Satchfan
I could not use the regular post. 'The forum would not let me reply to your post. It said the topic was locked. Sorry it took so long to get back to you. I was very busy with work. I copied your post below and the OTL logfile with the extras is below that. The OTL logfile with Minimum output is below that with extra file.
You asked about BIOS. The BIOS not installed started before the infection. I do not know if it is related. I do not know what the BSOD is. MS ws wrong because I doubled the RAM about a month ago. I still get messages that say I do not have enough memory. I often lose all the lettering on webpages. I often get blue screens. I got at least 4 blue screens today. I have had to rewrite this post to you 3 times because of blue screens. My computer will use about 800 MB on a very active multitasking when opening the task manager. It is usually much less.
For gmer - You said " (typically C:\) Drives/Partition other than Systemdrive " This was not an option. I presume you meant just C: so I unchecked that.
I hope this is all you need. I want to set up a virtual sandbox in my browser so I do not have this happen again if possible when it gets fixed.
Thanks for your help.
gbsk
Hello gbsk
OK, let’s try to find out what is going on with your computer.
I have a couple of questions about what you wrote in your post:
1. Why you think that Microsoft were wrong when they said they had cleared the infection.
2. When did the BSOD and the Bios error message begin – was this happening before the new memory was added?
Also, to help me further understand what is happening on your machine, I’d like you to run a couple of scans.
Run OTL
Download OTL to your Desktop
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Check the boxes beside LOP Check and Purity Check.
Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
CREATERESTOREPOINT
Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Download the GMER Rootkit Scanner
Download GMER Rootkit Scanner from here or here.
Extract the contents of the zipped file to desktop.
Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following …
Sections
IAT/EAT
(typically C:\) Drives/Partition other than Systemdrive
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Logs to include with next post:
OTL.txt
Extras.txt
Gmer.txt
Thanks
Satchfan
——————–
In Training at WTT Classroom
OTL logfile created on: 4/17/2010 6:08:26 AM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 19.72 Gb Free Space | 51.55% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/04/10 09:48:05 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe
PRC - [2010/04/05 21:11:44 | 002,010,864 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/02/21 06:03:12 | 001,093,208 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/02/11 10:53:42 | 002,756,488 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/01/28 22:22:16 | 003,427,160 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360.exe
PRC - [2010/01/14 17:08:16 | 000,378,128 | —- | M] (PC Tools) – C:\Program Files\ThreatFire\TFTray.exe
PRC - [2009/12/24 18:02:32 | 001,280,272 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360tray.exe
PRC - [2009/12/24 18:02:30 | 000,311,568 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360srv.exe
PRC - [2009/12/23 16:57:18 | 000,093,320 | —- | M] (McAfee, Inc.) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/12/09 19:02:38 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2004/08/04 01:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) – C:\WIXP\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/04/10 09:48:05 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe
MOD - [2010/02/23 15:45:10 | 000,015,056 | —- | M] (McAfee, Inc.) – c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2009/12/24 18:02:28 | 000,237,840 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360mon.dll
MOD - [2004/08/04 01:57:02 | 001,050,624 | —- | M] (Microsoft Corporation) – C:\WIXP\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/02/11 10:53:39 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Stopped] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Web Scanner)
SRV - [2010/02/11 10:53:39 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Stopped] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Mail Scanner)
SRV - [2010/02/11 10:53:39 | 000,040,384 | —- | M] (ALWIL Software) [Auto | Stopped] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2010/01/25 18:20:19 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/12/24 18:02:30 | 000,311,568 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\IObit Security 360\is360srv.exe – (IS360service)
SRV - [2009/12/23 16:57:18 | 000,093,320 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe – (McAfee SiteAdvisor Service)
SRV - [2009/12/09 19:02:38 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
========== Driver Services (SafeList) ==========
DRV - [2010/02/22 16:42:32 | 000,012,872 | —- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Running] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2010/02/22 16:42:31 | 000,066,632 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/22 16:42:31 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV)
DRV - [2010/02/11 10:42:34 | 000,046,672 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WIXP\system32\drivers\aswTdi.sys – (aswTdi)
DRV - [2010/02/11 10:42:13 | 000,162,512 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WIXP\system32\drivers\aswSP.sys – (aswSP)
DRV - [2010/02/11 10:39:01 | 000,023,376 | —- | M] (ALWIL Software) [Kernel | On_Demand | Stopped] – C:\WIXP\system32\drivers\aswRdr.sys – (aswRdr)
DRV - [2010/02/11 10:38:34 | 000,100,432 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WIXP\system32\drivers\aswmon2.sys – (aswMon2)
DRV - [2010/02/11 10:38:23 | 000,019,024 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WIXP\system32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2010/02/11 10:38:07 | 000,028,880 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WIXP\system32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2010/01/14 17:08:30 | 000,059,664 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\WIXP\system32\drivers\TfSysMon.sys – (TfSysMon)
DRV - [2009/12/02 16:23:40 | 000,149,040 | —- | M] (Microsoft Corporation) [File_System | System | Running] – C:\WIXP\system32\drivers\MpFilter.sys – (MpFilter)
DRV - [2009/08/05 15:58:40 | 000,093,872 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\WIXP\system32\drivers\SBREDrv.sys – (SBRE)
DRV - [2008/02/27 13:49:00 | 000,003,840 | —- | M] () [Kernel | System | Running] – C:\WIXP\System32\Drivers\BANTExt.sys – (BANTExt)
DRV - [2005/11/14 15:59:00 | 000,007,424 | —- | M] (CMS Peripherals, Inc.) [Kernel | Auto | Running] – C:\WIXP\system32\drivers\portd2k.sys – (portD)
DRV - [2002/08/28 14:59:12 | 000,036,224 | —- | M] (ADMtek Incorporated.) [Kernel | On_Demand | Running] – C:\WIXP\system32\drivers\an983.sys – (AN983)
DRV - [2001/08/22 09:42:58 | 000,013,632 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WIXP\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
DRV - [2001/02/18 19:17:26 | 000,058,608 | —- | M] (TouchStone Software Corporation) [Kernel | On_Demand | Stopped] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\TII69D.tmp\disk1\BIOSCHK.SYS – (BIOSCHK)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/04/08 23:21:51 | 000,000,000 | —D | M]
[2009/12/30 16:59:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Mozilla\Firefox\extensions
[2009/12/30 16:59:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/12/21 14:30:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2002/09/03 08:34:19 | 000,000,734 | —- | M]) - C:\WIXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WIXP\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (xplorer2 Toolbar) - {DB35FDA8-77E3-4784-92C2-EE7345E91AF4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O9 - Extra Button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WIXP\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WIXP\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WIXP\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WIXP\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:29:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/04/10 09:47:57 | 000,561,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe
[2010/04/07 12:49:19 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/04/07 05:41:10 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\kbdjpn.dll
[2010/04/07 05:41:10 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\dllcache\kbdjpn.dll
[2010/04/07 05:41:10 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\kbdkor.dll
[2010/04/07 05:41:10 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\dllcache\kbdkor.dll
[2010/04/07 05:41:10 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\kbd106.dll
[2010/04/07 05:41:10 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\dllcache\kbd106.dll
[2010/04/07 05:41:10 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\kbd101c.dll
[2010/04/07 05:41:10 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\dllcache\kbd101c.dll
[2010/04/07 05:41:10 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\kbd101b.dll
[2010/04/07 05:41:10 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\dllcache\kbd101b.dll
[2010/04/07 05:41:10 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\kbd103.dll
[2010/04/07 05:41:10 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\dllcache\kbd103.dll
[2010/04/07 05:31:44 | 000,000,000 | —D | C] – C:\TDdownload
[2010/04/05 21:06:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\IObit
[2010/04/02 19:41:34 | 000,014,640 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\spmsg.dll
[2010/04/02 19:32:13 | 000,000,000 | —D | C] – C:\WIXP\System32\drivers\UMDF
[2010/04/02 19:32:13 | 000,000,000 | —D | C] – C:\WIXP\System32\LogFiles
[2010/04/02 10:10:11 | 000,000,000 | -HSD | C] – C:\found.000
[2010/03/24 15:08:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Uniblue
[2010/03/24 15:05:25 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2010/03/21 12:04:20 | 000,000,000 | —D | C] – C:\4179ffc16156c248dd98
[2010/03/20 15:33:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\Conduit
[2010/03/20 15:33:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\xplorer2
[2010/03/20 15:33:52 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/03/20 15:33:30 | 000,000,000 | —D | C] – C:\Program Files\xplorer2
[2010/03/20 15:31:29 | 000,000,000 | —D | C] – C:\Program Files\zabkat
[2010/03/20 15:05:01 | 000,086,016 | —- | C] (Giganology Inc.) – C:\WIXP\System32\gigagetbho_v10.dll
[2010/03/20 15:04:31 | 000,000,000 | —D | C] – C:\Program Files\Giganology
[2010/03/19 13:18:12 | 000,181,632 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\MpSigStub.exe
[2010/03/19 12:52:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/03/19 12:32:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WIXP\Application Data\Windows Genuine Advantage
[2010/03/19 12:31:50 | 000,000,000 | —D | C] – C:\1fd0909a73c3b50997b330a06917b756
[2009/09/20 14:20:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/06/10 22:37:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/06/10 18:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/10 18:29:31 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/06/10 18:29:31 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[4 C:\WIXP\*.tmp files -> C:\WIXP\*.tmp -> ]
[1 C:\WIXP\System32\*.tmp files -> C:\WIXP\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/04/17 06:11:00 | 000,000,884 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/17 06:02:00 | 000,001,006 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
[2010/04/17 02:37:57 | 000,000,880 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/17 02:32:04 | 000,000,408 | -H– | M] () – C:\WIXP\tasks\MP Scheduled Scan.job
[2010/04/17 02:26:46 | 000,000,006 | -H– | M] () – C:\WIXP\tasks\SA.DAT
[2010/04/17 02:26:41 | 000,002,048 | –S- | M] () – C:\WIXP\bootstat.dat
[2010/04/17 02:25:05 | 001,835,008 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2010/04/17 02:25:05 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2010/04/16 20:53:29 | 000,005,077 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\1191 Dev Dharm Singh—Feb 2010.pdf
[2010/04/16 12:44:24 | 004,827,508 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\IconCache.db
[2010/04/16 12:44:06 | 000,000,866 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Money to Dya Kaur.rtf
[2010/04/15 19:24:11 | 000,202,624 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Training-and-Gender.pdf
[2010/04/15 13:26:13 | 000,115,924 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Receipt 2.pdf
[2010/04/15 12:02:00 | 000,000,954 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
[2010/04/13 13:58:09 | 000,000,883 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Document.rtf
[2010/04/13 13:35:07 | 000,000,467 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\obstacles to tap on for speech.rtf
[2010/04/13 13:17:21 | 000,007,498 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Speaking To Be Understood.rtf
[2010/04/12 15:37:25 | 000,000,883 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\F gleason.rtf
[2010/04/12 12:13:57 | 000,000,180 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Judgement letter with inclusion of origional note for Frances Lee Gleason to court.rtf
[2010/04/11 00:00:59 | 000,113,096 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Patrick & Carly-on Daytona-March 2007.jp2
[2010/04/10 21:42:26 | 000,313,949 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TWS SeminarRequestForm0001.pdf
[2010/04/10 09:48:05 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe
[2010/04/07 12:49:20 | 000,001,734 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\HijackThis.lnk
[2010/04/07 05:46:10 | 000,000,036 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/04/06 14:49:45 | 000,000,579 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Project 3 Persuasive speaking.rtf
[2010/04/05 21:11:45 | 000,439,552 | —- | M] () – C:\WIXP\System32\PerfStringBackup.INI
[2010/04/05 21:11:45 | 000,380,350 | —- | M] () – C:\WIXP\System32\perfh009.dat
[2010/04/05 21:11:45 | 000,052,764 | —- | M] () – C:\WIXP\System32\perfc009.dat
[2010/04/04 15:13:05 | 000,000,316 | RHS- | M] () – C:\boot.ini
[2010/04/04 15:13:04 | 000,000,517 | —- | M] () – C:\WIXP\win.ini
[2010/04/04 15:13:04 | 000,000,227 | —- | M] () – C:\WIXP\system.ini
[2010/04/02 23:39:55 | 000,000,707 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Shortcut to L&C.lnk
[2010/04/02 21:04:19 | 000,023,392 | —- | M] () – C:\WIXP\System32\nscompat.tlb
[2010/04/02 21:04:19 | 000,016,832 | —- | M] () – C:\WIXP\System32\amcompat.tlb
[2010/04/02 19:41:42 | 000,001,355 | —- | M] () – C:\WIXP\imsins.BAK
[2010/04/02 19:32:33 | 000,000,000 | -H– | M] () – C:\WIXP\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/03/24 15:05:42 | 000,000,729 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\SpeedUpMyPC.lnk
[2010/03/20 15:32:59 | 000,000,921 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\xplorer2 Lite.lnk
[2010/03/20 15:04:51 | 000,000,744 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gigaget.lnk
[4 C:\WIXP\*.tmp files -> C:\WIXP\*.tmp -> ]
[1 C:\WIXP\System32\*.tmp files -> C:\WIXP\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/04/16 20:53:29 | 000,005,077 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\1191 Dev Dharm Singh—Feb 2010.pdf
[2010/04/16 12:44:06 | 000,000,866 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Money to Dya Kaur.rtf
[2010/04/16 12:43:15 | 000,115,924 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Receipt 2.pdf
[2010/04/16 12:42:45 | 000,202,624 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Training-and-Gender.pdf
[2010/04/13 13:35:07 | 000,000,467 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\obstacles to tap on for speech.rtf
[2010/04/12 15:37:25 | 000,000,883 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\F gleason.rtf
[2010/04/12 12:31:18 | 000,000,883 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Document.rtf
[2010/04/12 12:13:57 | 000,000,180 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Judgement letter with inclusion of origional note for Frances Lee Gleason to court.rtf
[2010/04/11 03:19:12 | 000,313,949 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TWS SeminarRequestForm0001.pdf
[2010/04/11 00:00:51 | 000,113,096 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Patrick & Carly-on Daytona-March 2007.jp2
[2010/04/10 19:23:12 | 000,007,498 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Speaking To Be Understood.rtf
[2010/04/07 12:49:20 | 000,001,734 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\HijackThis.lnk
[2010/04/07 05:46:10 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/04/06 14:49:45 | 000,000,579 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Project 3 Persuasive speaking.rtf
[2010/04/02 23:39:55 | 000,000,707 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Shortcut to L&C.lnk
[2010/04/02 19:41:47 | 000,764,868 | —- | C] () – C:\WIXP\System32\dllcache\apph_sp.sdb
[2010/04/02 19:41:47 | 000,217,118 | —- | C] () – C:\WIXP\System32\dllcache\apphelp.sdb
[2010/04/02 19:32:33 | 000,000,000 | -H– | C] () – C:\WIXP\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/03/24 15:05:42 | 000,000,729 | —- | C] () – C:\Documents and Settings\All Users.WIXP\Desktop\SpeedUpMyPC.lnk
[2010/03/20 15:32:59 | 000,000,921 | —- | C] () – C:\Documents and Settings\All Users.WIXP\Desktop\xplorer2 Lite.lnk
[2010/03/20 15:04:51 | 000,000,744 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gigaget.lnk
[2010/03/19 13:10:26 | 000,000,408 | -H– | C] () – C:\WIXP\tasks\MP Scheduled Scan.job
[2010/03/08 13:21:09 | 000,004,608 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/03 06:41:44 | 000,003,840 | —- | C] () – C:\WIXP\System32\drivers\BANTExt.sys
[2010/01/22 13:22:54 | 000,767,952 | —- | C] () – C:\WIXP\BDTSupport.dll.old
[2009/12/21 17:57:56 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2009/12/21 17:57:54 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.dat.LOG
[2009/12/21 17:57:52 | 001,835,008 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2002/09/03 08:58:49 | 000,027,440 | —- | C] () – C:\WIXP\System32\drivers\secdrv.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:5C321E34
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 4/17/2010 6:08:27 AM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 19.72 Gb Free Space | 51.55% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Giganology\Gigaget\Gigaget.exe" = C:\Program Files\Giganology\Gigaget\Gigaget.exe:*:Enabled:Gigaget – (Giganology Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21199F32-B676-4FE2-A443-EF7DB6B8FD4F}" = Opera 10.10
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95632566-071E-4A02-92C1-4BD907065736}" = BounceBack Express
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{BE66348A-E83F-4982-941F-DFF2F742B851}" = Microsoft Office Live Meeting 2007
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1" = Uniblue SpeedUpMyPC
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Ask Toolbar_is1" = Foxit Toolbar
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"Belarc Advisor" = Belarc Advisor 8.1
"EB88B6218325D2AB47CFFBF7170236B60A6198FF" = Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0)
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Foxit Reader" = Foxit Reader
"gigaget_is1" = Gigaget
"GoToAssist" = GoToAssist 8.0.0.514
"HijackThis" = HijackThis 2.0.2
"IObit Security 360_is1" = IObit Security 360
"Karen's Countdown Timer II" = Karen's Countdown Timer II
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Security Essentials" = Microsoft Security Essentials
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"SpywareBlaster_is1" = SpywareBlaster 4.2
"TIMELEFT3_is1" = TimeLeft
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"xplorer2 Toolbar" = xplorer2 Toolbar
"xplorer2l" = xplorer² lite
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/5/2010 11:35:01 PM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/6/2010 5:15:26 PM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/8/2010 1:10:01 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/8/2010 3:10:26 AM | Computer Name = KHALSA-FAMILY | Source = EventSystem | ID = 4612
Description = The COM+ Event System ran out of memory during its internal processing,
at line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cp
Error - 4/8/2010 7:12:05 AM | Computer Name = KHALSA-FAMILY | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.2180, faulting module
directdb.dll, version 6.0.2900.2180, fault address 0x000072f0.
Error - 4/8/2010 9:52:43 AM | Computer Name = KHALSA-FAMILY | Source = Application Error | ID = 1001
Description = Fault bucket 128989890.
Error - 4/14/2010 2:31:30 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/15/2010 11:24:52 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/16/2010 8:57:53 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/17/2010 6:22:21 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 4/7/2010 6:40:29 AM | Computer Name = KHALSA-FAMILY | Source = DCOM | ID = 10010
Description = The server {80EE4901-33A8-11D1-A213-0080C88593A5} did not register
with DCOM within the required timeout.
Error - 4/7/2010 7:02:00 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/8/2010 3:10:49 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file 'wbkF92.tmp' on the volume 'HarddiskVolume2'. It has
stopped monitoring the volume.
Error - 4/9/2010 3:08:39 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/11/2010 5:02:35 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/12/2010 7:26:10 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file 'FAP1749.tmp' on the volume 'HarddiskVolume2'. It has
stopped monitoring the volume.
Error - 4/14/2010 6:02:00 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/15/2010 1:31:49 PM | Computer Name = KHALSA-FAMILY | Source = DCOM | ID = 10010
Description = The server {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C} did not register
with DCOM within the required timeout.
Error - 4/16/2010 2:45:02 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file 'Unknown.Log' on the volume 'HarddiskVolume2'. It has
stopped monitoring the volume.
Error - 4/17/2010 5:40:53 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
< End of report >
OTL logfile created on: 4/17/2010 6:36:59 AM - Run 1 Minimal Output
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 19.70 Gb Free Space | 51.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\IObit\IObit Security 360\is360.exe (IObit)
PRC - C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Program Files\IObit\IObit Security 360\is360tray.exe (IObit)
PRC - C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WIXP\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\Program Files\IObit\IObit Security 360\is360mon.dll (IObit)
MOD - C:\WIXP\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (IS360service) – C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/04/08 23:21:51 | 000,000,000 | —D | M]
[2009/12/30 16:59:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Mozilla\Firefox\extensions
[2009/12/30 16:59:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/12/21 14:30:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2002/09/03 08:34:19 | 000,000,734 | —- | M]) - C:\WIXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WIXP\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (xplorer2 Toolbar) - {DB35FDA8-77E3-4784-92C2-EE7345E91AF4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O9 - Extra Button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WIXP\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WIXP\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WIXP\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WIXP\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:29:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WIXP\system32\ias [2009/12/21 17:33:01 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WIXP\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (62782530557837312)
========== Files/Folders - Created Within 14 Days ==========
[2010/04/10 09:47:57 | 000,561,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe
[2010/04/07 12:49:19 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/04/07 05:31:44 | 000,000,000 | —D | C] – C:\TDdownload
[2010/04/05 21:06:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\IObit
[2009/09/20 14:20:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/06/10 22:37:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/06/10 18:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/10 18:29:31 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/06/10 18:29:31 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[4 C:\WIXP\*.tmp files -> C:\WIXP\*.tmp -> ]
[1 C:\WIXP\System32\*.tmp files -> C:\WIXP\System32\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010/04/17 06:11:00 | 000,000,884 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/17 06:02:00 | 000,001,006 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
[2010/04/17 02:37:57 | 000,000,880 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/17 02:32:04 | 000,000,408 | -H– | M] () – C:\WIXP\tasks\MP Scheduled Scan.job
[2010/04/17 02:26:46 | 000,000,006 | -H– | M] () – C:\WIXP\tasks\SA.DAT
[2010/04/17 02:26:41 | 000,002,048 | –S- | M] () – C:\WIXP\bootstat.dat
[2010/04/17 02:25:05 | 001,835,008 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2010/04/17 02:25:05 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2010/04/16 20:53:29 | 000,005,077 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\1191 Dev Dharm Singh—Feb 2010.pdf
[2010/04/16 12:44:24 | 004,827,508 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\IconCache.db
[2010/04/16 12:44:06 | 000,000,866 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Money to Dya Kaur.rtf
[2010/04/15 19:24:11 | 000,202,624 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Training-and-Gender.pdf
[2010/04/15 13:26:13 | 000,115,924 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Receipt 2.pdf
[2010/04/15 12:02:00 | 000,000,954 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
[2010/04/13 13:58:09 | 000,000,883 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Document.rtf
[2010/04/13 13:35:07 | 000,000,467 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\obstacles to tap on for speech.rtf
[2010/04/13 13:17:21 | 000,007,498 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Speaking To Be Understood.rtf
[2010/04/12 15:37:25 | 000,000,883 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\F gleason.rtf
[2010/04/12 12:13:57 | 000,000,180 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Judgement letter with inclusion of origional note for Frances Lee Gleason to court.rtf
[2010/04/11 00:00:59 | 000,113,096 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Patrick & Carly-on Daytona-March 2007.jp2
[2010/04/10 21:42:26 | 000,313,949 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TWS SeminarRequestForm0001.pdf
[2010/04/10 09:48:05 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\OTL.exe
[2010/04/07 12:49:20 | 000,001,734 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\HijackThis.lnk
[2010/04/07 05:46:10 | 000,000,036 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/04/06 14:49:45 | 000,000,579 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Project 3 Persuasive speaking.rtf
[2010/04/05 21:11:45 | 000,439,552 | —- | M] () – C:\WIXP\System32\PerfStringBackup.INI
[2010/04/05 21:11:45 | 000,380,350 | —- | M] () – C:\WIXP\System32\perfh009.dat
[2010/04/05 21:11:45 | 000,052,764 | —- | M] () – C:\WIXP\System32\perfc009.dat
[2010/04/04 15:13:05 | 000,000,316 | RHS- | M] () – C:\boot.ini
[2010/04/04 15:13:04 | 000,000,517 | —- | M] () – C:\WIXP\win.ini
[2010/04/04 15:13:04 | 000,000,227 | —- | M] () – C:\WIXP\system.ini
[4 C:\WIXP\*.tmp files -> C:\WIXP\*.tmp -> ]
[1 C:\WIXP\System32\*.tmp files -> C:\WIXP\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/04/16 20:53:29 | 000,005,077 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\1191 Dev Dharm Singh—Feb 2010.pdf
[2010/04/16 12:44:06 | 000,000,866 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Money to Dya Kaur.rtf
[2010/04/16 12:43:15 | 000,115,924 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Receipt 2.pdf
[2010/04/16 12:42:45 | 000,202,624 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Training-and-Gender.pdf
[2010/04/13 13:35:07 | 000,000,467 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\obstacles to tap on for speech.rtf
[2010/04/12 15:37:25 | 000,000,883 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\F gleason.rtf
[2010/04/12 12:31:18 | 000,000,883 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Document.rtf
[2010/04/12 12:13:57 | 000,000,180 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Judgement letter with inclusion of origional note for Frances Lee Gleason to court.rtf
[2010/04/11 03:19:12 | 000,313,949 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TWS SeminarRequestForm0001.pdf
[2010/04/11 00:00:51 | 000,113,096 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Patrick & Carly-on Daytona-March 2007.jp2
[2010/04/10 19:23:12 | 000,007,498 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Speaking To Be Understood.rtf
[2010/04/07 12:49:20 | 000,001,734 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\HijackThis.lnk
[2010/04/07 05:46:10 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/04/06 14:49:45 | 000,000,579 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Project 3 Persuasive speaking.rtf
[2010/03/08 13:21:09 | 000,004,608 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/03 06:41:44 | 000,003,840 | —- | C] () – C:\WIXP\System32\drivers\BANTExt.sys
[2010/01/22 13:22:54 | 000,767,952 | —- | C] () – C:\WIXP\BDTSupport.dll.old
[2009/12/21 17:57:56 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2009/12/21 17:57:54 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.dat.LOG
[2009/12/21 17:57:52 | 001,835,008 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2002/09/03 08:58:49 | 000,027,440 | —- | C] () – C:\WIXP\System32\drivers\secdrv.sys
========== LOP Check ==========
[2010/01/23 15:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Alwil Software
[2009/12/24 11:19:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Applications
[2010/01/25 18:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Citrix
[2009/12/27 21:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\IObit
[2010/02/23 01:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Karen's Power Tools
[2010/03/24 04:22:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\TEMP
[2009/12/30 16:58:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Foxit
[2010/04/05 21:06:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\IObit
[2010/02/23 01:29:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\NesterSoft
[2010/01/01 22:26:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Opera
[2009/12/24 12:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Thinstall
[2010/03/24 15:08:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Uniblue
[2010/04/17 02:32:04 | 000,000,408 | -H– | M] () – C:\WIXP\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\ServicePackFiles\i386\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\system32\drivers\agp440.sys
[2002/09/03 08:31:57 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\drivers\atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WIXP\$NtServicePackUninstall$\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\ServicePackFiles\i386\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\ServicePackFiles\i386\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WIXP\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\system32\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WIXP\$NtServicePackUninstall$\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\ServicePackFiles\i386\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\ServicePackFiles\i386\scecli.dll
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WIXP\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WIXP\system32\*.tmp files -> C:\WIXP\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/12/21 07:12:44 | 000,094,208 | —- | M] () – C:\WIXP\system32\config\default.sav
[2009/12/21 07:12:44 | 000,602,112 | —- | M] () – C:\WIXP\system32\config\software.sav
[2009/12/21 07:12:44 | 000,393,216 | —- | M] () – C:\WIXP\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:5C321E34
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 4/17/2010 6:36:59 AM - Run 1 Minimal Output
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 19.70 Gb Free Space | 51.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Giganology\Gigaget\Gigaget.exe" = C:\Program Files\Giganology\Gigaget\Gigaget.exe:*:Enabled:Gigaget – (Giganology Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21199F32-B676-4FE2-A443-EF7DB6B8FD4F}" = Opera 10.10
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95632566-071E-4A02-92C1-4BD907065736}" = BounceBack Express
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{BE66348A-E83F-4982-941F-DFF2F742B851}" = Microsoft Office Live Meeting 2007
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1" = Uniblue SpeedUpMyPC
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Ask Toolbar_is1" = Foxit Toolbar
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"Belarc Advisor" = Belarc Advisor 8.1
"EB88B6218325D2AB47CFFBF7170236B60A6198FF" = Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0)
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Foxit Reader" = Foxit Reader
"gigaget_is1" = Gigaget
"GoToAssist" = GoToAssist 8.0.0.514
"HijackThis" = HijackThis 2.0.2
"IObit Security 360_is1" = IObit Security 360
"Karen's Countdown Timer II" = Karen's Countdown Timer II
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Security Essentials" = Microsoft Security Essentials
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"SpywareBlaster_is1" = SpywareBlaster 4.2
"TIMELEFT3_is1" = TimeLeft
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"xplorer2 Toolbar" = xplorer2 Toolbar
"xplorer2l" = xplorer² lite
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/5/2010 11:35:01 PM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/6/2010 5:15:26 PM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/8/2010 1:10:01 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/8/2010 3:10:26 AM | Computer Name = KHALSA-FAMILY | Source = EventSystem | ID = 4612
Description = The COM+ Event System ran out of memory during its internal processing,
at line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cp
Error - 4/8/2010 7:12:05 AM | Computer Name = KHALSA-FAMILY | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.2180, faulting module
directdb.dll, version 6.0.2900.2180, fault address 0x000072f0.
Error - 4/8/2010 9:52:43 AM | Computer Name = KHALSA-FAMILY | Source = Application Error | ID = 1001
Description = Fault bucket 128989890.
Error - 4/14/2010 2:31:30 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/15/2010 11:24:52 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/16/2010 8:57:53 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 4/17/2010 6:22:21 AM | Computer Name = KHALSA-FAMILY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759331, P2 unspecified, P3 scanfile,
P4 2.1.6519.0, P5 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 4/7/2010 6:40:29 AM | Computer Name = KHALSA-FAMILY | Source = DCOM | ID = 10010
Description = The server {80EE4901-33A8-11D1-A213-0080C88593A5} did not register
with DCOM within the required timeout.
Error - 4/7/2010 7:02:00 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/8/2010 3:10:49 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file 'wbkF92.tmp' on the volume 'HarddiskVolume2'. It has
stopped monitoring the volume.
Error - 4/9/2010 3:08:39 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/11/2010 5:02:35 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/12/2010 7:26:10 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file 'FAP1749.tmp' on the volume 'HarddiskVolume2'. It has
stopped monitoring the volume.
Error - 4/14/2010 6:02:00 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 4/15/2010 1:31:49 PM | Computer Name = KHALSA-FAMILY | Source = DCOM | ID = 10010
Description = The server {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C} did not register
with DCOM within the required timeout.
Error - 4/16/2010 2:45:02 PM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file 'Unknown.Log' on the volume 'HarddiskVolume2'. It has
stopped monitoring the volume.
Error - 4/17/2010 5:40:53 AM | Computer Name = KHALSA-FAMILY | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
< End of report >
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-04-17 18:30:43
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\OWNER~1.KHA\LOCALS~1\Temp\fwlcqpog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB1D1DC5A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB1D1DB16]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB1D1E0CA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB1D1DFF4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB1D1D6EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB1D1DBF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB1D1D62C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB1D1D690]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB1D1DD10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB1D1E198]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB1D1DCD0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB1D1DE50]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB1EA9320]
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device A mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device A B0C91C8A