This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can Someone Look At My Log Please

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think I have a virus

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:37:01, on 5/20/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://m.www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKUS\S-1-5-21-839522115-1214440339-725345543-1003\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" (User '?')
O4 - HKUS\S-1-5-21-839522115-1214440339-725345543-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background (User '?')
O4 - HKUS\S-1-5-21-839522115-1214440339-725345543-1003\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User '?')
O4 - HKUS\S-1-5-21-839522115-1214440339-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-839522115-1214440339-725345543-1003\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - HKUS\S-1-5-21-839522115-1214440339-725345543-1003\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (User '?')
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 8818 bytes
Hello safan and welcome to WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again safan

I’d like you to run some different scans that will look a little deeper into your computer. Before that there are a couple of things I’d like to bring to your attention:

1. Ask Service and Toolbar - Askservice.exe uses excessive system and memory resources with no corresponding benefit. The ASK toolbar comes bundled with many third-party applications, is considered as Spyware and comes with vulnerabilities.

See the following links and decide yourself whether or not you want to keep it.:

http://secunia.com/advisories/product/15810/
http://www.benedelman.org/spyware/ask-toolbars/

2. P2P - I see you have P2P software, (Vuze), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it likely contributed to your current situation.
Please see this topic for more information: Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel >> Add or Remove Programs.

Should you decide to keep it, please don’t use it until we have finished up here.


Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKUS\S-1-5-21-839522115-1214440339-725345543-1003\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (User '?')
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe


Close all windows except for HijackThis and click Fix checked.


Please download DeFogger to your desktop.

Double click DeFogger to run the tool.

  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


Run OTL

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in:

    • netsvcs
      %SYSTEMDRIVE%\*.exe
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      /md5stop
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\drivers\*.sys /90
      [CREATERESTOREPOINT]
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Can you please give me an idea of why you think your computer is infected and what symptoms there are.

Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
This appeared on my desktop after I ran DeFogger. DeFogger didn't ask me to reboot.


defogger_disable by jpshortstuff (23.02.10.1)
Log created at 22:50 on 20/05/2010 (Owner)

Checking for autostart values…
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers…


-=E.O.F=-

I didn't do the next step yet. Should I proceed ?

This appeared on my desktop after I ran DeFogger. DeFogger didn't ask me to reboot.

This just means no CD emulation drivers were disabled..

Yes, please continue with the other instructions

Satchfan
OTL.txt
OTL logfile created on: 5/21/2010 1:51:42 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 548.00 Mb Available Physical Memory | 57.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 63.78 Gb Free Space | 42.80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADRIANE-MARIE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\VTTrayp.exe (S3 Graphics Co., Ltd.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe (Zone Labs Inc.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Zone Labs Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (ASKService) – C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
SRV - (ASKUpgrade) – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Zone Labs Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (TotRec7) – C:\WINDOWS\system32\drivers\TotRec7.sys (High Criteria inc.)
DRV - (ViPrt) – C:\WINDOWS\System32\DRIVERS\ViPrt.sys (VIA Technologies, Inc.)
DRV - (ViBus) – C:\WINDOWS\System32\DRIVERS\ViBus.sys (VIA Technologies, Inc.)
DRV - (videX32) – C:\WINDOWS\System32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)
DRV - (BIOS) – C:\WINDOWS\system32\drivers\BIOS.sys (BIOSTAR Group)
DRV - (AFS2K) – C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://m.www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=374563"
FF - prefs.js..browser.search.selectedEngine: "MyWebSearch"
FF - prefs.js..browser.startup.homepage: "http://m.www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRfox000&fl=0&ptb=qPEAn6dOvjREupyKiOCB3Q&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/20 23:34:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/07 12:06:08 | 000,000,000 | —D | M]

[2009/06/01 13:49:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/05/13 21:17:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2dj8s51d.default\extensions
[2009/06/01 15:56:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2dj8s51d.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/01/19 08:34:14 | 000,009,941 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2dj8s51d.default\searchplugins\mywebsearch.xml
[2010/05/13 21:17:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 15:37:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/06 15:37:16 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/07/06 17:03:06 | 000,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

O1 HOSTS File: ([2009/11/15 18:57:00 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [CTSyncU.exe] C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe (Zone Labs Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/01 13:19:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/06/01 13:19:37 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

[CREATERESTOREPOINT]
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 90 Days ==========

[2010/05/21 13:45:29 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/20 01:30:54 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/20 01:30:39 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\HJTInstall.exe
[2010/05/06 15:37:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/04/29 19:33:16 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/04/29 19:33:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
[2010/04/29 19:33:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Vuze_Remote
[2010/04/29 19:33:14 | 000,000,000 | —D | C] – C:\Program Files\Vuze_Remote
[2010/04/26 23:22:58 | 000,000,000 | —D | C] – C:\SWAT [DVDRip][2003][Eng][BugzBunny]
[2010/04/22 20:25:18 | 000,000,000 | —D | C] – C:\Beachbody Insanity
[2010/04/12 01:08:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/04/07 14:51:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Sammsoft
[2010/04/07 14:50:34 | 000,000,000 | —D | C] – C:\Program Files\The Weather Channel FW
[2010/04/07 14:50:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\The Weather Channel
[2010/04/07 14:50:06 | 000,302,192 | —- | C] (The Weather Channel Interactive) – C:\yahoosp_StubInstaller.exe
[2010/03/24 12:08:21 | 000,000,000 | —D | C] – C:\Pimleur - Spanish I II III
[2010/03/23 08:39:10 | 000,000,000 | —D | C] – C:\Shutter Island (2010) R5 DVDRip XviD-MAXSPEED
[2010/03/20 23:35:23 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/03/20 23:35:17 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/03/20 23:35:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/20 23:33:59 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/03/15 10:34:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Downloads

========== Files - Modified Within 90 Days ==========

[2010/05/21 13:46:25 | 000,002,205 | —- | M] () – C:\Documents and Settings\Owner\Desktop\intruc.rtf
[2010/05/21 13:45:29 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/21 12:42:15 | 000,000,334 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/05/21 12:40:54 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/21 12:40:26 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/21 12:40:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/21 00:39:29 | 003,932,160 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/05/21 00:39:06 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/05/20 22:43:42 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner\defogger_reenable
[2010/05/20 22:42:11 | 000,050,477 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Defogger.exe
[2010/05/20 22:36:07 | 007,377,082 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/05/20 20:14:52 | 367,076,512 | —- | M] () – C:\Gossip.Girl.S03E20.HDTV.XviD-2HD.[VTV].avi
[2010/05/20 20:06:06 | 366,854,858 | —- | M] () – C:\Gossip.Girl.S03E21.Ex-Husbands.and.Wives.HDTV.XviD-FQM.[VTV].avi
[2010/05/20 19:41:59 | 366,630,598 | —- | M] () – C:\Gossip.Girl.S03E19.HDTV.XviD-2HD.[VTV].avi
[2010/05/20 19:33:04 | 366,706,612 | —- | M] () – C:\Gossip.Girl.S03E22.HDTV.XviD-2HD.[VTV].avi
[2010/05/20 11:11:16 | 001,303,971 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Rosie.wma
[2010/05/20 01:34:32 | 001,402,880 | —- | M] () – C:\HiJackThis.msi
[2010/05/20 01:30:39 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\HJTInstall.exe
[2010/05/19 19:33:11 | 000,007,668 | —- | M] () – C:\[isoHunt] Gossip.Girl.S03E19.HDTV.XviD-2HD.[VTV].avi.torrent
[2010/05/19 19:32:12 | 000,007,724 | —- | M] () – C:\[isoHunt] Gossip.Girl.S03E20.HDTV.XviD-2HD.[VTV].avi.5531763.TPB.torrent
[2010/05/19 19:28:56 | 000,007,535 | —- | M] () – C:\Gossip.Girl.S03E21.Ex-Husbands.and.Wives.HDTV.XviD-FQM.[VTV].avi.5551268.TPB.torrent
[2010/05/19 19:27:58 | 000,007,425 | —- | M] () – C:\Gossip+Girl+3x22+%28HDTV-2HD%29+%5BVTV%5D+Torrent+-+btjunkie.torrent
[2010/05/19 19:19:28 | 000,213,504 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/17 18:28:32 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/05/17 16:52:08 | 000,000,521 | —- | M] () – C:\hpfr3420.xml
[2010/05/07 18:25:13 | 000,034,693 | —- | M] () – C:\Documents and Settings\Owner\Desktop\story.jpg
[2010/05/07 18:24:54 | 000,339,248 | —- | M] () – C:\Documents and Settings\Owner\Desktop\2003_phone_booth_wallpaper_001.jpg
[2010/05/06 21:05:41 | 000,015,502 | —- | M] () – C:\[isoHunt] 423aea7f3ea4e6ec4a56db26570c1f83fd6dc071.torrent
[2010/04/27 17:43:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/27 01:26:08 | 731,455,488 | —- | M] () – C:\Casualties of War (1989) DVD-RIP XviD.avi
[2010/04/27 01:03:26 | 1024,446,562 | —- | M] () – C:\The.Basketball.Diaries.1995-{DvDrip-KiPl3r}.avi
[2010/04/26 21:44:16 | 735,346,216 | —- | M] () – C:\Phone Booth (2002).avi
[2010/04/21 08:21:15 | 000,015,515 | —- | M] () – C:\[isoHunt] Why Did I Get Married Too (TS] [ENGL) 2010 COA.torrent
[2010/04/14 19:18:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/07 14:50:06 | 000,302,192 | —- | M] (The Weather Channel Interactive) – C:\yahoosp_StubInstaller.exe
[2010/04/05 13:55:33 | 000,021,500 | —- | M] () – C:\[isoHunt] Occupation 101 [DVD].torrent
[2010/03/28 20:52:46 | 000,000,132 | —- | M] () – C:\Documents and Settings\Owner\default.pls
[2010/03/24 12:06:12 | 000,061,860 | —- | M] () – C:\Primsleur___Spanish_I_II_III.torrent
[2010/03/23 13:38:09 | 000,013,308 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/03/16 18:57:17 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2010/03/04 11:36:33 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat

========== Files Created - No Company Name ==========

[2010/05/21 13:46:25 | 000,002,205 | —- | C] () – C:\Documents and Settings\Owner\Desktop\intruc.rtf
[2010/05/20 22:43:42 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\defogger_reenable
[2010/05/20 22:42:11 | 000,050,477 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Defogger.exe
[2010/05/20 19:34:18 | 366,854,858 | —- | C] () – C:\Gossip.Girl.S03E21.Ex-Husbands.and.Wives.HDTV.XviD-FQM.[VTV].avi
[2010/05/20 19:27:46 | 367,076,512 | —- | C] () – C:\Gossip.Girl.S03E20.HDTV.XviD-2HD.[VTV].avi
[2010/05/20 19:03:42 | 366,630,598 | —- | C] () – C:\Gossip.Girl.S03E19.HDTV.XviD-2HD.[VTV].avi
[2010/05/20 11:11:16 | 001,303,971 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Rosie.wma
[2010/05/20 01:34:31 | 001,402,880 | —- | C] () – C:\HiJackThis.msi
[2010/05/19 19:33:10 | 000,007,668 | —- | C] () – C:\[isoHunt] Gossip.Girl.S03E19.HDTV.XviD-2HD.[VTV].avi.torrent
[2010/05/19 19:32:04 | 000,007,724 | —- | C] () – C:\[isoHunt] Gossip.Girl.S03E20.HDTV.XviD-2HD.[VTV].avi.5531763.TPB.torrent
[2010/05/19 19:28:55 | 000,007,535 | —- | C] () – C:\Gossip.Girl.S03E21.Ex-Husbands.and.Wives.HDTV.XviD-FQM.[VTV].avi.5551268.TPB.torrent
[2010/05/19 19:28:29 | 366,706,612 | —- | C] () – C:\Gossip.Girl.S03E22.HDTV.XviD-2HD.[VTV].avi
[2010/05/19 19:27:57 | 000,007,425 | —- | C] () – C:\Gossip+Girl+3x22+%28HDTV-2HD%29+%5BVTV%5D+Torrent+-+btjunkie.torrent
[2010/05/07 18:25:12 | 000,034,693 | —- | C] () – C:\Documents and Settings\Owner\Desktop\story.jpg
[2010/05/07 18:24:52 | 000,339,248 | —- | C] () – C:\Documents and Settings\Owner\Desktop\2003_phone_booth_wallpaper_001.jpg
[2010/05/06 21:05:41 | 000,015,502 | —- | C] () – C:\[isoHunt] 423aea7f3ea4e6ec4a56db26570c1f83fd6dc071.torrent
[2010/04/26 23:56:23 | 731,455,488 | —- | C] () – C:\Casualties of War (1989) DVD-RIP XviD.avi
[2010/04/26 23:50:54 | 1024,446,562 | —- | C] () – C:\The.Basketball.Diaries.1995-{DvDrip-KiPl3r}.avi
[2010/04/26 21:04:21 | 735,346,216 | —- | C] () – C:\Phone Booth (2002).avi
[2010/04/21 08:21:14 | 000,015,515 | —- | C] () – C:\[isoHunt] Why Did I Get Married Too (TS] [ENGL) 2010 COA.torrent
[2010/04/05 13:55:33 | 000,021,500 | —- | C] () – C:\[isoHunt] Occupation 101 [DVD].torrent
[2010/03/24 12:06:10 | 000,061,860 | —- | C] () – C:\Primsleur___Spanish_I_II_III.torrent
[2010/03/23 13:38:09 | 000,013,308 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/02/22 08:30:57 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/08/13 11:12:58 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/06/05 18:31:28 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/06/04 18:29:32 | 000,168,448 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/06/04 18:29:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/06/04 18:29:28 | 000,795,648 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/06/04 18:29:28 | 000,130,048 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/06/04 18:29:26 | 000,067,584 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/06/04 18:29:26 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/06/01 14:02:48 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/06/01 13:55:07 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2009/06/01 13:54:20 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2003/03/09 00:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll

========== LOP Check ==========

[2009/06/01 15:56:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/06/01 13:34:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2010/03/20 23:36:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/01 17:18:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/05/20 21:03:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2009/07/06 17:04:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Foxit
[2010/04/07 15:01:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sammsoft
[2009/06/05 20:26:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TotalRecorder
[2009/09/10 15:05:45 | 000,000,342 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1243879849.job

========== Purity Check ==========



========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.exe >
[2009/11/24 22:16:37 | 027,386,280 | —- | M] ( ) – C:\AdbeRdr920_en_US.exe
[2009/08/26 21:55:22 | 012,951,423 | —- | M] (Dennis Meuwissen ) – C:\dvdflick_setup_1.3.0.7.exe
[2009/07/06 17:02:53 | 003,738,880 | —- | M] (Foxit Software) – C:\FoxitReader30_enu_Setup.exe
[2009/11/08 22:31:58 | 000,401,720 | —- | M] () – C:\HiJackThis.exe
[2010/05/20 01:30:39 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\HJTInstall.exe
[2010/03/20 23:29:12 | 098,181,416 | —- | M] (Apple Inc.) – C:\iTunesSetup.exe
[2010/02/03 17:54:44 | 001,438,976 | —- | M] () – C:\MoveMediaPlayerWin_071505000011.exe
[2009/11/18 21:28:34 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\spybotsd162.exe
[2009/11/18 21:33:04 | 003,012,768 | —- | M] (Javacool Software LLC ) – C:\spywareblastersetup42.exe
[2009/06/03 19:07:40 | 025,740,144 | —- | M] (Microsoft Corporation) – C:\wmp11-windowsxp-x86-enu.exe
[2010/04/07 14:50:06 | 000,302,192 | —- | M] (The Weather Channel Interactive) – C:\yahoosp_StubInstaller.exe


< MD5 for: AGP440.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/06/09 12:12:29 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/06/09 12:12:29 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\agp440.sys

< MD5 for: ATAPI.SYS >
[2003/03/31 08:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/06/09 12:12:29 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/06/09 12:12:29 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2003/03/31 08:00:00 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2003/03/31 08:00:00 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\eventlog.dll

< MD5 for: LOGEVENT.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\logevent.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2004/08/04 03:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2004/08/04 03:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< MD5 for: VIPRT.SYS >
[2007/10/18 06:28:52 | 000,052,224 | R— | M] (VIA Technologies, Inc.) MD5=020EB647FEA9187541827231CB236DCE – C:\WINDOWS\system32\drivers\ViPrt.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/06/01 09:10:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/06/01 09:10:09 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/06/01 09:10:08 | 000,405,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\Config\Config] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Connection Wizard\Connection Wizard] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Debug\UserMode\UserMode] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\chsime\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\CHTIME\Applets\Applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imejp\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imejp98\imejp98] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imjp8_1\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imkr6_1\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imkr6_1\dicts\dicts] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\shared\res\res] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\java\classes\classes] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\java\trustlib\trustlib] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\msapps\msinfo\msinfo] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\mui\mui] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\System_OEM\System_OEM] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Registration\CRMLog\CRMLog] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\10\msft\windows\windows] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\52\msft\windows\net\net] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\60\msft\windows\common\common] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\70\msft\windows\windows] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\41de1a081a084b9d6fc0b5c225e4fbe5\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\b7b0631e184025ba37e5a4ec1d8637e7\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\EventCache\EventCache] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Sun\Java\Deployment\Deployment] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\WinSxS\InstallTemp\InstallTemp] -> \Device\__max++>\^ -> Mount Point
< End of report >

Extras.txt
OTL Extras logfile created on: 5/21/2010 1:51:42 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 548.00 Mb Available Physical Memory | 57.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 63.78 Gb Free Space | 42.80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADRIANE-MARIE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze – (Vuze Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{569C24E9-1D28-4738-99EF-6BEC75DC5F6A}" = Creative ZEN Vision W
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{81063354-9060-42B2-A000-1EBE96778AA9}" = iTunes
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"8461-7759-5462-8226" = Vuze
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Vuze Toolbar
"Creative Removable Disk Manager" = Creative Removable Disk Manager
"DVD Flick_is1" = DVD Flick 1.3.0.7
"ESET Online Scanner" = ESET Online Scanner v3
"Foxit Reader" = Foxit Reader
"HijackThis" = HijackThis 2.0.2
"HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.5 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"SysInfo" = Creative System Information
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"Total Video Converter 3.10_is1" = Total Video Converter 3.10
"TotalRecorder" = Total Recorder 7.0
"VIA/S3G UniChrome Family Win2K/XP/Server2003 Display" = VIA/S3G Display Driver 6.14.10.0357
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"Vuze_Remote Toolbar" = Vuze_Remote Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Software Update" = Yahoo! Software Update
"ZENcast Organizer" = ZENcast Organizer
"ZoneAlarm Pro" = ZoneAlarm Pro

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/22/2010 8:36:40 PM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/23/2010 7:59:09 AM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/23/2010 2:22:58 PM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/24/2010 9:54:41 AM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/24/2010 10:03:11 AM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/24/2010 7:22:40 PM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/25/2010 10:48:19 AM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/25/2010 2:55:13 PM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/25/2010 8:03:17 PM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/26/2010 12:19:31 PM | Computer Name = ADRIANE-MARIE | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

[ System Events ]
Error - 5/20/2010 12:25:21 AM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 1:12:07 AM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 1:12:09 AM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 9:59:35 AM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 9:59:37 AM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 6:29:57 PM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 6:29:59 PM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 10:38:47 PM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/20/2010 10:38:50 PM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/21/2010 12:40:42 PM | Computer Name = ADRIANE-MARIE | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.


< End of report >

Gmer.txt
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-21 15:02:03
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\fxliakow.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\WINDOWS\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.) ZwConnectPort [0xECD3E4BD]
SSDT \??\C:\WINDOWS\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.) ZwOpenProcess [0xECD4F460]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[2472] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
Device \Driver\AFD \Device\Afd vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)

—- EOF - GMER 1.0.15 —-

Can you please give me an idea of why you think your computer is infected and what symptoms there are.

Computer is slower then normal when I turn it on, audio skips alot when I play my Sirius Satelite Radio and when I play music or video using Windows Midia Player. Also, Window has shut down 2 times with a blue screen appearing. I don't remember exactly what the message said because I just turned my computer off and then on again, but I believe it stated something along the lines of, "Window has to shut down for protection if this happens again remove any new hardware", and something else I can't remember….These problems started after I downloaded a movie using Vuze.
Hi safan Thanks for the logs and the information. These logs take time to look through so I must ask you to be patient. Once I have looked at your log, I'll consult with an expert and reply as soon as I can. Thanks Satchfan
Hi safan

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    [C:\WINDOWS\Config\Config] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\Connection Wizard\Connection Wizard] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\Debug\UserMode\UserMode] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\chsime\applets\applets] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\CHTIME\Applets\Applets] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\imejp\applets\applets] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\imejp98\imejp98] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\imjp8_1\applets\applets] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\imkr6_1\applets\applets] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\imkr6_1\dicts\dicts] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\ime\shared\res\res] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\java\classes\classes] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\java\trustlib\trustlib] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\msapps\msinfo\msinfo] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\mui\mui] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\PCHealth\HelpCtr\System_OEM\System_OEM] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\Registration\CRMLog\CRMLog] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabs] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\10\msft\windows\windows] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\52\msft\windows\net\net] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\60\msft\windows\common\common] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\70\msft\windows\windows] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\Download\41de1a081a084b9d6fc0b5c225e4fbe5\backup\backup] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\Download\b7b0631e184025ba37e5a4ec1d8637e7\backup\backup] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\EventCache\EventCache] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\Sun\Java\Deployment\Deployment] -> \Device\__max++>\^ -> Mount Point
    [C:\WINDOWS\WinSxS\InstallTemp\InstallTemp] -> \Device\__max++>\^ -> Mount Point
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, right-click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    Click on Yes, to continue scanning for malware.
Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt


Logs to include:

OTL.txt
ComboFix.txt


Satchfan
Hello again Satchfan

OTL
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Mount Point C:\WINDOWS\Config\Config removed successfully!
Mount Point C:\WINDOWS\Connection Wizard\Connection Wizard removed successfully!
Mount Point C:\WINDOWS\Debug\UserMode\UserMode removed successfully!
Mount Point C:\WINDOWS\ime\chsime\applets\applets removed successfully!
Mount Point C:\WINDOWS\ime\CHTIME\Applets\Applets removed successfully!
Mount Point C:\WINDOWS\ime\imejp\applets\applets removed successfully!
Mount Point C:\WINDOWS\ime\imejp98\imejp98 removed successfully!
Mount Point C:\WINDOWS\ime\imjp8_1\applets\applets removed successfully!
Mount Point C:\WINDOWS\ime\imkr6_1\applets\applets removed successfully!
Mount Point C:\WINDOWS\ime\imkr6_1\dicts\dicts removed successfully!
Mount Point C:\WINDOWS\ime\shared\res\res removed successfully!
Mount Point C:\WINDOWS\java\classes\classes removed successfully!
Mount Point C:\WINDOWS\java\trustlib\trustlib removed successfully!
Mount Point C:\WINDOWS\msapps\msinfo\msinfo removed successfully!
Mount Point C:\WINDOWS\mui\mui removed successfully!
Mount Point C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH removed successfully!
Mount Point C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint removed successfully!
Mount Point C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles removed successfully!
Mount Point C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs removed successfully!
Mount Point C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS removed successfully!
Mount Point C:\WINDOWS\PCHealth\HelpCtr\System_OEM\System_OEM removed successfully!
Mount Point C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp removed successfully!
Mount Point C:\WINDOWS\Registration\CRMLog\CRMLog removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabs removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\10\msft\windows\windows removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\52\msft\windows\net\net removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\60\msft\windows\common\common removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\backup\asms\70\msft\windows\windows removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\Download\41de1a081a084b9d6fc0b5c225e4fbe5\backup\backup removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\Download\b7b0631e184025ba37e5a4ec1d8637e7\backup\backup removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\EventCache\EventCache removed successfully!
Mount Point C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered removed successfully!
Mount Point C:\WINDOWS\Sun\Java\Deployment\Deployment removed successfully!
Mount Point C:\WINDOWS\WinSxS\InstallTemp\InstallTemp removed successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Jordan
->Temp folder emptied: 8986727 bytes
->Temporary Internet Files folder emptied: 1319676 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 42883686 bytes
->Flash cache emptied: 114100 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 725047 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1024863 bytes

User: Owner
->Temp folder emptied: 100184216 bytes
->Temporary Internet Files folder emptied: 7789023 bytes
->Java cache emptied: 38296291 bytes
->FireFox cache emptied: 95771925 bytes
->Flash cache emptied: 326689 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 95045 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 2566001842 bytes

Total Files Cleaned = 2,731.00 mb


OTL by OldTimer - Version 3.2.5.0 log created on 05222010_193519

OTL by OldTimer - Version 3.2.5.0 log created on 05222010_193519

Files\Folders moved on Reboot…
File\Folder C:\WINDOWS\temp\ZLT04213.TMP not found!

Registry entries deleted on Reboot…

ComboFix.txt
ComboFix 10-05-22.01 - Owner 05/22/2010 20:11:13.1.2 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jordan\Application Data\Dealio
c:\documents and settings\Jordan\Application Data\Dealio\res\widgets.xml
c:\documents and settings\Jordan\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe

.
((((((((((((((((((((((((( Files Created from 2010-04-23 to 2010-05-23 )))))))))))))))))))))))))))))))
.

2010-05-22 23:35 . 2010-05-22 23:35 ——– d—–w- C:\_OTL
2010-05-20 05:35 . 2010-05-20 05:35 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-05-20 05:34 . 2010-05-20 05:34 1402880 —-a-w- C:\HiJackThis.msi
2010-05-20 05:30 . 2010-05-20 05:30 ——– d—–w- c:\program files\Trend Micro
2010-05-20 05:30 . 2010-05-20 05:30 812344 —-a-w- C:\HJTInstall.exe
2010-05-20 02:01 . 2010-05-20 02:01 ——– d—–w- c:\documents and settings\Jordan\Local Settings\Application Data\Conduit
2010-05-20 02:01 . 2010-05-20 02:01 ——– d—–w- c:\documents and settings\Jordan\Local Settings\Application Data\Vuze_Remote
2010-05-06 19:37 . 2010-05-06 19:37 ——– d—–w- c:\program files\Common Files\Java
2010-05-06 19:37 . 2010-05-06 19:37 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-04-29 23:33 . 2010-04-29 23:33 ——– d—–w- c:\program files\Conduit
2010-04-29 23:33 . 2010-04-29 23:33 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Conduit
2010-04-29 23:33 . 2010-05-03 14:07 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Vuze_Remote
2010-04-29 23:33 . 2010-05-21 02:35 ——– d—–w- c:\program files\Vuze_Remote
2010-04-27 03:22 . 2010-04-27 03:22 ——– d—–w- C:\SWAT [DVDRip][2003][Eng][BugzBunny]
2010-04-23 00:25 . 2010-04-23 03:02 ——– d—–w- C:\Beachbody Insanity

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-21 18:47 . 2010-05-21 22:56 1052160 —-a-w- c:\windows\Internet Logs\xDB20.tmp
2010-05-21 16:41 . 2010-05-21 18:47 1052160 —-a-w- c:\windows\Internet Logs\xDB1F.tmp
2010-05-21 01:03 . 2009-06-01 19:56 ——– d—–w- c:\documents and settings\Owner\Application Data\Azureus
2010-05-20 04:26 . 2010-05-20 05:12 1050624 —-a-w- c:\windows\Internet Logs\xDB1E.tmp
2010-05-20 01:54 . 2010-05-20 01:59 1042432 —-a-w- c:\windows\Internet Logs\xDB1D.tmp
2010-05-20 01:13 . 2010-05-20 01:18 1043968 —-a-w- c:\windows\Internet Logs\xDB1B.tmp
2010-05-20 01:13 . 2010-05-20 01:18 2987008 —-a-w- c:\windows\Internet Logs\xDB1C.tmp
2010-05-12 16:53 . 2009-06-01 19:56 ——– d—–w- c:\program files\Vuze
2010-04-12 05:08 . 2010-04-12 05:08 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-07 22:38 . 2010-04-07 22:38 ——– d—–w- c:\documents and settings\Jordan\Application Data\Search Settings
2010-04-07 19:01 . 2010-04-07 18:51 ——– d—–w- c:\documents and settings\Owner\Application Data\Sammsoft
2010-04-07 18:52 . 2010-04-07 18:52 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Application Updater
2010-04-07 18:50 . 2010-04-07 18:50 ——– d—–w- c:\program files\The Weather Channel FW
2010-04-07 18:50 . 2010-04-07 18:50 302192 —-a-w- C:\yahoosp_StubInstaller.exe
2010-03-23 17:38 . 2010-03-23 17:38 13308 —ha-w- c:\windows\system32\mlfcache.dat
2010-03-21 03:29 . 2010-03-21 03:26 98181416 —-a-w- C:\iTunesSetup.exe
2010-03-10 06:15 . 2003-03-31 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-04 15:36 . 2010-02-22 12:30 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-02-25 06:24 . 2006-06-23 15:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2003-03-31 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-15 23:50 . 2009-11-15 23:50 318369 —-a-w- c:\program files\HiJackThis.zip
2009-11-09 02:40 . 2009-11-09 02:40 4045528 —-a-w- c:\program files\mbam141.exe
2009-06-04 17:35 . 2009-06-04 17:34 14249858 —-a-w- c:\program files\klcodec475f.exe
2009-06-01 17:49 . 2009-06-01 17:48 7526856 —-a-w- c:\program files\Firefox Setup 3.0.10.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-13 700416]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-21 53248]
"VTTrayp"="VTtrayp.exe" [2007-02-06 176128]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
ZoneAlarm Pro.lnk - c:\program files\Zone Labs\ZoneAlarm\zapro.exe [2009-6-1 422984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=DrvTrNTm.dll
"wave"=DrvTrNTm.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=

R4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2008-12-09 464264]
R4 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2008-12-09 234888]
S0 ViBus;ViBus;c:\windows\System32\DRIVERS\ViBus.sys [2007-10-18 16896]
S0 ViPrt;VIA SATA IDE Device Driver;c:\windows\System32\DRIVERS\ViPrt.sys [2007-10-18 52224]
S1 BIOS;BIOS;c:\windows\System32\drivers\BIOS.sys [2005-03-16 13696]
S3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [2008-04-17 120472]

.
Contents of the 'Scheduled Tasks' folder

2010-04-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-09-10 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8243879849.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 04:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://m.www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\2dj8s51d.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: browser.startup.homepage - hxxp://m.www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRfox000&fl=0&ptb=qPEAn6dOvjREupyKiOCB3Q&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
BHO-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\program files\AskBarDis\bar\bin\askBar.dll
WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
AddRemove-HijackThis - c:\docume~1\Owner\LOCALS~1\Temp\Rar$EX00.750\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-22 20:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-05-22 20:21:46
ComboFix-quarantined-files.txt 2010-05-23 00:21

Pre-Run: 73,206,099,968 bytes free
Post-Run: 73,169,195,008 bytes free

- - End Of File - - 5C014F5885C90D285BB34F4E378ED992

I hope I did everything right.
Hi safan

Your logs have shown up very little so far so we need to dig a bit deeper.


Please disable this program and leave it disabled unil we are done.

SPYBOT TEATIMER
• Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
• On the left hand side, click on Tools, then click on the Resident Icon in the list.
• Uncheck the Resident TeaTimer (Protection of overall system settings) active box.
• Click on the System Startup icon in the List
• Uncheck the "TeaTimer" box and click OK at any prompts.
• If Teatimer gives you a warning that changes were made, click Allow Change when prompted.
• Exit Spybot S&D when done.
• (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :file
    C:\WINDOWS\system32\drivers\mrxsmb.sys

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Please download RootRepeal to your desktop.• Physically disconnect your machine from the internet as your system will be unprotected.
• Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
• Click the Report tab at the bottom and then the Scan button.
• A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
• Another box will open, check the boxes beside all the drives, eg: C:\ , then click OK.
• The scan will take a little while to run, so let it go unhindered.
• Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop.
• Reconnect to the internet
• Post the log here in your reply.
Is your computer still showing the same symptoms?

Satchfan

• Click on the System Startup icon in the List
• Uncheck the "TeaTimer" box and click OK at any prompts.

Their isn't a box in System SartUp that says "TeaTimer". Their is a box that says VTTimer. Should I check that one ?

Is your computer still showing the same symptoms?

I haven't seen the blue screen that says "Windows has to shut down for protection". My computer is still slow though, with boot up and loading settings.

Their is a box that says VTTimer. Should I check that one ?

No, that is to do with your graphics card.

When you've clicked on the System Startup icon in the list on the left, under "Value", look for SpybotSD TeaTimer.

If you can't find it, you can temporarily uninstall Spybot and reinstall it when we're finished.

Satchfan
SystemLook
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 13:41 on 24/05/2010 by Owner (Administrator - Elevation successful)

========== file ==========

C:\WINDOWS\system32\drivers\mrxsmb.sys - File found and opened.
MD5: F3AEFB11ABC521122B67095044169E98
Created at 12:00 on 31/03/2003
Modified at 13:11 on 24/02/2010
Size: 455680 bytes
Attributes: –a—
FileDescription: Windows NT SMB Minirdr
FileVersion: 5.1.2600.5944 (xpsp_sp3_gdr.100224-1415)
ProductVersion: 5.1.2600.5944
OriginalFilename: MRXSMB.Sys
InternalName: MRxSmb.sys
ProductName: Microsoft® Windows® Operating System
CompanyName: Microsoft Corporation
LegalCopyright: © Microsoft Corporation. All rights reserved.

-=End Of File=-

RootRepeal report
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/05/24 13:46
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xEFE55000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7D5B000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEB76F000 Size: 49152 File Visible: No Signed: -
Status: -

==EOF==
Safan

Although there were infections on your computer, your logs now appear clean.

I would say that any slowing up of your system is not now caused by malware.

As I said at the beginning, the Askservice uses excessive system and memory resources with no actual benefit. I would advise you to uninstall the Askservice and any corresponding toolbars through Add/Remove programs.


A bit of housekeeping would also help to unclog your system, but first we need to tidy up your computer by removing the tools that have been used.

Follow these steps to uninstall Combofix• Click START then RUN
• Now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.

🖼Click to load external image (Posted Image)
• Please follow the prompts to uninstall Combofix.
• Once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.


Uninstall OTL
• Double-click OTL.exe
• Click the CleanUp! button.
• Select Yes when the Begin cleanup Process? prompt appears.
• If you are prompted to reboot during the cleanup, select Yes.
• The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.


Re-enable your Emulation drivers
• The application window will appear
• Click the Re-enable button to re-enable your CD Emulation drivers
• Click Yes to continue
• A 'Finished!' message will appear
• Click OK
• DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.


Clear all your temporary files.

Download ATF Cleaner here

To use ATF Cleaner:

Double-click ATF-Cleaner.exe (on your desktop) to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser

Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

For Technical Support, double-click the e-mail address located at the bottom of each menu


Defragment your operating system

The way files are organised on your hard drive has an impact on the performance of your computer. If your files are stored neatly, end-to-end, without fragmentation, your computer will work a lot quicker.

To defrag your system:

Click on Start, Programs, Accessories, System Tools, Disk Defragmenter,
When the program opens, click on Defragment

If your hard drive is very fragmented, this could take some time so it’s probably best to let it run while you go and attend to something else.

You can read more about Fragmentation here.


I recommend installing the following applications:


• SpywareBlaster to help prevent spyware from installing in the first place.
• SuperAntispyware Run weekly to keep your system clean


Although Spybot was a very good program, it is no longer updated like some other spyware programs and the two above are much more effective.

If you decide to stick with Spybot, remember to re-enable TeaTimer using the same steps as before but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.


Finally, may I repeat what I previously said about P2P programs. We have noticed that many people seeking help from us are coming with infections contracted from the use of P2P programs. When you use these programs you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these downloads are being targeted to carry infections.

Please let me know if there are any more problems.

Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI