xA8]
10:07:00:201 3028 KLMD_ReadMem: Trying to ReadMemory 0xE100D820[0x18]
10:07:00:201 3028 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:07:00:201 3028 DetectCureTDL3: IrpHandler (0) addr: F7624BB0
10:07:00:201 3028 DetectCureTDL3: IrpHandler (1) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (2) addr: F7624BB0
10:07:00:201 3028 DetectCureTDL3: IrpHandler (3) addr: F761ED1F
10:07:00:201 3028 DetectCureTDL3: IrpHandler (4) addr: F761ED1F
10:07:00:201 3028 DetectCureTDL3: IrpHandler (5) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (6) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (7) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (8) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (9) addr: F761F2E2
10:07:00:201 3028 DetectCureTDL3: IrpHandler (10) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (11) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (12) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (13) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (14) addr: F761F3BB
10:07:00:201 3028 DetectCureTDL3: IrpHandler (15) addr: F7622F28
10:07:00:201 3028 DetectCureTDL3: IrpHandler (16) addr: F761F2E2
10:07:00:201 3028 DetectCureTDL3: IrpHandler (17) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (18) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (19) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (20) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (21) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (22) addr: F7620C82
10:07:00:201 3028 DetectCureTDL3: IrpHandler (23) addr: F762599E
10:07:00:201 3028 DetectCureTDL3: IrpHandler (24) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (25) addr: 804F4562
10:07:00:201 3028 DetectCureTDL3: IrpHandler (26) addr: 804F4562
10:07:00:201 3028 TDL3_FileDetect: Processing driver: Disk
10:07:00:201 3028 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:201 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:216 3028 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:07:00:216 3028
10:07:00:216 3028 DetectCureTDL3: DEVICE_OBJECT: 86674860
10:07:00:216 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86674860
10:07:00:216 3028 DetectCureTDL3: DEVICE_OBJECT: 87275980
10:07:00:216 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87275980
10:07:00:216 3028 KLMD_ReadMem: Trying to ReadMemory 0x87275980[0x38]
10:07:00:216 3028 DetectCureTDL3: DRIVER_OBJECT: 87269858
10:07:00:216 3028 KLMD_ReadMem: Trying to ReadMemory 0x87269858[0xA8]
10:07:00:216 3028 KLMD_ReadMem: Trying to ReadMemory 0xE1009DE0[0x1E]
10:07:00:216 3028 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
10:07:00:216 3028 DetectCureTDL3: IrpHandler (0) addr: F797B218
10:07:00:216 3028 DetectCureTDL3: IrpHandler (1) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (2) addr: F797B218
10:07:00:216 3028 DetectCureTDL3: IrpHandler (3) addr: F797B23C
10:07:00:216 3028 DetectCureTDL3: IrpHandler (4) addr: F797B23C
10:07:00:216 3028 DetectCureTDL3: IrpHandler (5) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (6) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (7) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (8) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (9) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (10) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (11) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (12) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (13) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (14) addr: F696DF16
10:07:00:216 3028 DetectCureTDL3: IrpHandler (15) addr: F696EA7E
10:07:00:216 3028 DetectCureTDL3: IrpHandler (16) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (17) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (18) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (19) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (20) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (21) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (22) addr: F797A5F0
10:07:00:216 3028 DetectCureTDL3: IrpHandler (23) addr: F7978A6E
10:07:00:216 3028 DetectCureTDL3: IrpHandler (24) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (25) addr: 804F4562
10:07:00:216 3028 DetectCureTDL3: IrpHandler (26) addr: 804F4562
10:07:00:216 3028 KLMD_ReadMem: Trying to ReadMemory 0xF7977F26[0x400]
10:07:00:216 3028 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
10:07:00:216 3028 TDL3_FileDetect: Processing driver: usbstor
10:07:00:216 3028 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:07:00:216 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:07:00:232 3028 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
10:07:00:232 3028
10:07:00:232 3028 DetectCureTDL3: DEVICE_OBJECT: 866FC680
10:07:00:232 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 866FC680
10:07:00:232 3028 KLMD_ReadMem: Trying to ReadMemory 0x866FC680[0x38]
10:07:00:232 3028 DetectCureTDL3: DRIVER_OBJECT: 8737DA60
10:07:00:232 3028 KLMD_ReadMem: Trying to ReadMemory 0x8737DA60[0xA8]
10:07:00:232 3028 KLMD_ReadMem: Trying to ReadMemory 0xE100D820[0x18]
10:07:00:232 3028 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:07:00:232 3028 DetectCureTDL3: IrpHandler (0) addr: F7624BB0
10:07:00:232 3028 DetectCureTDL3: IrpHandler (1) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (2) addr: F7624BB0
10:07:00:232 3028 DetectCureTDL3: IrpHandler (3) addr: F761ED1F
10:07:00:232 3028 DetectCureTDL3: IrpHandler (4) addr: F761ED1F
10:07:00:232 3028 DetectCureTDL3: IrpHandler (5) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (6) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (7) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (8) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (9) addr: F761F2E2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (10) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (11) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (12) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (13) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (14) addr: F761F3BB
10:07:00:232 3028 DetectCureTDL3: IrpHandler (15) addr: F7622F28
10:07:00:232 3028 DetectCureTDL3: IrpHandler (16) addr: F761F2E2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (17) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (18) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (19) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (20) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (21) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (22) addr: F7620C82
10:07:00:232 3028 DetectCureTDL3: IrpHandler (23) addr: F762599E
10:07:00:232 3028 DetectCureTDL3: IrpHandler (24) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (25) addr: 804F4562
10:07:00:232 3028 DetectCureTDL3: IrpHandler (26) addr: 804F4562
10:07:00:232 3028 TDL3_FileDetect: Processing driver: Disk
10:07:00:232 3028 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:232 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:232 3028 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:07:00:232 3028
10:07:00:232 3028 DetectCureTDL3: DEVICE_OBJECT: 870B5AB8
10:07:00:232 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 870B5AB8
10:07:00:232 3028 DetectCureTDL3: DEVICE_OBJECT: 86FD1968
10:07:00:232 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86FD1968
10:07:00:232 3028 KLMD_ReadMem: Trying to ReadMemory 0x86FD1968[0x38]
10:07:00:232 3028 DetectCureTDL3: DRIVER_OBJECT: 87268DA0
10:07:00:232 3028 KLMD_ReadMem: Trying to ReadMemory 0x87268DA0[0xA8]
10:07:00:232 3028 KLMD_ReadMem: Trying to ReadMemory 0xE1EEDB90[0x20]
10:07:00:232 3028 DetectCureTDL3: DRIVER_OBJECT name: \Driver\ti21sony, Driver Name: ti21sony
10:07:00:232 3028 DetectCureTDL3: IrpHandler (0) addr: F69DF196
10:07:00:232 3028 DetectCureTDL3: IrpHandler (1) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (2) addr: F69DF204
10:07:00:232 3028 DetectCureTDL3: IrpHandler (3) addr: F69DF40C
10:07:00:232 3028 DetectCureTDL3: IrpHandler (4) addr: F69DF65E
10:07:00:232 3028 DetectCureTDL3: IrpHandler (5) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (6) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (7) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (8) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (9) addr: F69DF2FE
10:07:00:232 3028 DetectCureTDL3: IrpHandler (10) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (11) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (12) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (13) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (14) addr: F69DF248
10:07:00:232 3028 DetectCureTDL3: IrpHandler (15) addr: F69DF272
10:07:00:232 3028 DetectCureTDL3: IrpHandler (16) addr: F69DF4D2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (17) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (18) addr: F69DF0FC
10:07:00:232 3028 DetectCureTDL3: IrpHandler (19) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (20) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (21) addr: F69AE6B2
10:07:00:232 3028 DetectCureTDL3: IrpHandler (22) addr: F69DF364
10:07:00:232 3028 DetectCureTDL3: IrpHandler (23) addr: F69DF596
10:07:00:232 3028 DetectCureTDL3: IrpHandler (24) addr: F69AE6B2
10:07:00:248 3028 DetectCureTDL3: IrpHandler (25) addr: F69AE6B2
10:07:00:248 3028 DetectCureTDL3: IrpHandler (26) addr: F69AE6B2
10:07:00:248 3028 TDL3_FileDetect: Processing driver: ti21sony
10:07:00:248 3028 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\ti21sony.sys
10:07:00:248 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\ti21sony.sys
10:07:00:263 3028 TDL3_FileDetect: C:\WINDOWS\system32\drivers\ti21sony.sys - Verdict: Clean
10:07:00:263 3028
10:07:00:263 3028 DetectCureTDL3: DEVICE_OBJECT: 87320C68
10:07:00:263 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87320C68
10:07:00:263 3028 KLMD_ReadMem: Trying to ReadMemory 0x87320C68[0x38]
10:07:00:263 3028 DetectCureTDL3: DRIVER_OBJECT: 8737DA60
10:07:00:263 3028 KLMD_ReadMem: Trying to ReadMemory 0x8737DA60[0xA8]
10:07:00:263 3028 KLMD_ReadMem: Trying to ReadMemory 0xE100D820[0x18]
10:07:00:263 3028 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:07:00:263 3028 DetectCureTDL3: IrpHandler (0) addr: F7624BB0
10:07:00:263 3028 DetectCureTDL3: IrpHandler (1) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (2) addr: F7624BB0
10:07:00:263 3028 DetectCureTDL3: IrpHandler (3) addr: F761ED1F
10:07:00:263 3028 DetectCureTDL3: IrpHandler (4) addr: F761ED1F
10:07:00:263 3028 DetectCureTDL3: IrpHandler (5) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (6) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (7) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (8) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (9) addr: F761F2E2
10:07:00:263 3028 DetectCureTDL3: IrpHandler (10) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (11) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (12) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (13) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (14) addr: F761F3BB
10:07:00:263 3028 DetectCureTDL3: IrpHandler (15) addr: F7622F28
10:07:00:263 3028 DetectCureTDL3: IrpHandler (16) addr: F761F2E2
10:07:00:263 3028 DetectCureTDL3: IrpHandler (17) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (18) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (19) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (20) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (21) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (22) addr: F7620C82
10:07:00:263 3028 DetectCureTDL3: IrpHandler (23) addr: F762599E
10:07:00:263 3028 DetectCureTDL3: IrpHandler (24) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (25) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (26) addr: 804F4562
10:07:00:263 3028 TDL3_FileDetect: Processing driver: Disk
10:07:00:263 3028 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:263 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:263 3028 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:07:00:263 3028
10:07:00:263 3028 DetectCureTDL3: DEVICE_OBJECT: 8737BC68
10:07:00:263 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8737BC68
10:07:00:263 3028 KLMD_ReadMem: Trying to ReadMemory 0x8737BC68[0x38]
10:07:00:263 3028 DetectCureTDL3: DRIVER_OBJECT: 8737DA60
10:07:00:263 3028 KLMD_ReadMem: Trying to ReadMemory 0x8737DA60[0xA8]
10:07:00:263 3028 KLMD_ReadMem: Trying to ReadMemory 0xE100D820[0x18]
10:07:00:263 3028 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:07:00:263 3028 DetectCureTDL3: IrpHandler (0) addr: F7624BB0
10:07:00:263 3028 DetectCureTDL3: IrpHandler (1) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (2) addr: F7624BB0
10:07:00:263 3028 DetectCureTDL3: IrpHandler (3) addr: F761ED1F
10:07:00:263 3028 DetectCureTDL3: IrpHandler (4) addr: F761ED1F
10:07:00:263 3028 DetectCureTDL3: IrpHandler (5) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (6) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (7) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (8) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (9) addr: F761F2E2
10:07:00:263 3028 DetectCureTDL3: IrpHandler (10) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (11) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (12) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (13) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (14) addr: F761F3BB
10:07:00:263 3028 DetectCureTDL3: IrpHandler (15) addr: F7622F28
10:07:00:263 3028 DetectCureTDL3: IrpHandler (16) addr: F761F2E2
10:07:00:263 3028 DetectCureTDL3: IrpHandler (17) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (18) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (19) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (20) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (21) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (22) addr: F7620C82
10:07:00:263 3028 DetectCureTDL3: IrpHandler (23) addr: F762599E
10:07:00:263 3028 DetectCureTDL3: IrpHandler (24) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (25) addr: 804F4562
10:07:00:263 3028 DetectCureTDL3: IrpHandler (26) addr: 804F4562
10:07:00:263 3028 TDL3_FileDetect: Processing driver: Disk
10:07:00:263 3028 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:263 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:07:00:279 3028 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:07:00:279 3028
10:07:00:279 3028 DetectCureTDL3: DEVICE_OBJECT: 87354AB8
10:07:00:279 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87354AB8
10:07:00:279 3028 DetectCureTDL3: DEVICE_OBJECT: 873569E8
10:07:00:279 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 873569E8
10:07:00:279 3028 DetectCureTDL3: DEVICE_OBJECT: 87324940
10:07:00:279 3028 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87324940
10:07:00:279 3028 KLMD_ReadMem: Trying to ReadMemory 0x87324940[0x38]
10:07:00:279 3028 DetectCureTDL3: DRIVER_OBJECT: 8735B4D8
10:07:00:279 3028 KLMD_ReadMem: Trying to ReadMemory 0x8735B4D8[0xA8]
10:07:00:279 3028 KLMD_ReadMem: Trying to ReadMemory 0xE1008160[0x1A]
10:07:00:279 3028 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
10:07:00:279 3028 DetectCureTDL3: IrpHandler (0) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (1) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (2) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (3) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (4) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (5) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (6) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (7) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (8) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (9) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (10) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (11) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (12) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (13) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (14) addr: F696DF16
10:07:00:279 3028 DetectCureTDL3: IrpHandler (15) addr: F696EA7E
10:07:00:279 3028 DetectCureTDL3: IrpHandler (16) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (17) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (18) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (19) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (20) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (21) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (22) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (23) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (24) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (25) addr: F7432B3A
10:07:00:279 3028 DetectCureTDL3: IrpHandler (26) addr: F7432B3A
10:07:00:279 3028 KLMD_ReadMem: Trying to ReadMemory 0xF7430864[0x400]
10:07:00:279 3028 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
10:07:00:279 3028 TDL3_FileDetect: Processing driver: atapi
10:07:00:279 3028 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
10:07:00:279 3028 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
10:07:00:279 3028 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
10:07:00:279 3028
10:07:00:279 3028 Completed
10:07:00:279 3028
10:07:00:279 3028 Results:
10:07:00:295 3028 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
10:07:00:295 3028 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
10:07:00:295 3028 File objects infected / cured / cured on reboot: 0 / 0 / 0
10:07:00:295 3028
10:07:00:295 3028 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
10:07:00:295 3028 UtilityDeinit: KLMD(ARK) unloaded successfully
Hi,

Please do the following:


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Malwarebytes' Anti-Malware 1.44 Database version: 3738 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 2/14/2010 10:35:21 AM mbam-log-2010-02-14 (10-35-21).txt Scan type: Quick Scan Objects scanned: 135390 Time elapsed: 8 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, February 14, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, February 14, 2010 15:38:49 Records in database: 3502288 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ Scan statistics: Objects scanned: 130058 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 04:44:51 No threats found. Scanned area is clean. Selected area has been scanned.
Computer is running fine but Google is still getting redirected. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:45:43.79 on Sun 02/14/2010 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.638 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\svchost.exe -k NetworkService svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\system32\gearsec.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Lexmark 4300 Series\lxcemon.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\lxcecoms.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\GUILLERMO\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ig?hl=en uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7 uInternet Settings,ProxyOverride = 127.0.0.1;*.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll uURLSearchHooks: H - No File BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [VAIO Recovery] c:\windows\sonysys\vaio recovery\PartSeal.exe mRun: [SonyPowerCfg] c:\program files\sony\vaio power management\SPMgr.exe mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe mRun: [VAIOCameraUtility] "c:\program files\sony\vaio camera utility\VCUServe.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe" mRun: [LXCECATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCEtime.dll,_RunDLLEntry@16 mRun: [lxcemon.exe] "c:\program files\lexmark 4300 series\lxcemon.exe" mRun: [EzPrint] "c:\program files\lexmark 4300 series\ezprint.exe" mRun: [FaxCenterServer] "c:\program files\lexmark fax solutions\fm3032.exe" /s mRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe mRun: [Verizon_McciTrayApp] c:\program files\verizon\McciTrayApp.exe mRun: [VAIO Update 3] "c:\program files\sony\vaio update 3\VAIOUpdt.exe" /Stationary mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\docume~1\guille~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\guille~1\startm~1\programs\startup\lifedr~1.lnk - c:\program files\palmone\LifeDriveMgrTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se for sd\CameraMonitor.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} - hxxp://esupport.sony.com/VaioInfo.CAB DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} - file://e:\components\hidinputmonitorx.ocx DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxp://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader.cab DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} - file://e:\components\A9.ocx DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} - hxxp://calshare.calibresys.com/intra/Portal/resources/msddsc.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1159490702250 DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://69.20.169.101/activex/AxisCamControl.ocx DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll Notify: WRNotifier - WRLogonNTF.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-27 333192] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-3-12 28424] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-4 285392] R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [2003-12-1 53248] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -svaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -sVAIO_VEDB [?] R3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [2007-10-27 513152] R3 MusCVideo32;MusCVideo32;c:\windows\system32\drivers\MusCVideo32.sys [2007-10-27 2688] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-3-15 226304] S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-27 360584] S2 OracleDBConsoledb101;OracleDBConsoledb101;c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe –> c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe [?] S3 palmmdm;Palm Modem;c:\windows\system32\drivers\palmmdm.sys [2007-9-20 9728] S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2006-3-15 29184] S3 SoundMovieServer;SoundMovieServer;c:\windows\system32\snmvtsvc.exe [2007-10-27 184320] S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.exe -i vaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.EXE -i VAIO_VEDB [?] =============== Created Last 30 ================ 2010-02-14 08:20 a-dshr– C:\cmdcons 2010-02-14 08:17 261,632 a——- c:\windows\PEV.exe 2010-02-14 08:17 161,792 a——- c:\windows\SWREG.exe 2010-02-14 08:17 98,816 a——- c:\windows\sed.exe 2010-02-14 08:17 77,312 a——- c:\windows\MBR.exe 2010-02-12 22:14 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-12 22:14 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-02-12 22:14 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-02-12 22:13 5,115,824 a——- C:\new_prog.exe 2010-02-12 22:05 –d—– c:\windows\pss 2010-02-12 21:58 401,720 a——- C:\HiJackThis.exe 2010-02-12 18:51 –d—– c:\docume~1\guille~1\applic~1\Malwarebytes 2010-02-12 18:50 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes ==================== Find3M ==================== 2010-01-24 10:11 360,584 a——- c:\windows\system32\drivers\avgtdix.sys 2010-01-05 05:00 832,512 ——– c:\windows\system32\wininet.dll 2010-01-05 05:00 78,336 a——- c:\windows\system32\ieencode.dll 2010-01-05 05:00 17,408 a——- c:\windows\system32\corpol.dll 2009-12-17 17:14 411,368 a——- c:\windows\system32\deploytk.dll 2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll 2008-06-15 12:10 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008061520080616\index.dat ============= FINISH: 19:47:22.40 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 8/15/2006 9:31:33 PM System Uptime: 2/14/2010 7:06:12 AM (12 hours ago) Motherboard: Sony Corporation | | VAIO Processor: Genuine Intel® CPU T2300 @ 1.66GHz | N/A | 1662/167mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 86 GiB total, 23.201 GiB free. D: is Removable E: is CDROM () F: is CDROM () G: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\21338A08004603 Manufacturer: Microsoft Name: 1394 Net Adapter PNP Device ID: V1394\NIC1394\21338A08004603 Service: NIC1394 Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Microsoft Loopback Adapter Device ID: ROOT\NET\0000 Manufacturer: Microsoft Name: Microsoft Loopback Adapter PNP Device ID: ROOT\NET\0000 Service: msloop ==== System Restore Points =================== RP1: 1/25/2010 10:09:52 PM - System Checkpoint RP2: 1/26/2010 10:25:17 PM - System Checkpoint RP3: 1/27/2010 9:53:23 PM - Avg8 Update RP4: 1/29/2010 12:23:44 PM - System Checkpoint RP5: 1/30/2010 3:10:19 PM - System Checkpoint RP6: 1/31/2010 3:35:32 PM - System Checkpoint RP7: 2/1/2010 3:48:57 PM - System Checkpoint RP8: 2/1/2010 6:55:41 PM - Software Distribution Service 3.0 RP9: 2/2/2010 8:25:52 PM - System Checkpoint RP10: 2/3/2010 8:51:03 PM - System Checkpoint RP11: 2/5/2010 8:34:52 AM - System Checkpoint RP12: 2/6/2010 4:31:06 PM - System Checkpoint RP13: 2/7/2010 5:19:54 PM - System Checkpoint RP14: 2/9/2010 1:44:07 PM - System Checkpoint RP15: 2/10/2010 5:08:14 PM - System Checkpoint RP16: 2/11/2010 5:12:34 PM - System Checkpoint RP17: 2/12/2010 6:13:00 PM - System Checkpoint RP18: 2/13/2010 10:50:48 AM - Automatic Restore Point RP19: 2/14/2010 10:49:18 AM - Installed Java™ 6 Update 18 ==== Installed Programs ====================== ABBYY FineReader 6.0 Sprint Adobe Flash Player 10 ActiveX Adobe Flash Player Plugin Adobe Reader 8.1.6 Adobe Shockwave Player 11 AGEIA PhysX v2.4.4 AllMusicConverter 3.1.1 Amazon MP3 Downloader 1.0.3 Amazon Unbox Video AnyDVD Apple Application Support Apple Mobile Device Support Apple Software Update AVG Free 9.0 Bonjour Botanical Images Vol 1 burst! v3.1.0 Canon Camera Access Library Canon Camera Support Core Library Canon RAW Image Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities EOS Utility Canon Utilities MyCamera Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility Citrix Presentation Server Client Click to DVD 2.0.03 Menu Data Click to DVD 2.5.20 CloneDVD2 CloneDVDmobile Compatibility Pack for the 2007 Office system Critical Update for Windows Media Player 11 (KB959772) DSD Direct DSD Playback Plug-in 1.0 DVgate Plus ERUNT 1.1j GARMIN 500 Series Trainer GEAR 32bit Driver Installer Google Earth Google Updater GreatBattlesCD HDAUDIO SoftV92 Data Fax Modem with SmartCP High Definition Audio Driver Package - KB835221 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 10 (KB910393) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Image Converter 2 Plus ImageMixer 3 SE for SD ImageStation Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers Intel® PROSet/Wireless Software InterVideo WinDVD for VAIO ISScript iTunes J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 6 J2SE Runtime Environment 5.0 Update 9 Java Auto Updater Java™ 6 Update 18 Java™ 6 Update 5 Java™ 6 Update 7 Java™ SE Runtime Environment 6 Update 1 LAN Setting Utility Lexmark 4300 Series Lexmark Fax Solutions Macromedia Flash Player 8 Malwarebytes' Anti-Malware mCore mDriver Memory Stick Formatter Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Digital Image Library 9 - Blocker Microsoft Digital Image Starter Edition 2006 Microsoft Digital Image Starter Edition 2006 Editor Microsoft Digital Image Starter Edition 2006 Library Microsoft FrontPage Client - English Microsoft IntelliPoint 5.3 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Office Standard Edition 2003 Microsoft SQL Server Desktop Engine (VAIO_VEDB) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual J# .NET Redistributable Package 1.1 Microsoft Visual Studio .NET Professional 2003 - English Microsoft Works MixMeister Express 6 Demo MixMeister Express 6.1.8 mMHouse MobileMe Control Panel MobiSystems Money Move Networks Media Player for Internet Explorer mPfMgr mProSafe MSDN Library for Visual Studio .NET 2003 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) mWlsSafe mXML Netflix Movie Viewer NVIDIA Drivers Office 2003 Trial Assistant OpenMG Limited Patch 4.4-06-13-19-01 OpenMG Metadata Extractor for Windows Media Player OpenMG Secure Module 4.4.00 OpenOffice.org Installer 1.0 OverDrive Media Console Palm Picasa 2 Quicken 2006 QuickTime Real Estate Transaction Viewer RealPlayer Rhapsody Player Engine Roxio DigitalMedia Audio Roxio DigitalMedia Copy Roxio DigitalMedia Data Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB970483) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Setting Utility Series SigmaTel Audio Sonic Encoders SonicStage 3.4 SonicStage Mastering Studio 2.2 SonicStage Mastering Studio Audio Filter SonicStage Mastering Studio Audio Filter Custom Preset SonicStage Mastering Studio Plugins Sony Certificate PCH Sony MP4 Shared Library Sony Utilities DLL Sony Video Shared Library Starry Night Starter Update for Windows Internet Explorer 7 (KB976749) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 USB Storage Driver User Agent String Utility VAIO Breeze Wallpaper VAIO Camera Utility VAIO Central VAIO Entertainment Platform VAIO Event Service VAIO Hardware Diagnostics VAIO Light Flo Wallpaper VAIO Media 5.0 VAIO Media AC3 Decoder 1.0 VAIO Media Integrated Server 5.0 VAIO Media Redistribution 5.0 VAIO Media Registration Tool 5.0 VAIO Original Screen Saver VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents VAIO Power Management VAIO Registration VAIO Security Center VAIO Support Central VAIO Update 3 VAIO Wireless LAN Setup Utility VAIOSurveySA Visual Studio .NET Professional 2003 - English Visual Studio.NET Baseline - English WebFldrs XP WinAce Archiver Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 10 Hotfix [See KB886612 for more information] Windows Media Player 11 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 Wireless Switch Setting Utility Yahoo! BrowserPlus Yahoo! Photos Print-at-Home Tool Yahoo! SiteBuilder ==== Event Viewer Messages From Past Week ======== 2/9/2010 4:48:15 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service. 2/9/2010 4:39:22 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Spooler service. 2/14/2010 8:18:27 AM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 2/13/2010 11:18:44 PM, error: Service Control Manager [7031] - The AVG Free WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 2/12/2010 9:33:58 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgTdiX SI3132 2/12/2010 6:31:24 PM, error: Service Control Manager [7000] - The SonyCPU service failed to start due to the following error: The system cannot find the file specified. 2/12/2010 6:31:10 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgTdiX 2/12/2010 6:30:43 PM, error: Service Control Manager [7000] - The OracleDBConsoleorcl service failed to start due to the following error: The system cannot find the file specified. 2/12/2010 6:30:43 PM, error: Service Control Manager [7000] - The OracleDBConsoledb101 service failed to start due to the following error: The system cannot find the file specified. ==== End Of File ===========================
Please do the following:

  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • This will open your Add or Remove Programs
  • A list of installed programs will populate
  • Remove the following programs:


Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6 Update 1


NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


Please download HostsXpert
  • Unzip HostsXpert to it's own folder in a convenient place such as C:\HostsXpert
  • Run: HostsXpert.exe
  • Click: Restore MS Hosts File
  • Click: Replace
  • Click: OK
  • Click: Make ReadOnly
  • Close HostsXpert.



NEXT

  • Go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.


NEXT

Are you being redirected anymore? If so, is it happening in both IE and FireFox
Hi,

Please run the following:



Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
OTL logfile created on: 2/14/2010 9:26:49 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\GUILLERMO\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 471.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.16 Gb Total Space | 22.89 Gb Free Space | 26.57% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SONYLAPTOP
Current User Name: GUILLERMO
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\GUILLERMO\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Lexmark 4300 Series\lxcemon.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\lxcecoms.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\GUILLERMO\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\SlySoft\AnyDVD\ADvdDiscHlp1.dll (SlySoft, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (OracleDBConsoleorcl) – File not found
SRV - (OracleDBConsoledb101) – File not found
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SoundMovieServer) – C:\WINDOWS\System32\snmvtsvc.exe (SoundMovieServer)
SRV - (ADVService) – C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (lxce_device) – C:\WINDOWS\System32\lxcecoms.exe (Lexmark International, Inc.)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (SonicStageMonitoring) – C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
SRV - (gearsec) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr=&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl=en&ie=UTF-8&q=%s&btnG=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l=55&alpha=%s&S=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;*.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/08/19 16:10:28 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/02/14 21:02:49 | 000,000,698 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 4300 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LXCECATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.DLL ()
O4 - HKLM..\Run: [lxcemon.exe] C:\Program Files\Lexmark 4300 Series\lxcemon.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\SONYSYS\VAIO Recovery\Partseal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 3] C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe (Sony Corporation)
O4 - HKLM..\Run: [VAIOCameraUtility] C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\verizon\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKCU..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Uninstall Adobe Download Manager] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor for SD.lnk = C:\Program Files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe (PIXELA CORPORATION)
O4 - Startup: C:\Documents and Settings\GUILLERMO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\GUILLERMO\Start Menu\Programs\Startup\LifeDrive™ Manager.lnk = C:\Program Files\palmOne\LifeDriveMgrTray.exe (palmOne, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_18.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB (VaioInfo.CMClass)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} file://E:\components\hidinputmonitorx.ocx (HidInputMonitorX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader.cab (MySpace Uploader Control)
O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} file://E:\components\A9.ocx (A9Helper.A9)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} http://calshare.calibresys.com/intra/Porta…rces/msddsc.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1159490702250 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://69.20.169.101/activex/AxisCamControl.ocx (CamImage Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\GUILLERMO\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\GUILLERMO\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/15 20:16:41 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2006/03/15 20:15:51 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)

========== Files/Folders - Created Within 14 Days ==========

[2010/02/14 21:24:55 | 000,549,376 | —- | C] (OldTimer Tools) – C:\Documents and Settings\GUILLERMO\Desktop\OTL.exe
[2010/02/14 21:00:45 | 000,000,000 | —D | C] – C:\hostsxpert
[2010/02/14 20:57:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/02/14 20:56:15 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/02/14 20:54:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9 Installer
[2010/02/14 20:51:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/02/14 20:51:19 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/02/14 20:50:58 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/02/14 20:50:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/02/14 10:51:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/02/14 10:05:56 | 000,175,880 | —- | C] (Kaspersky Lab) – C:\Documents and Settings\GUILLERMO\Desktop\TDSSKiller.exe
[2010/02/14 08:20:15 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/02/14 08:17:22 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/02/14 08:17:22 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/02/14 08:17:22 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/02/14 08:17:22 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/02/14 08:16:34 | 000,000,000 | —D | C] – C:\Qoobox
[2010/02/13 10:52:16 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/13 10:51:55 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/02/13 10:51:35 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\GUILLERMO\Desktop\erunt_setup.exe
[2010/02/13 10:50:29 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\GUILLERMO\Desktop\SysRestorePoint.exe
[2010/02/12 22:14:09 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/12 22:14:07 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/12 22:14:07 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/12 22:13:03 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\new_prog.exe
[2010/02/12 22:05:50 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/02/12 21:58:50 | 000,401,720 | —- | C] (Trend Micro Inc.) – C:\HiJackThis.exe
[2010/02/12 18:51:08 | 000,000,000 | —D | C] – C:\Documents and Settings\GUILLERMO\Application Data\Malwarebytes
[2010/02/12 18:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/11 12:31:13 | 000,000,000 | —D | C] – C:\Documents and Settings\GUILLERMO\My Documents\Parks
[2009/01/01 18:39:43 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2009/01/01 14:44:29 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\IsolatedStorage
[2008/07/17 22:19:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/07/17 22:19:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Google
[2008/03/12 21:44:30 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/03/12 21:44:30 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/03/12 21:44:30 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/03/12 21:44:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/12/03 15:00:04 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/01/13 15:31:03 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2007/01/13 15:31:03 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2 C:\Documents and Settings\GUILLERMO\My Documents\*.tmp files -> C:\Documents and Settings\GUILLERMO\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/02/14 21:25:00 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Documents and Settings\GUILLERMO\Desktop\OTL.exe
[2010/02/14 20:58:10 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/02/14 20:52:23 | 000,000,732 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Acrobat_com.lnk
[2010/02/14 19:55:50 | 055,595,572 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/14 12:42:15 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/02/14 10:05:29 | 000,152,714 | —- | M] () – C:\Documents and Settings\GUILLERMO\Desktop\tdsskiller.zip
[2010/02/14 10:03:24 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/14 09:58:51 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/14 08:20:23 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/02/14 07:46:41 | 003,857,112 | R— | M] () – C:\Documents and Settings\GUILLERMO\Desktop\ComboFix.exe
[2010/02/14 07:15:40 | 000,359,929 | —- | M] () – C:\Documents and Settings\GUILLERMO\Desktop\dds.scr
[2010/02/14 07:08:24 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/14 07:06:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/14 07:06:45 | 1063,440,384 | -HS- | M] () – C:\hiberfil.sys
[2010/02/14 06:50:10 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D6D2C90A-97D3-4EE9-8110-36A71DAA1F5A}.job
[2010/02/13 11:12:58 | 000,293,376 | —- | M] () – C:\Documents and Settings\GUILLERMO\Desktop\bg1eqhky.exe
[2010/02/13 10:52:02 | 000,000,767 | —- | M] () – C:\Documents and Settings\GUILLERMO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/13 10:51:55 | 000,000,611 | —- | M] () – C:\Documents and Settings\GUILLERMO\Desktop\NTREGOPT.lnk
[2010/02/13 10:51:55 | 000,000,592 | —- | M] () – C:\Documents and Settings\GUILLERMO\Desktop\ERUNT.lnk
[2010/02/13 10:51:45 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\GUILLERMO\Desktop\erunt_setup.exe
[2010/02/13 10:50:33 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\GUILLERMO\Desktop\SysRestorePoint.exe
[2010/02/13 10:46:43 | 000,000,000 | —- | M] () – C:\Documents and Settings\GUILLERMO\defogger_reenable
[2010/02/13 10:46:31 | 000,050,477 | —- | M] () – C:\Documents and Settings\GUILLERMO\Desktop\Defogger.exe
[2010/02/12 22:14:12 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/12 22:13:14 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\new_prog.exe
[2010/02/12 21:58:57 | 000,401,720 | —- | M] (Trend Micro Inc.) – C:\HiJackThis.exe
[2010/02/12 21:31:11 | 008,650,752 | -H– | M] () – C:\Documents and Settings\GUILLERMO\NTUSER.DAT
[2010/02/12 21:31:11 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\GUILLERMO\ntuser.ini
[2010/02/12 21:31:04 | 016,073,490 | -H– | M] () – C:\Documents and Settings\GUILLERMO\Local Settings\Application Data\IconCache.db
[2010/02/11 10:15:27 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/07 16:05:19 | 000,145,920 | —- | M] () – C:\Documents and Settings\GUILLERMO\My Documents\All Airlines Covered by Aviation Jobs Section.doc
[2010/02/07 15:43:22 | 000,241,400 | —- | M] () – C:\Documents and Settings\GUILLERMO\My Documents\Canadian frog road kills.pdf
[2010/02/07 15:41:57 | 000,382,588 | —- | M] () – C:\Documents and Settings\GUILLERMO\My Documents\Frog call at a higher pitch in traffic noise (Australia).pdf
[2010/02/07 15:39:39 | 000,140,959 | —- | M] () – C:\Documents and Settings\GUILLERMO\My Documents\No. Leopard Frogs vs. Automobiles.pdf
[2010/02/04 14:34:32 | 000,175,880 | —- | M] (Kaspersky Lab) – C:\Documents and Settings\GUILLERMO\Desktop\TDSSKiller.exe
[2 C:\Documents and Settings\GUILLERMO\My Documents\*.tmp files -> C:\Documents and Settings\GUILLERMO\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/14 20:58:10 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/02/14 20:52:23 | 000,000,732 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Acrobat_com.lnk
[2010/02/14 10:05:26 | 000,152,714 | —- | C] () – C:\Documents and Settings\GUILLERMO\Desktop\tdsskiller.zip
[2010/02/14 08:20:23 | 000,000,209 | —- | C] () – C:\Boot.bak
[2010/02/14 08:20:18 | 000,260,272 | —- | C] () – C:\cmldr
[2010/02/14 08:17:22 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/02/14 08:17:22 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/02/14 08:17:22 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/02/14 08:17:22 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/02/14 08:17:22 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/02/14 07:46:35 | 003,857,112 | R— | C] () – C:\Documents and Settings\GUILLERMO\Desktop\ComboFix.exe
[2010/02/14 07:15:30 | 000,359,929 | —- | C] () – C:\Documents and Settings\GUILLERMO\Desktop\dds.scr
[2010/02/13 11:11:56 | 000,293,376 | —- | C] () – C:\Documents and Settings\GUILLERMO\Desktop\bg1eqhky.exe
[2010/02/13 10:52:02 | 000,000,767 | —- | C] () – C:\Documents and Settings\GUILLERMO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/13 10:51:55 | 000,000,611 | —- | C] () – C:\Documents and Settings\GUILLERMO\Desktop\NTREGOPT.lnk
[2010/02/13 10:51:55 | 000,000,592 | —- | C] () – C:\Documents and Settings\GUILLERMO\Desktop\ERUNT.lnk
[2010/02/13 10:46:43 | 000,000,000 | —- | C] () – C:\Documents and Settings\GUILLERMO\defogger_reenable
[2010/02/13 10:46:27 | 000,050,477 | —- | C] () – C:\Documents and Settings\GUILLERMO\Desktop\Defogger.exe
[2010/02/12 22:14:12 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/12 16:04:50 | 000,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/02/07 16:04:41 | 000,145,920 | —- | C] () – C:\Documents and Settings\GUILLERMO\My Documents\All Airlines Covered by Aviation Jobs Section.doc
[2010/02/07 15:43:22 | 000,241,400 | —- | C] () – C:\Documents and Settings\GUILLERMO\My Documents\Canadian frog road kills.pdf
[2010/02/07 15:41:57 | 000,382,588 | —- | C] () – C:\Documents and Settings\GUILLERMO\My Documents\Frog call at a higher pitch in traffic noise (Australia).pdf
[2010/02/07 15:39:39 | 000,140,959 | —- | C] () – C:\Documents and Settings\GUILLERMO\My Documents\No. Leopard Frogs vs. Automobiles.pdf
[2010/01/16 22:40:42 | 000,201,328 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/01/31 20:06:54 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\Zlib.dll
[2008/05/27 21:56:44 | 000,360,584 | —- | C] () – C:\WINDOWS\System32\drivers\avgtdix.sys
[2008/03/09 21:31:18 | 000,000,785 | —- | C] () – C:\WINDOWS\GARMINWT.INI
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/02/02 22:28:59 | 000,000,000 | —- | C] () – C:\WINDOWS\autorun.INI
[2007/10/27 20:38:52 | 000,000,652 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/03/20 20:50:21 | 000,000,173 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/02/04 23:23:02 | 000,316,696 | —- | C] () – C:\WINDOWS\System32\ImagXpr6.dll
[2007/01/25 22:51:55 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2007/01/12 13:30:23 | 000,000,000 | —- | C] () – C:\WINDOWS\bbcauto.INI
[2007/01/06 13:31:35 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2006/10/21 22:52:22 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2006/10/19 19:45:39 | 000,001,778 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/12 18:47:10 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXPRMON.DLL
[2006/10/12 18:47:10 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\LXPMONUI.DLL
[2006/10/12 18:44:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxcevs.dll
[2006/10/10 20:58:15 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2006/10/09 18:40:38 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/09/28 20:01:17 | 000,000,000 | —- | C] () – C:\WINDOWS\frontpg.ini
[2006/09/28 19:57:14 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2006/09/28 19:57:14 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2006/09/28 19:56:50 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2006/09/28 19:56:50 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2006/09/28 19:56:48 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2006/09/19 18:02:00 | 000,031,232 | —- | C] () – C:\Documents and Settings\GUILLERMO\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/15 20:32:37 | 000,000,132 | —- | C] () – C:\Documents and Settings\GUILLERMO\Local Settings\Application Data\fusioncache.dat
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2006/06/12 14:43:22 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2006/03/29 16:13:07 | 000,002,154 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/03/29 16:01:13 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2006/03/29 15:58:56 | 000,000,219 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/03/29 15:58:14 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/03/29 15:58:14 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/03/29 15:58:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/03/29 15:58:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/03/29 15:58:14 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/03/29 15:58:14 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/03/29 15:51:50 | 000,000,520 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/17 19:55:21 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/16 14:45:15 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/03/16 14:24:17 | 000,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/03/15 20:23:59 | 000,000,811 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/15 18:57:00 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/03/15 18:56:49 | 000,000,758 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/11/01 20:53:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/05 17:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/06/12 15:21:12 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll

========== LOP Check ==========

[2009/01/01 14:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Amazon
[2009/11/08 22:50:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/11/04 22:18:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2006/12/14 17:43:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2006/03/29 16:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2007/03/20 21:14:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
[2007/01/06 13:16:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2009/01/01 19:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PIXELA
[2007/11/10 23:06:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/09/26 20:59:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/10/18 20:43:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/01/19 23:30:04 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\Amazon
[2009/03/10 07:52:02 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\Citrix
[2008/02/24 13:59:37 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\Downloaded Installations
[2007/01/06 13:14:43 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\HotSync
[2009/03/10 07:53:19 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\ICAClient
[2006/08/15 20:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\InterVideo
[2006/08/16 00:23:49 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\Leadertech
[2009/05/12 11:32:52 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\OverDrive
[2008/09/26 11:43:45 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\SlySoft
[2008/08/08 14:17:00 | 000,000,000 | —D | M] – C:\Documents and Settings\GUILLERMO\Application Data\Smith Micro
[2010/02/14 06:50:10 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{D6D2C90A-97D3-4EE9-8110-36A71DAA1F5A}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2010/02/12 21:58:57 | 000,401,720 | —- | M] (Trend Micro Inc.) – C:\HiJackThis.exe
[2010/02/12 22:13:14 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\new_prog.exe


< MD5 for: AGP440.SYS >
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/06/15 11:29:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/06/15 11:29:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/06/15 11:29:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/06/15 11:29:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/04 01:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/10 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2004/08/04 01:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/10 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 19:11:51 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[2010/01/05 05:00:20 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2010/01/05 05:00:21 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/03/15 12:02:55 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/03/15 12:02:55 | 000,663,552 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/03/15 12:02:54 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >

OTL Extras logfile created on: 2/14/2010 9:26:49 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\GUILLERMO\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 471.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.16 Gb Total Space | 22.89 Gb Free Space | 26.57% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SONYLAPTOP
Current User Name: GUILLERMO
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sony\Click to DVD 2\CtoDvd.exe" = C:\Program Files\Sony\Click to DVD 2\CtoDvd.exe:*:Disabled:Click to DVD – (Sony Corporation)
"C:\Program Files\palmOne\Hotsync.exe" = C:\Program Files\palmOne\Hotsync.exe:*:Enabled:HotSync® Manager Application – (PalmSource, Inc)
"C:\Program Files\Sony\VAIO Media 5.0\Vc.exe" = C:\Program Files\Sony\VAIO Media 5.0\Vc.exe:*:Disabled:[VAIO Media] VAIO Media – (Sony Corporation)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Microsoft Office\OFFICE11\MSPUB.EXE" = C:\Program Files\Microsoft Office\OFFICE11\MSPUB.EXE:*:Enabled:Microsoft Office Publisher – (Microsoft Corporation)
"C:\Program Files\burst\core-new1.1.3\btdownloadheadless.exe" = C:\Program Files\burst\core-new1.1.3\btdownloadheadless.exe:*:Enabled:burst! download engine – ()
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{013E1BA8-C815-4E27-BCB9-D6B1B2E24094}" = SonicStage Mastering Studio Audio Filter Custom Preset
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility
"{1417F599-1DBD-4499-9375-B2813E9F890C}" = VAIO Camera Utility
"{16EE7EAD-CC3D-4359-8438-6259867331ED}" = MixMeister Express 6 Demo
"{17B66E83-1BC9-11D5-A54A-0090278A1BB8}" = Microsoft FrontPage Client - English
"{184EB198-1DBA-46DB-B728-7A5FC13D5C2B}_is1" = Yahoo! Photos Print-at-Home Tool
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{20610409-CA18-41A6-9E21-A93AE82EE7C5}" = Visual Studio .NET Professional 2003 - English
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2624B680-02BC-4CBC-839C-DA20DF6EF6EC}" = Citrix Presentation Server Client
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 18
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper
"{314932C5-1387-4783-99F7-E292DD2585A9}" = GreatBattlesCD
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{34D6EED8-7650-4E1C-BC26-F5B2DDE185C6}" = OverDrive Media Console
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{52242A19-B603-4A86-9101-8B6E0442C16C}" = Palm
"{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{5757AE1A-1DB4-4898-9806-09F77FBD5E57}" = MSDN Library for Visual Studio .NET 2003
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility
"{5B39603F-2A77-40E6-950D-ED7B8307933D}" = Microsoft IntelliPoint 5.3
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{624C7A8B-B882-41F9-A1DC-D4AF5C5CF49E}" = MobiSystems Money
"{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9B953606-000E-491C-B74D-78ECFDD520A0}" = OpenMG Metadata Extractor for Windows Media Player
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9DF095E1-8EC2-4892-8740-93769DB1E944}" = User Agent String Utility
"{9E158BB9-37B9-464B-837E-CC1D5766291B}" = VAIO Update 3
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.03 Menu Data
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 3.4
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A87EBA79-93DB-4A87-B9BA-62F8FB12D993}" = ImageStation
"{A947C2B3-7445-42C4-9063-EE704CACCB22}" = VAIO Hardware Diagnostics
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB467B85-4F52-48C2-AEED-0673D00417B0}" = SonicStage Mastering Studio Audio Filter
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{BF3B304B-8A18-452D-A19F-6012CA8418D7}" = SonicStage Mastering Studio 2.2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C27BF761-C499-488D-A964-A3718BC6EC3E}" = DSD Direct
"{C89EB8CD-675F-44F4-9729-4C9A8FAC2D4F}" = DSD Playback Plug-in 1.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D4D24FE5-FAB3-4FE2-AFFC-623955F4DF3A}" = Visual Studio.NET Baseline - English
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
"{E1D7C392-EAF5-405F-A31D-BBD3B56C0C6A}" = ImageMixer 3 SE for SD
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.20
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E89B484C-B913-49A0-959B-89E836001658}" = GEAR 32bit Driver Installer
"{EE7EB179-5AA2-4B28-AC92-5CBAAF82BA7F}" = SonicStage Mastering Studio Plugins
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE3BF611-9B8B-44DC-A424-F8C4BA122A1D}" = VAIO Security Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AGEIA PhysX v2.4.4" = AGEIA PhysX v2.4.4
"AllMusicConverter_is1" = AllMusicConverter 3.1.1
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AnyDVD" = AnyDVD
"AVG9Uninstall" = AVG Free 9.0
"Botanical Images Vol 1" = Botanical Images Vol 1
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CloneDVD2" = CloneDVD2
"CloneDVDmobile" = CloneDVDmobile
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CSCLIB" = Canon Camera Support Core Library
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"GARMIN 500 Series Trainer" = GARMIN 500 Series Trainer
"GENEUIDE" = USB Storage Driver
"Google Updater" = Google Updater
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"InstallShield_{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"InstallShield_{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"Lexmark 4300 Series" = Lexmark 4300 Series
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mmersetup_is1" = MixMeister Express 6.1.8
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyCamera" = Canon Utilities MyCamera
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenMG HotFix4.4-05-12-06-01" = OpenMG Limited Patch 4.4-06-13-19-01
"Picasa2" = Picasa 2
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"Real Estate Transaction Viewer" = Real Estate Transaction Viewer
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Starry Night Starter" = Starry Night Starter
"Visual Studio .NET Professional 2003 - English" = Microsoft Visual Studio .NET Professional 2003 - English
"WinAce Archiver" = WinAce Archiver
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"burst" = burst! v3.1.0
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/13/2010 10:26:39 PM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 489
Description = wuauclt (5428) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 2/13/2010 10:26:39 PM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 455
Description = wuaueng.dll (5428) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 2/13/2010 10:27:14 PM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 489
Description = wuauclt (5860) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 2/13/2010 10:27:14 PM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 455
Description = wuaueng.dll (5860) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 2/13/2010 10:27:24 PM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 489
Description = wuauclt (5860) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 2/13/2010 10:27:24 PM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 455
Description = wuaueng.dll (5860) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 2/14/2010 10:26:23 AM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 489
Description = wuauclt (5732) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 2/14/2010 10:26:23 AM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 455
Description = wuaueng.dll (5732) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 2/14/2010 10:26:47 AM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 489
Description = wuauclt (5732) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 2/14/2010 10:26:47 AM | Computer Name = SONYLAPTOP | Source = ESENT | ID = 455
Description = wuaueng.dll (5732) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

[ System Events ]
Error - 2/14/2010 8:07:46 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AvgTdiX

Error - 2/14/2010 8:08:13 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7000
Description = The SonyCPU service failed to start due to the following error: %%2

Error - 2/14/2010 8:08:16 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7000
Description = The SonyCPU service failed to start due to the following error: %%2

Error - 2/14/2010 9:18:27 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 2/14/2010 9:23:09 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 2/14/2010 9:29:28 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 2/14/2010 10:36:30 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 2/14/2010 10:37:29 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 2/14/2010 10:47:04 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 2/14/2010 10:47:39 AM | Computer Name = SONYLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.


< End of report >
Hi,

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    [2010/02/14 06:50:10 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D6D2C90A-97D3-4EE9-8110-36A71DAA1F5A}.job
    [2010/02/13 11:12:58 | 000,293,376 | —- | M] () – C:\Documents and Settings\GUILLERMO\Desktop\bg1eqhky.exe
    
    :Files
    C:\WINDOWS\system32\drivers\atapi.sys | C:\WINDOWS\ServicePackFiles\i386\atapi.sys /replace
    
    :Commands
    [purity]
    [emptytemp]
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT


Canadian frog road kills.pdf
No. Leopard Frogs vs. Automobiles.pdf

are those files you installed yourself? do you trust the source?

Any improvement in the redirection?

what sites are you being redirected to? (mung the link)
Those are files that I downloaded and the source was trusted (they were from a biological journal suggested by herpdigest.com). I am getting redirected to a different site almost everytime. I googled rowing, clicked on the link for usrowing.org and got sent to savecompare.com and then another link for concept2.com and it sends me to shoppingsteps.com instead. My log is below. I will not be checking this forum again until tomorrow morning. Thanks! All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. C:\WINDOWS\tasks\User_Feed_Synchronization-{D6D2C90A-97D3-4EE9-8110-36A71DAA1F5A}.job moved successfully. C:\Documents and Settings\GUILLERMO\Desktop\bg1eqhky.exe moved successfully. ========== FILES ========== Unable to replace file: C:\WINDOWS\system32\drivers\atapi.sys with C:\WINDOWS\ServicePackFiles\i386\atapi.sys without a reboot. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: GUILLERMO ->Temp folder emptied: 99827145 bytes ->Temporary Internet Files folder emptied: 20728614 bytes ->Java cache emptied: 132544871 bytes ->Apple Safari cache emptied: 5830620 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32835 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: SONYLAPTOP %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 17427 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 67 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 247.00 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.1.28.0 log created on 02142010_222102 Files\Folders moved on Reboot… C:\WINDOWS\temp\Perflib_Perfdata_94c.dat moved successfully. Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI