Still getting nortons warning - tidserv reqest 2 blocked
still getting browser redirected
08:15:50:078 3348 TDSS rootkit removing tool [removed] Mar 22 2010 10:43:04
08:15:50:093 3348 ================================================================================
08:15:50:093 3348 SystemInfo:
08:15:50:093 3348 OS Version: 5.1.2600 ServicePack: 3.0
08:15:50:093 3348 Product type: Workstation
08:15:50:093 3348 ComputerName: OWNER-92DFBD76A
08:15:50:093 3348 UserName: User
08:15:50:093 3348 Windows directory: C:\WINDOWS
08:15:50:093 3348 Processor architecture: Intel x86
08:15:50:093 3348 Number of processors: 4
08:15:50:093 3348 Page size: 0x1000
08:15:50:093 3348 Boot type: Normal boot
08:15:50:093 3348 ================================================================================
08:15:50:093 3348 UnloadDriverW: NtUnloadDriver error 1
08:15:50:093 3348 ForceUnloadDriverW: UnloadDriverW(klmd21) error 1
08:15:50:140 3348 LoadDriverW: Driver already loaded
08:15:50:140 3348 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
08:15:50:140 3348 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
08:15:50:140 3348 wfopen_ex: Trying to KLMD file open
08:15:50:140 3348 wfopen_ex: File opened ok (Flags 2)
08:15:50:140 3348 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
08:15:50:140 3348 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
08:15:50:140 3348 wfopen_ex: Trying to KLMD file open
08:15:50:140 3348 wfopen_ex: File opened ok (Flags 2)
08:15:50:140 3348 Initialize success
08:15:50:140 3348
08:15:50:140 3348 Scanning Services …
08:15:50:609 3348 Raw services enum returned 339 services
08:15:50:609 3348
08:15:50:609 3348 Scanning Kernel memory …
08:15:50:609 3348 Devices to scan: 2
08:15:50:609 3348
08:15:50:609 3348 Driver Name: Disk
08:15:50:609 3348 IRP_MJ_CREATE : BA0EEBB0
08:15:50:609 3348 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
08:15:50:609 3348 IRP_MJ_CLOSE : BA0EEBB0
08:15:50:609 3348 IRP_MJ_READ : BA0E8D1F
08:15:50:609 3348 IRP_MJ_WRITE : BA0E8D1F
08:15:50:609 3348 IRP_MJ_QUERY_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_SET_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_QUERY_EA : 804F4562
08:15:50:609 3348 IRP_MJ_SET_EA : 804F4562
08:15:50:609 3348 IRP_MJ_FLUSH_BUFFERS : BA0E92E2
08:15:50:609 3348 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_DIRECTORY_CONTROL : 804F4562
08:15:50:609 3348 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
08:15:50:609 3348 IRP_MJ_DEVICE_CONTROL : BA0E93BB
08:15:50:609 3348 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
08:15:50:609 3348 IRP_MJ_SHUTDOWN : BA0E92E2
08:15:50:609 3348 IRP_MJ_LOCK_CONTROL : 804F4562
08:15:50:609 3348 IRP_MJ_CLEANUP : 804F4562
08:15:50:609 3348 IRP_MJ_CREATE_MAILSLOT : 804F4562
08:15:50:609 3348 IRP_MJ_QUERY_SECURITY : 804F4562
08:15:50:609 3348 IRP_MJ_SET_SECURITY : 804F4562
08:15:50:609 3348 IRP_MJ_POWER : BA0EAC82
08:15:50:609 3348 IRP_MJ_SYSTEM_CONTROL : BA0EF99E
08:15:50:609 3348 IRP_MJ_DEVICE_CHANGE : 804F4562
08:15:50:609 3348 IRP_MJ_QUERY_QUOTA : 804F4562
08:15:50:609 3348 IRP_MJ_SET_QUOTA : 804F4562
08:15:50:625 3348 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
08:15:50:625 3348
08:15:50:625 3348 Driver Name: atapi
08:15:50:625 3348 IRP_MJ_CREATE : 890FBAC8
08:15:50:625 3348 IRP_MJ_CREATE_NAMED_PIPE : 890FBAC8
08:15:50:625 3348 IRP_MJ_CLOSE : 890FBAC8
08:15:50:625 3348 IRP_MJ_READ : 890FBAC8
08:15:50:625 3348 IRP_MJ_WRITE : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_EA : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_EA : 890FBAC8
08:15:50:625 3348 IRP_MJ_FLUSH_BUFFERS : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_VOLUME_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_VOLUME_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_DIRECTORY_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_FILE_SYSTEM_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_DEVICE_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_INTERNAL_DEVICE_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_SHUTDOWN : 890FBAC8
08:15:50:625 3348 IRP_MJ_LOCK_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_CLEANUP : 890FBAC8
08:15:50:625 3348 IRP_MJ_CREATE_MAILSLOT : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_SECURITY : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_SECURITY : 890FBAC8
08:15:50:625 3348 IRP_MJ_POWER : 890FBAC8
08:15:50:625 3348 IRP_MJ_SYSTEM_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_DEVICE_CHANGE : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_QUOTA : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_QUOTA : 890FBAC8
08:15:50:625 3348 Driver "atapi" infected by TDSS rootkit!
08:15:50:625 3348 C:\WINDOWS\system32\drivers\tsk7.tmp - Verdict: 3
08:15:50:625 3348
08:15:50:625 3348 Completed
08:15:50:625 3348
08:15:50:625 3348 Results:
08:15:50:625 3348 Memory objects infected / cured / cured on reboot: 1 / 0 / 0
08:15:50:640 3348 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
08:15:50:640 3348 File objects infected / cured / cured on reboot: 0 / 0 / 0
08:15:50:640 3348
08:15:50:640 3348 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
08:15:50:640 3348 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
08:15:50:640 3348 UnloadDriverW: NtUnloadDriver error 1
08:15:50:640 3348 KLMD(ARK) unloaded successfully
OTL Extras logfile created on: 6/04/2010 8:26:48 AM - Run 1
OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 213.24 Gb Free Space | 71.54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-92DFBD76A
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"E:\programs\LimeWire\LimeWire.exe" = E:\programs\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"C:\Program Files\Java\jre6\bin\rmiregistry.exe" = C:\Program Files\Java\jre6\bin\rmiregistry.exe:*:Disabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{110E7958-3EE1-4684-9168-CD5D73A2CDDD}" = Mirar
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{251C3815-7A55-4607-A82D-C3B98F0FBAB8}" = Sony Vegas 7.0
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{5AE91C01-5906-11D5-A50C-006067797177}" = Cashflow Manager 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71A41426-C7A4-4DCF-A9ED-C5B4B105ED1D}" = Sony Media Manager 2.2
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9811A185-3D3D-11D6-9E14-00036D172B00}" = Adobe MPEG Encoder
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{FB3BE405-6BF0-490A-84B3-00611385EA0D}" = Common-Use Signing Interface
"4Videosoft DVD to QuickTime Converter_is1" = 4Videosoft DVD to QuickTime Converter
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Premiere 6.5" = Adobe Premiere 6.5
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"CanoCraft CS-P 3.7" = Canon CanoCraft CS-P 3.7
"Canon Setup Utility 2.0" = Canon Setup Utility 2.0
"CANONBJ_Deinstall_CNMCP78.DLL" = Canon iP4200
"Common-Use Signing Interface" = Common-Use Signing Interface
"Creative Mass Storage Drivers" = Creative Mass Storage Drivers
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"Efficient Diary_is1" = Efficient Diary 1.76
"Ewisoft Website Builder (include eCommerce Builder)_is1" = Ewisoft Website Builder (include eCommerce Builder) Version 5
"Fax Machine_is1" = Fax Machine 4.33
"Free DVD Ripper 2.25_is1" = Free DVD Ripper Version 2.25
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MuVo Driver" = Creative Mass Storage Drivers
"NAV" = Norton AntiVirus
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"SMPlayer" = SMPlayer 0.6.7
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SysInfo" = Creative System Information
"TVEpaDrv" = Kaiser Baas USB VIDEO TO DVD MAKER Device Driver
"Ulead Photo Express 2.0 SE" = Ulead Photo Express 2.0 SE
"Ultra QuickTime Converter_is1" = Ultra QuickTime Converter 3.2.0104
"Uninstall_is1" = Uninstall 1.0.0.1
"VobSub" = VobSub v2.23 (Remove Only)
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate
"Xvid_is1" = Xvid 1.2.2 final uninstall
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/04/2010 7:23:06 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
spybotsd.exe, version 1.6.2.46, fault address 0x00001941.
Error - 4/04/2010 2:59:25 AM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
Error - 4/04/2010 5:31:54 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.
Error - 4/04/2010 5:38:37 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
Error - 4/04/2010 5:40:20 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 4.1.249.1045, fault address 0x0001b1a1.
Error - 4/04/2010 5:42:23 PM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/04/2010 5:42:23 PM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/04/2010 5:42:26 PM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/04/2010 6:13:05 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.
Error - 4/04/2010 11:31:54 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.
[ System Events ]
Error - 5/04/2010 7:50:41 AM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/04/2010 5:19:28 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/04/2010 5:19:28 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/04/2010 5:20:35 PM | Computer Name = OWNER-92DFBD76A | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022156E075E has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 5/04/2010 5:20:41 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 5/04/2010 5:20:41 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 5/04/2010 6:09:04 PM | Computer Name = OWNER-92DFBD76A | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 5/04/2010 6:09:04 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/04/2010 6:09:04 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/04/2010 6:09:21 PM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt
< End of report >
OTL logfile created on: 6/04/2010 8:26:48 AM - Run 1
OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 213.24 Gb Free Space | 71.54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-92DFBD76A
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/04/06 08:17:04 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
PRC - [2009/08/22 16:37:15 | 000,117,640 | R— | M] (Symantec Corporation) – C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/14 22:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/04/14 22:00:00 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\ntvdm.exe
PRC - [2008/04/14 22:00:00 | 000,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Outlook Express\msimn.exe
PRC - [2004/12/02 18:23:34 | 000,102,400 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
PRC - [2003/10/24 14:37:56 | 000,217,194 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
PRC - [1998/07/08 12:01:28 | 000,055,296 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
PRC - [1998/03/19 14:22:02 | 000,041,984 | —- | M] (Caere Corporation) – C:\OPLIMIT\OCRAWR32.EXE
========== Modules (SafeList) ==========
MOD - [2010/04/06 08:17:04 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
MOD - [1998/07/11 13:34:52 | 000,135,680 | —- | M] (Caere Corporation) – C:\OPLIMIT\OAHOOK32.DLL
========== Win32 Services (SafeList) ==========
SRV - [2009/08/22 16:37:15 | 000,117,640 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe – (Norton AntiVirus)
SRV - [2002/12/17 16:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 16:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[2010/04/02 16:02:15 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/04/05 21:50:35 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe ()
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe (Ulead Systems, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (Caere Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/01/19 23:45:43 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746478449557504)
========== Files/Folders - Created Within 14 Days ==========
[2010/04/06 08:16:59 | 000,561,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/04/06 08:15:03 | 000,000,000 | —D | C] – C:\tds old log
[2010/04/06 08:09:38 | 000,036,488 | —- | C] (Kaspersky Lab, SLA) – C:\WINDOWS\System32\drivers\klmdb.sys
[2010/04/05 13:27:18 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/04/05 13:24:50 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/05 13:24:50 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/05 13:24:50 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/05 13:24:50 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/05 13:24:17 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/05 13:20:18 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/04 17:41:55 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2010/04/04 09:19:44 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\User\Desktop\spybotsd162.exe
[2010/04/03 18:33:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2010/04/03 18:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/04/03 18:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/04/02 20:48:24 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/02 20:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/04/02 20:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/02 20:12:52 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/02 16:37:42 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/02 14:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/02 14:10:55 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/04/02 12:37:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/04/02 12:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/02/27 09:44:19 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/02/27 09:44:19 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/19 10:30:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\CyberLink
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[2009/05/18 06:58:57 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/05/17 12:33:13 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/12 06:57:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010/04/06 08:17:04 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/04/06 08:13:16 | 000,535,230 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/06 08:13:16 | 000,450,960 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/06 08:13:16 | 000,075,452 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/06 08:09:38 | 000,036,488 | —- | M] (Kaspersky Lab, SLA) – C:\WINDOWS\System32\drivers\klmdb.sys
[2010/04/06 08:09:13 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/04/06 08:09:11 | 000,000,394 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2010/04/06 08:08:53 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/06 08:08:48 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/06 08:08:47 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/06 08:08:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/06 08:07:25 | 008,912,896 | —- | M] () – C:\Documents and Settings\User\ntuser.dat
[2010/04/06 08:07:25 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\User\ntuser.ini
[2010/04/06 08:07:20 | 000,000,757 | —- | M] () – C:\WINDOWS\oplimit.ini
[2010/04/06 07:29:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/05 21:51:23 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/05 21:50:35 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/04/05 18:40:09 | 003,174,328 | -H– | M] () – C:\Documents and Settings\User\Local Settings\Application Data\IconCache.db
[2010/04/05 18:15:08 | 000,019,968 | —- | M] () – C:\Documents and Settings\User\Desktop\TDSS rootkit removing tool.doc
[2010/04/05 17:55:39 | 000,154,469 | —- | M] () – C:\Documents and Settings\User\Desktop\tdsskiller.zip
[2010/04/05 13:27:28 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/04/05 13:19:59 | 003,907,280 | R— | M] () – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2010/04/05 08:16:27 | 000,284,915 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.zip
[2010/04/05 07:55:55 | 000,525,824 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/04/05 07:49:17 | 000,050,477 | —- | M] () – C:\Documents and Settings\User\Desktop\Defogger.exe
[2010/04/04 20:18:15 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/04/04 20:18:14 | 000,000,108 | —- | M] () – C:\WINDOWS\System32\temp_0000_30437.aok
[2010/04/04 18:56:11 | 000,231,390 | —- | M] () – C:\Documents and Settings\User\Desktop\RootkitRevealer.zip
[2010/04/04 17:41:49 | 001,339,288 | —- | M] () – C:\Documents and Settings\User\Desktop\sar_15_sfx.exe
[2010/04/04 09:50:14 | 000,000,154 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/04/04 09:21:13 | 000,000,933 | —- | M] () – C:\Documents and Settings\User\Desktop\Spybot - Search & Destroy.lnk
[2010/04/04 09:19:58 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\User\Desktop\spybotsd162.exe
[2010/04/04 08:30:52 | 000,220,160 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/02 16:24:53 | 000,533,691 | —- | M] () – C:\Documents and Settings\User\Desktop\Main News - The Northern Rivers Echo Newspaper, Lismore.mht
[2010/04/01 07:30:01 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/03/30 19:00:39 | 000,001,186 | -HS- | M] () – C:\WINDOWS\System32\1213155173
[2010/03/29 23:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/29 23:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/04/05 18:15:08 | 000,019,968 | —- | C] () – C:\Documents and Settings\User\Desktop\TDSS rootkit removing tool.doc
[2010/04/05 17:55:38 | 000,154,469 | —- | C] () – C:\Documents and Settings\User\Desktop\tdsskiller.zip
[2010/04/05 13:27:27 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/04/05 13:27:21 | 000,260,272 | —- | C] () – C:\cmldr
[2010/04/05 13:24:50 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/05 13:24:50 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/05 13:24:50 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/05 13:24:50 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/05 13:24:50 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/05 13:18:33 | 003,907,280 | R— | C] () – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2010/04/05 08:16:22 | 000,284,915 | —- | C] () – C:\Documents and Settings\User\Desktop\gmer.zip
[2010/04/05 07:51:51 | 000,525,824 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/04/05 07:49:06 | 000,050,477 | —- | C] () – C:\Documents and Settings\User\Desktop\Defogger.exe
[2010/04/04 20:18:14 | 000,000,108 | —- | C] () – C:\WINDOWS\System32\temp_0000_30437.aok
[2010/04/04 18:56:10 | 000,231,390 | —- | C] () – C:\Documents and Settings\User\Desktop\RootkitRevealer.zip
[2010/04/04 17:41:43 | 001,339,288 | —- | C] () – C:\Documents and Settings\User\Desktop\sar_15_sfx.exe
[2010/04/04 09:21:13 | 000,000,933 | —- | C] () – C:\Documents and Settings\User\Desktop\Spybot - Search & Destroy.lnk
[2010/04/02 16:24:52 | 000,533,691 | —- | C] () – C:\Documents and Settings\User\Desktop\Main News - The Northern Rivers Echo Newspaper, Lismore.mht
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/09/11 08:20:12 | 000,012,288 | —- | C] () – C:\Documents and Settings\User\Application Data\plugcach.fon
[2009/05/27 17:15:58 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\mdmparm.dll
[2009/05/27 17:15:58 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ClassXps.dll
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/05/21 13:21:17 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/05/21 13:21:17 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,394 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 10:50:07 | 000,000,154 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/24 13:03:05 | 008,912,896 | —- | C] () – C:\Documents and Settings\User\ntuser.dat
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 20:22:52 | 000,220,160 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:11:09 | 000,000,278 | -HS- | C] () – C:\Documents and Settings\User\ntuser.ini
[2009/01/19 14:11:08 | 000,001,024 | -H– | C] () – C:\Documents and Settings\User\ntuser.dat.LOG
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
========== LOP Check ==========
[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/11/15 16:56:24 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/02/18 12:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2009/11/15 09:34:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2010/04/04 20:53:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\LimeWire
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/01/03 11:43:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/04/14 22:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/04/14 22:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\Program Files\atapi.sys
[2010/04/05 19:19:20 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2010/04/06 08:08:04 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 22:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 22:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 22:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 22:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2007/01/12 21:30:08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\CyberLink\PowerDirector\EventLog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/14 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008/04/14 22:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 22:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 22:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[2008/04/14 22:00:00 | 000,068,768 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\mmsystem.dll
[2008/04/14 22:00:00 | 000,005,120 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\shell.dll
[2008/04/14 22:00:00 | 000,013,888 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\toolhelp.dll
[9 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\System32\config\*.sav >
[2009/01/19 23:49:01 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/19 23:49:01 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/19 23:49:01 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >