This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google redirect and more

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Google links are being hijacked and the windows update is not being allowed to run. Attempts to connect to the update section of microsofts websites are denied, but access to other websites is fine. Just installed CA as virus protection, but it always gives an error message during virus scan. Attached is the Hijack This log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:44:59 PM, on 6/1/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\ltmsg.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AIM Helper - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Wbazup] rundll32.exe "C:\WINDOWS\mshidx80.dll",Startup (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Wbazup] rundll32.exe "C:\WINDOWS\mshidx80.dll",Startup (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1275412849031
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 8747 bytes

Thank you for any help you can provide!
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 4 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


Extract the file and run it.


If TDSSKiller asks you to close all programs please allow it to do so.


Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)


If TDSSKiller asks to reboot your computer please allow it to do so.

Please post the content of that log TDSSKiller



NEXT:



Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now



NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that is produced after running TDSSKiller.
3. The log that is produced after running the ComboFix scan.
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Thank you for your help SweetTech. 1. I disabled the CA firewall, but left the other parts of the CA anti-virus scan on, as the instructions at the link you provided mentioned only the firewall. If I should disable the rest of the anti-virus software, please let me know. Also, after the TDSSkiller ran, the windows auto-update started working. It downloaded the updates, but I have not installed them. Let me know if I should go ahead and install it. 2. Here is the TDSS log: 17:09:06:406 2152 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48 17:09:06:406 2152 ================================================================================ 17:09:06:406 2152 SystemInfo: 17:09:06:406 2152 OS Version: 5.1.2600 ServicePack: 3.0 17:09:06:406 2152 Product type: Workstation 17:09:06:421 2152 ComputerName: BRANDON 17:09:06:421 2152 UserName: Brandon Miles 17:09:06:421 2152 Windows directory: C:\WINDOWS 17:09:06:421 2152 Processor architecture: Intel x86 17:09:06:421 2152 Number of processors: 1 17:09:06:421 2152 Page size: 0x1000 17:09:06:515 2152 Boot type: Normal boot 17:09:06:515 2152 ================================================================================ 17:09:07:437 2152 Initialize success 17:09:07:437 2152 17:09:07:437 2152 Scanning Services … 17:09:08:359 2152 Raw services enum returned 338 services 17:09:08:390 2152 Suspicious serv ghcpy (h: 0, b: 1) 17:09:08:390 2152 17:09:08:453 2152 Hidden service detected! 17:09:08:453 2152 Service name: ghcpy 17:09:08:453 2152 Image path: 17:09:08:453 2152 Type "delete" (without quotes) to delete it: 17:09:39:140 2152 17:09:39:140 2152 By user detect ghcpy 17:09:39:156 2152 RegNode HKLM\SYSTEM\ControlSet001\services\ghcpy infected by TDSS rootkit … 17:09:39:156 2152 will be deleted on reboot 17:09:39:156 2152 RegNode HKLM\SYSTEM\ControlSet002\services\ghcpy infected by TDSS rootkit … 17:09:39:156 2152 will be deleted on reboot 17:09:39:156 2152 File C:\WINDOWS\system32\drivers\ghcpy.sys infected by TDSS rootkit … 17:09:39:156 2152 will be deleted on reboot 17:09:39:156 2152 17:09:39:156 2152 Scanning Drivers … 17:09:41:468 2152 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS 17:09:41:671 2152 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 17:09:41:890 2152 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 17:09:42:093 2152 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys 17:09:42:328 2152 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 17:09:42:546 2152 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 17:09:42:734 2152 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 17:09:42:937 2152 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys 17:09:43:125 2152 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys 17:09:43:359 2152 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys 17:09:43:562 2152 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys 17:09:43:781 2152 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys 17:09:44:046 2152 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys 17:09:44:250 2152 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys 17:09:44:437 2152 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys 17:09:44:687 2152 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys 17:09:44:890 2152 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys 17:09:45:093 2152 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys 17:09:45:281 2152 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 17:09:45:484 2152 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 17:09:45:671 2152 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 17:09:46:171 2152 ati2mtag (3b23691e9eef04de3364d9271371bbde) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 17:09:46:531 2152 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 17:09:46:734 2152 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 17:09:46:890 2152 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 17:09:47:078 2152 bvrp_pci (c043ca48f1f5c00ff8272180fbbd15e9) C:\WINDOWS\system32\drivers\bvrp_pci.sys 17:09:47:281 2152 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys 17:09:47:484 2152 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 17:09:47:687 2152 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys 17:09:47:859 2152 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 17:09:48:062 2152 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 17:09:48:250 2152 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 17:09:48:656 2152 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys 17:09:49:468 2152 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys 17:09:49:875 2152 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys 17:09:50:093 2152 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys 17:09:50:296 2152 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 17:09:50:515 2152 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 17:09:50:750 2152 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 17:09:50:953 2152 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 17:09:51:140 2152 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 17:09:51:359 2152 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys 17:09:51:562 2152 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 17:09:52:046 2152 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 17:09:52:281 2152 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 17:09:52:468 2152 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 17:09:52:656 2152 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 17:09:52:843 2152 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 17:09:53:015 2152 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 17:09:53:218 2152 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 17:09:53:437 2152 ghcpy (19c8fb7ae0c7f10453aafda8debae559) C:\WINDOWS\system32\drivers\ghcpy.sys 17:09:53:437 2152 Suspicious file (NoAccess): C:\WINDOWS\system32\drivers\ghcpy.sys. md5: 19c8fb7ae0c7f10453aafda8debae559 17:09:53:640 2152 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 17:09:53:859 2152 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys 17:09:54:093 2152 hpt3xx (b077b7f8e79779ea967e84a4fc040227) C:\WINDOWS\System32\DRIVERS\hpt3xx.sys 17:09:54:328 2152 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 17:09:54:546 2152 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 17:09:54:734 2152 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys 17:09:54:921 2152 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 17:09:55:109 2152 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys 17:09:55:312 2152 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys 17:09:55:531 2152 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys 17:09:55:734 2152 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 17:09:55:921 2152 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 17:09:56:156 2152 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 17:09:56:343 2152 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 17:09:56:531 2152 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 17:09:56:765 2152 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 17:09:56:968 2152 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 17:09:57:156 2152 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 17:09:57:343 2152 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 17:09:57:546 2152 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys 17:09:57:750 2152 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 17:09:57:968 2152 KmxAgent (f4ffca2de8290de6118583bf74962243) C:\WINDOWS\system32\DRIVERS\kmxagent.sys 17:09:58:203 2152 KmxCF (9cb6ae1a28c0a5b70afc208f068bc24f) C:\WINDOWS\system32\DRIVERS\KmxCF.sys 17:09:58:406 2152 KmxCfg (df0de1110162e761a7f60c392ad177dd) C:\WINDOWS\system32\DRIVERS\kmxcfg.sys 17:09:58:609 2152 KmxFile (28c7643d33ed066622e93260f818adfd) C:\WINDOWS\system32\DRIVERS\KmxFile.sys 17:09:58:875 2152 KmxFw (6db409366cb3325a67a01308ce23ae1a) C:\WINDOWS\system32\DRIVERS\kmxfw.sys 17:09:59:312 2152 KmxSbx (2df089f8594ae18d5c1a1bfbdd967eab) C:\WINDOWS\system32\DRIVERS\KmxSbx.sys 17:09:59:640 2152 KmxStart (f68a8118c1e26967533cc06206154784) C:\WINDOWS\system32\DRIVERS\kmxstart.sys 17:09:59:859 2152 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 17:10:00:062 2152 Lbd (713cd5267abfb86fe90a72e384e82a38) C:\WINDOWS\system32\DRIVERS\Lbd.sys 17:10:00:515 2152 ltmodem5 (e9ebe8ccd1e5b3ca2ddf1765147caca0) C:\WINDOWS\system32\DRIVERS\ltmdmxp.sys 17:10:00:750 2152 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 17:10:00:937 2152 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 17:10:01:156 2152 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 17:10:01:343 2152 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 17:10:01:531 2152 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 17:10:01:750 2152 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys 17:10:01:953 2152 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 17:10:02:187 2152 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 17:10:02:406 2152 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 17:10:02:609 2152 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 17:10:02:796 2152 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 17:10:02:968 2152 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 17:10:03:187 2152 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 17:10:03:437 2152 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 17:10:03:640 2152 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 17:10:03:828 2152 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 17:10:04:015 2152 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 17:10:04:187 2152 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 17:10:04:546 2152 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 17:10:04:750 2152 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 17:10:04:984 2152 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 17:10:05:187 2152 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 17:10:05:406 2152 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 17:10:05:640 2152 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 17:10:05:921 2152 nv4 (be6ba6e03c480aa00e01441050b83e6c) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 17:10:06:156 2152 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 17:10:06:343 2152 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 17:10:06:531 2152 OMCI (e1e54131462b63efefaf14aca8e4012b) C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS 17:10:06:718 2152 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys 17:10:06:906 2152 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 17:10:07:078 2152 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 17:10:07:281 2152 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 17:10:07:453 2152 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 17:10:07:765 2152 PCIIde (ff7dcaf93194cc176f0d924bf8781112) C:\WINDOWS\system32\DRIVERS\pciide.sys 17:10:07:781 2152 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\pciide.sys. Real md5: ff7dcaf93194cc176f0d924bf8781112, Fake md5: ccf5f451bb1a5a2a522a76e670000ff0 17:10:07:796 2152 File "C:\WINDOWS\system32\DRIVERS\pciide.sys" infected by TDSS rootkit … 17:10:11:046 2152 Backup copy found, using it.. 17:10:11:078 2152 will be cured on next reboot 17:10:11:265 2152 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 17:10:12:296 2152 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys 17:10:12:609 2152 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys 17:10:12:843 2152 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 17:10:13:078 2152 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 17:10:13:312 2152 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 17:10:13:515 2152 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 17:10:13:750 2152 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 17:10:14:140 2152 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys 17:10:14:453 2152 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys 17:10:14:953 2152 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys 17:10:15:312 2152 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys 17:10:15:625 2152 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys 17:10:16:156 2152 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 17:10:16:359 2152 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 17:10:16:578 2152 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 17:10:16:859 2152 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 17:10:17:265 2152 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 17:10:17:562 2152 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 17:10:17:828 2152 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 17:10:18:234 2152 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 17:10:18:515 2152 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 17:10:18:843 2152 rtl8139 (d6066a0596b13e486204dd365fdb2d4f) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 17:10:19:203 2152 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 17:10:19:531 2152 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 17:10:19:953 2152 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 17:10:20:359 2152 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 17:10:20:953 2152 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys 17:10:21:296 2152 smwdm (b911c822922cf62df83ad36d5c9775cc) C:\WINDOWS\system32\drivers\smwdm.sys 17:10:21:640 2152 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys 17:10:21:875 2152 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 17:10:22:109 2152 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 17:10:22:359 2152 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys 17:10:22:562 2152 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 17:10:22:796 2152 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 17:10:23:046 2152 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys 17:10:23:250 2152 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys 17:10:23:515 2152 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys 17:10:23:859 2152 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys 17:10:24:125 2152 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 17:10:24:453 2152 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 17:10:24:765 2152 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 17:10:25:218 2152 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 17:10:25:437 2152 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 17:10:25:656 2152 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys 17:10:25:875 2152 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 17:10:26:171 2152 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys 17:10:26:406 2152 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 17:10:26:640 2152 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 17:10:26:828 2152 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 17:10:27:031 2152 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 17:10:27:234 2152 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 17:10:27:453 2152 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 17:10:27:656 2152 VET-FILT (daadb622164e93376b31598c053a9e87) C:\WINDOWS\system32\drivers\VET-FILT.sys 17:10:27:906 2152 VET-REC (66747d67066e29b24363d5537b93d294) C:\WINDOWS\system32\drivers\VET-REC.sys 17:10:28:171 2152 VETEBOOT (6c39c682003129dc0bac2183a8c9d744) C:\WINDOWS\system32\drivers\VETEBOOT.sys 17:10:28:468 2152 VETEFILE (fca7465bc8786d29d57439351324d938) C:\WINDOWS\system32\drivers\VETEFILE.sys 17:10:28:828 2152 VETFDDNT (10545ed2f206c922eb02e522b1a3fa75) C:\WINDOWS\system32\drivers\VETFDDNT.sys 17:10:29:078 2152 VETMONNT (77ef6a724334313b808fb6fe36b57be6) C:\WINDOWS\system32\drivers\VETMONNT.sys 17:10:29:343 2152 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 17:10:29:578 2152 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys 17:10:29:828 2152 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys 17:10:30:078 2152 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 17:10:30:343 2152 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 17:10:30:796 2152 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 17:10:31:062 2152 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 17:10:31:312 2152 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 17:10:31:546 2152 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 17:10:31:562 2152 Reboot required for cure complete.. 17:10:32:375 2152 Cure on reboot scheduled successfully 17:10:32:375 2152 17:10:32:375 2152 Completed 17:10:32:375 2152 17:10:32:375 2152 Results: 17:10:32:375 2152 Registry objects infected / cured / cured on reboot: 2 / 0 / 2 17:10:32:375 2152 File objects infected / cured / cured on reboot: 2 / 0 / 2 17:10:32:375 2152 17:10:32:390 2152 KLMD(ARK) unloaded successfully 3. Something seemed to go wrong with ComboFix. After downloading it and running it, it did not ask about the Windows recovery. I assumed that meant it detected it already on my computer. It then gave me two boxes (I only clicked on the Combo-Fix once) where the computer beeped and it gave a warning from ComboFix (Do not trust anything from www.combofix.org etc). I clicked No on the first box and it closed. I clicked Yes on the second box. It sounded like the CPU was going for a few minutes, but nothing else happened (waited about 1 hour). 4. Google links appear to work now. I can access the microsoft update website as well. I have not installed any of the automatically downloaded windows updates. Thanks again for the help!
OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Extra Registry select Use Safe List
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Here is the OTL.Txt file:

OTL logfile created on: 6/1/2010 6:10:42 PM - Run 1
OTL by OldTimer - Version 3.2.5.2 Folder = C:\Documents and Settings\Brandon Miles\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

767.00 Mb Total Physical Memory | 359.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): c:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 11.91 Gb Free Space | 31.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BRANDON
Current User Name: Brandon Miles
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe (CA, Inc.)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\WINDOWS\SYSTEM32\ltmsg.exe (LUCENT TECHNOLOGIES)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOEHook.dll (CA)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (VETMSGNT) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (UmxFwHlp) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
SRV - (PPCtlPriv) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
SRV - (ITMRTSVC) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)


========== Driver Services (SafeList) ==========

DRV - (VETEFILE) – C:\WINDOWS\SYSTEM32\DRIVERS\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT) – C:\WINDOWS\SYSTEM32\DRIVERS\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETMONNT) – C:\WINDOWS\SYSTEM32\DRIVERS\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (VET-FILT) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\WINDOWS\SYSTEM32\DRIVERS\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-rec.sys (Computer Associates International, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxSbx) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxSbx.sys (CA)
DRV - (KmxFw) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxFw.sys (CA)
DRV - (KmxFile) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxFile.sys (CA)
DRV - (KmxCF) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxCF.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxCfg.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxAgent.sys (CA)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ASCTRM) – C:\WINDOWS\SYSTEM32\DRIVERS\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ltmodem5) – C:\WINDOWS\SYSTEM32\DRIVERS\ltmdmxp.sys (LT)
DRV - (rtl8139) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys (Realtek Semiconductor Corporation )
DRV - (nv4) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (hpt3xx) – C:\WINDOWS\System32\DRIVERS\hpt3xx.sys (HighPoint Technologies, Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (bvrp_pci) – C:\WINDOWS\SYSTEM32\DRIVERS\bvrp_pci.sys ()
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =



O1 HOSTS File: ([2010/05/28 13:10:57 | 000,396,219 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13702 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe (CA, Inc.)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe ()
O4 - HKLM..\Run: [LTWinModem1] C:\WINDOWS\System32\ltmsg.exe (LUCENT TECHNOLOGIES)
O4 - HKLM..\Run: [QOELOADER] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1275412849031 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7933.6787384259 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/11/15 08:31:14 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: dwwionce - (C:\WINDOWS\system32\cidadiag.dll) - C:\WINDOWS\System32\cidadiag.dll File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2003/01/23 18:41:05 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\L3CODECX.ACM (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/01 18:07:05 | 000,571,392 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe
[2010/06/01 17:28:58 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/06/01 17:28:01 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/01 17:25:43 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/06/01 09:56:17 | 000,739,696 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2010/06/01 09:56:17 | 000,133,520 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2010/06/01 09:31:48 | 000,099,592 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\isafeif.dll
[2010/06/01 09:31:48 | 000,079,424 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\vetredir.dll
[2010/06/01 09:31:48 | 000,075,016 | —- | C] (CA, Inc.) – C:\WINDOWS\System32\isafprod.dll
[2010/06/01 09:31:48 | 000,032,240 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys
[2010/06/01 09:31:48 | 000,026,352 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys
[2010/06/01 09:31:48 | 000,021,488 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys
[2010/06/01 09:31:48 | 000,021,104 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys
[2010/06/01 09:31:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Scanner
[2010/06/01 09:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CA
[2010/06/01 09:30:57 | 000,000,000 | —D | C] – C:\Program Files\CA
[2010/06/01 07:32:11 | 045,145,784 | —- | C] (CA) – C:\Documents and Settings\Brandon Miles\Desktop\iss_en_32.exe
[2010/05/29 10:10:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Application Data\GetRightToGo
[2010/05/29 08:36:46 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/29 08:05:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/05/29 08:05:43 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/05/29 07:14:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/05/29 07:14:18 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/05/28 12:42:37 | 000,000,000 | —D | C] – C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2010/05/28 09:14:55 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/05/28 09:14:54 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/05/28 09:14:37 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/05/28 09:08:52 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/05/28 09:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/05/28 08:22:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/05/27 15:42:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Desktop\VirusProt
[2010/05/27 14:42:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/05/27 09:27:14 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/05/27 06:25:13 | 000,000,000 | —D | C] – C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2010/05/27 06:25:13 | 000,000,000 | —D | C] – C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2010/05/26 18:04:50 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/26 18:04:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/05/26 17:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\ujwgoufgd
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/01 18:07:05 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe
[2010/06/01 17:20:30 | 003,701,981 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\ComboFix.exe
[2010/06/01 17:16:02 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/06/01 17:13:15 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/01 17:12:58 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/06/01 17:12:38 | 804,114,432 | -HS- | M] () – C:\hiberfil.sys
[2010/06/01 17:11:52 | 000,047,126 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/06/01 17:11:27 | 008,126,464 | —- | M] () – C:\Documents and Settings\Brandon Miles\ntuser.dat
[2010/06/01 17:11:27 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Brandon Miles\NTUSER.INI
[2010/06/01 17:11:20 | 001,982,384 | -H– | M] () – C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\IconCache.db
[2010/06/01 17:06:32 | 000,966,213 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\tdsskiller.zip
[2010/06/01 14:37:26 | 000,002,463 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.lnk
[2010/06/01 13:37:47 | 001,402,880 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.msi
[2010/06/01 12:45:30 | 000,000,256 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2010/06/01 12:45:30 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/06/01 12:45:30 | 000,000,000 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/06/01 11:33:45 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Brandon Miles\Desktop\~$lesResume.doc
[2010/06/01 10:34:36 | 000,000,530 | —- | M] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
[2010/06/01 10:20:12 | 000,739,696 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2010/06/01 10:20:11 | 000,133,520 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2010/06/01 09:56:49 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/06/01 09:56:02 | 000,032,240 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys
[2010/06/01 09:56:02 | 000,026,352 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys
[2010/06/01 09:56:02 | 000,021,488 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys
[2010/06/01 09:56:02 | 000,021,104 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys
[2010/06/01 07:32:11 | 045,145,784 | —- | M] (CA) – C:\Documents and Settings\Brandon Miles\Desktop\iss_en_32.exe
[2010/05/29 10:11:02 | 000,001,152 | —- | M] () – C:\WINDOWS\System32\windrv.sys
[2010/05/28 15:57:17 | 000,052,224 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\Boston_Company_List(1).xls
[2010/05/28 13:10:57 | 000,396,219 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/05/28 11:46:43 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Brandon Miles\My Documents\~$lesResumeFormat.doc
[2010/05/28 09:14:30 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/05/28 09:14:28 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/05/28 09:09:27 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/05/28 08:42:10 | 000,014,546 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.pdf
[2010/05/28 08:34:47 | 000,038,912 | —- | M] () – C:\Documents and Settings\Brandon Miles\My Documents\MilesResumeFormat.doc
[2010/05/28 08:22:20 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/28 08:09:52 | 000,046,592 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.doc
[2010/05/27 15:54:48 | 000,046,080 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-C.doc
[2010/05/26 17:55:17 | 000,000,024 | —- | M] () – C:\WINDOWS\herjek.config
[2010/05/26 16:51:18 | 000,047,104 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B[2][1].doc
[2010/05/24 19:34:37 | 000,000,073 | —- | M] () – C:\WINDOWS\webica.ini
[2010/05/24 18:26:13 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[2010/05/22 21:02:50 | 000,044,032 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B.doc
[2010/05/21 23:07:45 | 000,047,104 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume.doc
[2010/05/16 07:06:21 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/05/12 03:00:32 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/01 17:20:26 | 003,701,981 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\ComboFix.exe
[2010/06/01 17:06:26 | 000,966,213 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\tdsskiller.zip
[2010/06/01 13:37:45 | 001,402,880 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.msi
[2010/06/01 12:45:28 | 000,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2010/06/01 11:33:45 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Brandon Miles\Desktop\~$lesResume.doc
[2010/06/01 10:16:18 | 804,114,432 | -HS- | C] () – C:\hiberfil.sys
[2010/06/01 09:51:34 | 000,047,126 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/06/01 09:51:34 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/06/01 09:51:34 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/06/01 09:51:34 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/06/01 09:51:34 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/06/01 09:51:34 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/06/01 09:51:34 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/06/01 09:51:34 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/06/01 09:31:28 | 000,000,530 | —- | C] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
[2010/05/29 10:11:02 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2010/05/29 08:36:46 | 000,002,463 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.lnk
[2010/05/29 07:16:38 | 000,000,020 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\vqdlkr.dat
[2010/05/28 15:33:13 | 000,052,224 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\Boston_Company_List(1).xls
[2010/05/28 11:46:43 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Brandon Miles\My Documents\~$lesResumeFormat.doc
[2010/05/28 10:12:23 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/05/28 09:16:35 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/05/28 09:09:27 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/05/28 08:42:10 | 000,014,546 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.pdf
[2010/05/27 23:50:58 | 000,038,912 | —- | C] () – C:\Documents and Settings\Brandon Miles\My Documents\MilesResumeFormat.doc
[2010/05/27 15:56:05 | 000,046,592 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.doc
[2010/05/27 15:46:31 | 000,046,080 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-C.doc
[2010/05/26 17:55:17 | 000,000,024 | —- | C] () – C:\WINDOWS\herjek.config
[2010/05/26 16:51:18 | 000,047,104 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B[2][1].doc
[2010/05/21 23:19:58 | 000,044,032 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B.doc
[2010/05/21 23:07:44 | 000,047,104 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume.doc
[2010/05/16 07:06:21 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/05/16 07:06:21 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2008/04/07 00:43:21 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2007/09/21 23:13:10 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/12/26 13:09:28 | 000,000,073 | —- | C] () – C:\WINDOWS\webica.ini
[2006/06/21 06:33:40 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/03/21 17:11:51 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2006/02/20 05:00:42 | 000,003,084 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2005/10/14 05:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 05:56:50 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 05:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 05:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 05:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 05:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 05:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2004/10/12 19:17:15 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/11/22 21:39:38 | 000,000,000 | —- | C] () – C:\WINDOWS\QTW.ini
[2003/02/23 20:11:47 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2003/02/23 20:11:47 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2003/02/23 20:11:47 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2002/11/05 19:42:20 | 000,000,105 | —- | C] () – C:\WINDOWS\TheMatrix.ini
[2002/10/15 17:38:06 | 000,000,020 | —- | C] () – C:\WINDOWS\InfModM.ini
[2002/08/15 01:25:39 | 000,000,930 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2002/06/20 18:31:44 | 000,001,095 | —- | C] () – C:\WINDOWS\ChemDraw.ini
[2002/06/20 09:43:36 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2002/06/13 02:02:41 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/06/13 01:57:12 | 000,000,029 | —- | C] () – C:\WINDOWS\wgedit.ini
[2002/06/13 01:57:10 | 000,057,344 | —- | C] () – C:\WINDOWS\uninstBVRP.dll
[2002/06/13 01:57:01 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2002/06/13 01:52:16 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/06/13 00:32:40 | 000,000,480 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2001/11/15 09:19:38 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2001/08/18 08:00:00 | 000,057,856 | —- | C] () – C:\WINDOWS\mshidx80.dll
[1999/01/22 22:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2010/06/01 09:56:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2007/07/01 13:52:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/05/28 09:09:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2007/12/30 23:48:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Brandon Miles\Application Data\Aim
[2007/12/16 11:09:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Brandon Miles\Application Data\BitZipper
[2010/05/29 10:10:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Brandon Miles\Application Data\GetRightToGo
[2006/12/26 13:09:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Brandon Miles\Application Data\ICAClient
[2002/12/02 22:52:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Brandon Miles\Application Data\InterTrust
[2004/07/12 23:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Brandon Miles\Application Data\Leadertech
[2007/07/01 13:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Brandon Miles\Application Data\Viewpoint
[2010/06/01 09:56:49 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/06/01 10:34:36 | 000,000,530 | —- | M] () – C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/06/01 17:12:35 | 000,007,167 | —- | M] () – C:\aaw7boot.log
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/01 12:45:30 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2001/11/14 17:35:22 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2010/06/01 09:31:50 | 000,034,844 | —- | M] () – C:\caavsetupLog.txt
[2010/06/01 10:17:28 | 000,027,094 | —- | M] () – C:\caisslog.txt
[2006/12/26 13:09:29 | 000,000,000 | —- | M] () – C:\COMLOG.txt
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2002/06/13 00:34:44 | 000,003,869 | RH– | M] () – C:\DELL.SDR
[2010/06/01 17:12:38 | 804,114,432 | -HS- | M] () – C:\hiberfil.sys
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2002/06/13 02:00:05 | 000,000,314 | -H– | M] () – C:\IPH.PH
[2007/12/16 16:47:42 | 000,000,138 | —- | M] () – C:\moduleName.txt
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2003/12/09 01:08:47 | 000,509,624 | R— | M] () – C:\My Money Backup.mny.mbf
[2004/11/22 15:39:24 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/04 17:58:27 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/06/01 17:12:36 | 1206,067,200 | -HS- | M] () – C:\pagefile.sys
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2010/06/01 17:10:32 | 000,045,352 | —- | M] () – C:\TDSSKiller.2.3.2.0_01.06.2010_17.09.06_log.txt
[2008/09/10 03:08:02 | 000,098,617 | —- | M] () – C:\YServer.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/07/03 23:25:03 | 000,421,888 | —- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\ATIDEMGX.dll
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2003/01/23 12:29:50 | 000,524,288 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\default.sav
[2003/01/23 18:22:57 | 000,262,144 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\security.sav
[2003/01/23 12:29:50 | 016,252,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\software.sav
[2003/01/23 12:29:51 | 004,194,304 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\system.sav

< %systemroot%\system32\drivers\*.sys /180 >
[2010/02/04 11:53:02 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\SYSTEM32\DRIVERS\Lbd.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mrxsmb.sys
[2010/06/01 17:12:06 | 000,003,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\pciide.sys
[2010/05/28 09:14:30 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\SYSTEM32\DRIVERS\SBREDrv.sys
[2009/12/31 12:50:03 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\srv.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys
[2010/06/01 09:56:02 | 000,026,352 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-filt.sys
[2010/06/01 09:56:02 | 000,021,104 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-rec.sys
[2010/06/01 10:20:11 | 000,133,520 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\veteboot.sys
[2010/06/01 10:20:12 | 000,739,696 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetefile.sys
[2010/06/01 09:56:02 | 000,021,488 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetfddnt.sys
[2010/06/01 09:56:02 | 000,032,240 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetmonnt.sys
< End of report >
And here is the Extras.txt file:

OTL Extras logfile created on: 6/1/2010 6:10:42 PM - Run 1
OTL by OldTimer - Version 3.2.5.2 Folder = C:\Documents and Settings\Brandon Miles\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

767.00 Mb Total Physical Memory | 359.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): c:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 11.91 Gb Free Space | 31.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BRANDON
Current User Name: Brandon Miles
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = Reg Error: Key error.] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
chm.file [open] – Reg Error: Key error.
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\PROGRA~1\MICROS~4\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\PROGRA~1\MICROS~4\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"c:\documents and settings\brandon miles\local settings\application data\asam.exe" = c:\documents and settings\brandon miles\local settings\application data\asam.exe:*:Enabled:enable – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{035E858B-2E6E-7AC7-16A9-41506F698D1E}" = Catalyst Control Center Graphics Full New
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{083F79E4-6FE9-46FB-A6C6-4F8862742947}" = ATI HYDRAVISION
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{2F06D374-97CE-D8FB-9383-73150A2382DF}" = CCC Help English
"{2F93BFDD-EECE-924B-54ED-B0896F03D758}" = Catalyst Control Center Graphics Previews Common
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4FA944D6-623E-EBBD-47D7-CE02A28C0796}" = Catalyst Control Center Graphics Light
"{538D98C6-CFC9-4BD3-B373-653B7A382CE8}" = IE2K
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77654E99-F083-ED32-B326-118741828039}" = Catalyst Control Center Graphics Full Existing
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7FC2AF73-10ED-404E-84A8-636B452404FD}" = Realtek RTL8139 Diagnostics Program
"{87CA98F3-0A13-77FE-A9F0-2AB1F28D741A}" = ccc-core-preinstall
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C8BC74F-E17F-4D59-D098-2F90BB9AE9E0}" = Skins
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{91E8A85F-2960-40ED-BA84-7F4567BB00C0}" = Dell | Support
"{95D885F5-B696-11D5-9D1D-0050DAB14E03}" = Shockwave Player
"{9B5337F7-0444-5607-A397-909EFEFA7CFF}" = Catalyst Control Center Core Implementation
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4C10EEF-D26C-410D-82E7-73370C6FD812}" = Neverwinter Nights Gold Edition
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B6A51892-D4A5-616B-4489-44B790179455}" = ccc-utility
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B8C3B479-1716-11D5-968A-0050BA84F5F7}" = Baldur's Gate™ II - Throne of Bhaal ™
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Photo 2002
"{CB20D3BC-6C7C-A9CA-D679-914240CDA0D3}" = ccc-core-static
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2A0F8F4-CE50-4857-A21C-3061682B2E87}" = Sansa Media Converter
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3436EE2-D5CB-4249-840B-3A0140CC34C1}" = PhoneTools
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"BitZipper_is1" = BitZipper 5.0.2
"Citrix ICA Web Client" = Citrix ICA Web Client
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"eTrust Suite Personal" = CA Internet Security Suite
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
"InstallShield_{538D98C6-CFC9-4BD3-B373-653B7A382CE8}" = Dell Picture Studio - Image Expert 2000
"LimeWire" = LimeWire 4.12.11
"LTWinModem" = Lucent Win Modem
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"RealPlayer 6.0" = RealPlayer Basic
"Shockwave" = Shockwave
"System Requirements Lab" = System Requirements Lab
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2002Setup" = Microsoft Works 2002 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/30/2010 6:42:09 AM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 5/30/2010 12:44:09 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/30/2010 12:44:09 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 5/31/2010 2:11:35 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/31/2010 2:11:35 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 5/31/2010 2:22:01 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/31/2010 2:22:02 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 5/31/2010 4:40:50 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/31/2010 4:40:50 PM | Computer Name = BRANDON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/1/2010 7:55:10 AM | Computer Name = BRANDON | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/2/2010 12:41:04 AM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error

Error - 2/7/2010 11:00:26 PM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error

Error - 2/11/2010 6:41:39 PM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error

Error - 2/14/2010 4:22:17 PM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error

Error - 2/18/2010 9:30:13 PM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error

Error - 2/25/2010 7:13:46 PM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error

Error - 2/25/2010 7:13:48 PM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error

Error - 2/25/2010 7:13:48 PM | Computer Name = BRANDON | Source = ati2mtag | ID = 49170
Description = MODE: GXO Execute BIOS Table Error


< End of report >
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    O2 - BHO: (no name) - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7933.6787384259 (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O36 - AppCertDlls: dwwionce - (C:\WINDOWS\system32\cidadiag.dll) - C:\WINDOWS\System32\cidadiag.dll File not found
    [2010/05/26 17:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\ujwgoufgd
    [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2010/06/01 17:11:52 | 000,047,126 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
    [2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
    [2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
    [2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
    [2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
    [2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
    [2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
    [2010/06/01 17:11:52 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
    [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]


NEXT:



OTL Custom Scan

We need to run an OTL Custom Scan
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following bolded text into the [external image: Posted Image] textbox.


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180
    C:\Users\Amanda\AppData\Roaming\Luzebu\*.* /s
    C:\Users\Amanda\AppData\Roaming\Ogba\*.* /s

  • Push [external image: Posted Image]
  • A report will open. Copy and Paste that report in your next reply.



NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the OTL fix.
3. The log that was produced after running the MalwareBytes' Anti-Malware scan.
4. The log that was produced after running the ESET Online Virus Scanner.
5. The log that was produced after running the OTL scan.
6. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.

Cheers,
SweetTech.
OK scans took a little bit of time to run, but they are complete.

1. No questions

2. OTL Fix log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D70E6A20-7060-4829-B3D7-B6624A1DE7C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D70E6A20-7060-4829-B3D7-B6624A1DE7C6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {9F1C11AA-197B-4942-BA54-47A8489BB47F}
C:\WINDOWS\Downloaded Program Files\iuctl.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\\dwwionce:C:\WINDOWS\system32\cidadiag.dll deleted successfully.
C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\ujwgoufgd folder moved successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\SET29.tmp deleted successfully.
C:\WINDOWS\System32\SET49.tmp deleted successfully.
C:\WINDOWS\System32\SET4C.tmp deleted successfully.
C:\WINDOWS\System32\SET5B.tmp deleted successfully.
C:\WINDOWS\002581_.tmp deleted successfully.
C:\WINDOWS\005747_.tmp deleted successfully.
C:\WINDOWS\SET20.tmp deleted successfully.
C:\WINDOWS\SET2C.tmp deleted successfully.
C:\WINDOWS\SET3E.tmp deleted successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k0 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k7 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k6 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k5 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k4 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k3 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k2 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k1 moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Brandon Miles
->Temp folder emptied: 270508419 bytes
->Temporary Internet Files folder emptied: 101615822 bytes
->Java cache emptied: 65132124 bytes
->Flash cache emptied: 8737 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 31332497 bytes
->Flash cache emptied: 1639 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 29198434 bytes
->Flash cache emptied: 15225 bytes

User: Owner
->Temp folder emptied: 7282654 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: RBM
->Temp folder emptied: 835 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26588950 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 31223450 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 594079 bytes
RecycleBin emptied: 179481913 bytes

Total Files Cleaned = 709.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Brandon Miles
->Flash cache emptied: 0 bytes

User: Default User

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

User: Owner

User: RBM

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.5.2 log created on 06012010_211617

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

3. Malwarebyte Log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4162

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

6/1/2010 10:01:53 PM
mbam-log-2010-06-01 (22-01-53).txt

Scan type: Quick scan
Objects scanned: 146642
Time elapsed: 26 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wbazup (Trojan.Hiloti) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\mshidx80.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
C:\WINDOWS\herjek.config (Malware.Trace) -> Quarantined and deleted successfully.

4. ESET log (interesting file name :o):

C:\Documents and Settings\Brandon Miles\Shared\jaimee hammer cute girl has orgasm on webcam.mpg a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Program Files\Morpheus\morpheustoolbar.exe Win32/Toolbar.AskSBar application

5. OTL Scan Log:

OTL logfile created on: 6/2/2010 1:12:57 AM - Run 2
OTL by OldTimer - Version 3.2.5.2 Folder = C:\Documents and Settings\Brandon Miles\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

767.00 Mb Total Physical Memory | 273.00 Mb Available Physical Memory | 36.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): c:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 12.30 Gb Free Space | 33.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BRANDON
Current User Name: Brandon Miles
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe (CA, Inc.)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\Dell\Support\Alert\bin\DAMon.exe ()
PRC - C:\WINDOWS\SYSTEM32\ltmsg.exe (LUCENT TECHNOLOGIES)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOEHook.dll (CA)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (VETMSGNT) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (UmxFwHlp) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
SRV - (PPCtlPriv) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
SRV - (ITMRTSVC) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)


========== Driver Services (SafeList) ==========

DRV - (VETEFILE) – C:\WINDOWS\SYSTEM32\DRIVERS\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT) – C:\WINDOWS\SYSTEM32\DRIVERS\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETMONNT) – C:\WINDOWS\SYSTEM32\DRIVERS\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (VET-FILT) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\WINDOWS\SYSTEM32\DRIVERS\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-rec.sys (Computer Associates International, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxSbx) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxSbx.sys (CA)
DRV - (KmxFw) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxFw.sys (CA)
DRV - (KmxFile) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxFile.sys (CA)
DRV - (KmxCF) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxCF.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxCfg.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxAgent.sys (CA)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ASCTRM) – C:\WINDOWS\SYSTEM32\DRIVERS\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ltmodem5) – C:\WINDOWS\SYSTEM32\DRIVERS\ltmdmxp.sys (LT)
DRV - (rtl8139) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys (Realtek Semiconductor Corporation )
DRV - (nv4) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (hpt3xx) – C:\WINDOWS\System32\DRIVERS\hpt3xx.sys (HighPoint Technologies, Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (bvrp_pci) – C:\WINDOWS\SYSTEM32\DRIVERS\bvrp_pci.sys ()
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =



O1 HOSTS File: ([2010/05/28 13:10:57 | 000,396,219 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13702 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe (CA, Inc.)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe ()
O4 - HKLM..\Run: [LTWinModem1] C:\WINDOWS\System32\ltmsg.exe (LUCENT TECHNOLOGIES)
O4 - HKLM..\Run: [QOELOADER] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1275412849031 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/11/15 08:31:14 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2003/01/23 18:41:05 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/01 22:16:37 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/06/01 21:31:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Application Data\Malwarebytes
[2010/06/01 21:31:16 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/01 21:31:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/01 21:31:10 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/01 21:31:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/01 21:29:49 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Brandon Miles\Desktop\mbam-setup-1.46.exe
[2010/06/01 21:16:17 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/01 18:07:05 | 000,571,392 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe
[2010/06/01 17:28:01 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/01 17:25:43 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/06/01 09:56:17 | 000,739,696 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2010/06/01 09:56:17 | 000,133,520 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2010/06/01 09:31:48 | 000,099,592 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\isafeif.dll
[2010/06/01 09:31:48 | 000,079,424 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\vetredir.dll
[2010/06/01 09:31:48 | 000,075,016 | —- | C] (CA, Inc.) – C:\WINDOWS\System32\isafprod.dll
[2010/06/01 09:31:48 | 000,032,240 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys
[2010/06/01 09:31:48 | 000,026,352 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys
[2010/06/01 09:31:48 | 000,021,488 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys
[2010/06/01 09:31:48 | 000,021,104 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys
[2010/06/01 09:31:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Scanner
[2010/06/01 09:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CA
[2010/06/01 09:30:57 | 000,000,000 | —D | C] – C:\Program Files\CA
[2010/06/01 07:32:11 | 045,145,784 | —- | C] (CA) – C:\Documents and Settings\Brandon Miles\Desktop\iss_en_32.exe
[2010/05/29 10:10:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Application Data\GetRightToGo
[2010/05/29 08:36:46 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/29 08:05:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/05/29 08:05:43 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/05/29 07:14:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/05/29 07:14:18 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/05/28 12:42:37 | 000,000,000 | —D | C] – C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2010/05/28 09:14:55 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/05/28 09:14:54 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/05/28 09:14:37 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/05/28 09:08:52 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/05/28 09:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/05/28 08:22:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/05/27 15:42:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Desktop\VirusProt
[2010/05/27 14:42:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/05/27 09:27:14 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/05/27 06:25:13 | 000,000,000 | —D | C] – C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2010/05/27 06:25:13 | 000,000,000 | —D | C] – C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2010/05/26 18:04:50 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/26 18:04:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe

========== Files - Modified Within 30 Days ==========

[2010/06/01 22:07:48 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/06/01 22:06:29 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/01 22:06:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/06/01 22:05:57 | 804,114,432 | -HS- | M] () – C:\hiberfil.sys
[2010/06/01 22:05:14 | 000,050,166 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/06/01 22:04:48 | 008,126,464 | —- | M] () – C:\Documents and Settings\Brandon Miles\ntuser.dat
[2010/06/01 22:04:48 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Brandon Miles\NTUSER.INI
[2010/06/01 22:04:37 | 001,983,752 | -H– | M] () – C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\IconCache.db
[2010/06/01 21:31:20 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 21:29:56 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Brandon Miles\Desktop\mbam-setup-1.46.exe
[2010/06/01 18:07:05 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe
[2010/06/01 17:20:30 | 003,701,981 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\ComboFix.exe
[2010/06/01 17:06:32 | 000,966,213 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\tdsskiller.zip
[2010/06/01 14:37:26 | 000,002,463 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.lnk
[2010/06/01 13:37:47 | 001,402,880 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.msi
[2010/06/01 12:45:30 | 000,000,256 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2010/06/01 12:45:30 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/06/01 12:45:30 | 000,000,000 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/06/01 11:33:45 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Brandon Miles\Desktop\~$lesResume.doc
[2010/06/01 10:34:36 | 000,000,530 | —- | M] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
[2010/06/01 10:20:12 | 000,739,696 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2010/06/01 10:20:11 | 000,133,520 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2010/06/01 09:56:49 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/06/01 09:56:02 | 000,032,240 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys
[2010/06/01 09:56:02 | 000,026,352 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys
[2010/06/01 09:56:02 | 000,021,488 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys
[2010/06/01 09:56:02 | 000,021,104 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys
[2010/06/01 07:32:11 | 045,145,784 | —- | M] (CA) – C:\Documents and Settings\Brandon Miles\Desktop\iss_en_32.exe
[2010/05/29 10:11:02 | 000,001,152 | —- | M] () – C:\WINDOWS\System32\windrv.sys
[2010/05/28 15:57:17 | 000,052,224 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\Boston_Company_List(1).xls
[2010/05/28 13:10:57 | 000,396,219 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/05/28 11:46:43 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Brandon Miles\My Documents\~$lesResumeFormat.doc
[2010/05/28 09:14:30 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/05/28 09:14:28 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/05/28 09:09:27 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/05/28 08:42:10 | 000,014,546 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.pdf
[2010/05/28 08:34:47 | 000,038,912 | —- | M] () – C:\Documents and Settings\Brandon Miles\My Documents\MilesResumeFormat.doc
[2010/05/28 08:22:20 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/28 08:09:52 | 000,046,592 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.doc
[2010/05/27 15:54:48 | 000,046,080 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-C.doc
[2010/05/26 16:51:18 | 000,047,104 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B[2][1].doc
[2010/05/24 19:34:37 | 000,000,073 | —- | M] () – C:\WINDOWS\webica.ini
[2010/05/24 18:26:13 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[2010/05/22 21:02:50 | 000,044,032 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B.doc
[2010/05/21 23:07:45 | 000,047,104 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume.doc
[2010/05/16 07:06:21 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/05/12 03:00:32 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== Files Created - No Company Name ==========

[2010/06/01 21:31:20 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 21:21:38 | 000,050,166 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/06/01 17:20:26 | 003,701,981 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\ComboFix.exe
[2010/06/01 17:06:26 | 000,966,213 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\tdsskiller.zip
[2010/06/01 13:37:45 | 001,402,880 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.msi
[2010/06/01 12:45:28 | 000,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2010/06/01 11:33:45 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Brandon Miles\Desktop\~$lesResume.doc
[2010/06/01 10:16:18 | 804,114,432 | -HS- | C] () – C:\hiberfil.sys
[2010/06/01 09:31:28 | 000,000,530 | —- | C] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
[2010/05/29 10:11:02 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2010/05/29 08:36:46 | 000,002,463 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.lnk
[2010/05/29 07:16:38 | 000,000,020 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\vqdlkr.dat
[2010/05/28 15:33:13 | 000,052,224 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\Boston_Company_List(1).xls
[2010/05/28 11:46:43 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Brandon Miles\My Documents\~$lesResumeFormat.doc
[2010/05/28 10:12:23 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/05/28 09:16:35 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/05/28 09:09:27 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/05/28 08:42:10 | 000,014,546 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.pdf
[2010/05/27 23:50:58 | 000,038,912 | —- | C] () – C:\Documents and Settings\Brandon Miles\My Documents\MilesResumeFormat.doc
[2010/05/27 15:56:05 | 000,046,592 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.doc
[2010/05/27 15:46:31 | 000,046,080 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-C.doc
[2010/05/26 16:51:18 | 000,047,104 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B[2][1].doc
[2010/05/21 23:19:58 | 000,044,032 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B.doc
[2010/05/21 23:07:44 | 000,047,104 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume.doc
[2010/05/16 07:06:21 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/05/16 07:06:21 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2008/04/07 00:43:21 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2007/09/21 23:13:10 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/12/26 13:09:28 | 000,000,073 | —- | C] () – C:\WINDOWS\webica.ini
[2006/06/21 06:33:40 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/03/21 17:11:51 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2006/02/20 05:00:42 | 000,003,084 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2005/10/14 05:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 05:56:50 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 05:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 05:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 05:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 05:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 05:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2004/10/12 19:17:15 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/11/22 21:39:38 | 000,000,000 | —- | C] () – C:\WINDOWS\QTW.ini
[2003/02/23 20:11:47 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2003/02/23 20:11:47 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2003/02/23 20:11:47 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2002/11/05 19:42:20 | 000,000,105 | —- | C] () – C:\WINDOWS\TheMatrix.ini
[2002/10/15 17:38:06 | 000,000,020 | —- | C] () – C:\WINDOWS\InfModM.ini
[2002/08/15 01:25:39 | 000,000,930 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2002/06/20 18:31:44 | 000,001,095 | —- | C] () – C:\WINDOWS\ChemDraw.ini
[2002/06/20 09:43:36 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2002/06/13 02:02:41 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/06/13 01:57:12 | 000,000,029 | —- | C] () – C:\WINDOWS\wgedit.ini
[2002/06/13 01:57:10 | 000,057,344 | —- | C] () – C:\WINDOWS\uninstBVRP.dll
[2002/06/13 01:57:01 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2002/06/13 01:52:16 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/06/13 00:32:40 | 000,000,480 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2001/11/15 09:19:38 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[1999/01/22 22:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/06/01 22:05:54 | 000,007,615 | —- | M] () – C:\aaw7boot.log
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/01 12:45:30 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2001/11/14 17:35:22 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2010/06/01 09:31:50 | 000,034,844 | —- | M] () – C:\caavsetupLog.txt
[2010/06/01 10:17:28 | 000,027,094 | —- | M] () – C:\caisslog.txt
[2006/12/26 13:09:29 | 000,000,000 | —- | M] () – C:\COMLOG.txt
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2002/06/13 00:34:44 | 000,003,869 | RH– | M] () – C:\DELL.SDR
[2010/06/01 22:05:57 | 804,114,432 | -HS- | M] () – C:\hiberfil.sys
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2002/06/13 02:00:05 | 000,000,314 | -H– | M] () – C:\IPH.PH
[2007/12/16 16:47:42 | 000,000,138 | —- | M] () – C:\moduleName.txt
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2003/12/09 01:08:47 | 000,509,624 | R— | M] () – C:\My Money Backup.mny.mbf
[2004/11/22 15:39:24 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/04 17:58:27 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/06/01 22:05:55 | 1206,067,200 | -HS- | M] () – C:\pagefile.sys
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2010/06/01 17:10:32 | 000,045,352 | —- | M] () – C:\TDSSKiller.2.3.2.0_01.06.2010_17.09.06_log.txt
[2008/09/10 03:08:02 | 000,098,617 | —- | M] () – C:\YServer.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/07/03 23:25:03 | 000,421,888 | —- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\ATIDEMGX.dll
[2010/03/11 08:38:51 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtmsft.dll
[2010/03/11 08:38:51 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2003/01/23 12:29:50 | 000,524,288 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\default.sav
[2003/01/23 18:22:57 | 000,262,144 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\security.sav
[2003/01/23 12:29:50 | 016,252,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\software.sav
[2003/01/23 12:29:51 | 004,194,304 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\system.sav

< %systemroot%\system32\drivers\*.sys /180 >
[2010/02/04 11:53:02 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\SYSTEM32\DRIVERS\Lbd.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mrxsmb.sys
[2010/06/01 17:12:06 | 000,003,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\pciide.sys
[2010/05/28 09:14:30 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\SYSTEM32\DRIVERS\SBREDrv.sys
[2009/12/31 12:50:03 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\srv.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys
[2010/06/01 09:56:02 | 000,026,352 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-filt.sys
[2010/06/01 09:56:02 | 000,021,104 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-rec.sys
[2010/06/01 10:20:11 | 000,133,520 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\veteboot.sys
[2010/06/01 10:20:12 | 000,739,696 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetefile.sys
[2010/06/01 09:56:02 | 000,021,488 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetfddnt.sys
[2010/06/01 09:56:02 | 000,032,240 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetmonnt.sys

< C:\Users\Amanda\AppData\Roaming\Luzebu\*.* /s >

< C:\Users\Amanda\AppData\Roaming\Ogba\*.* /s >
< End of report >

6. The startup after reboot is a little slower than normal, but otherwise everything is working fine.
Hello,

Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 20 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
– Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
– Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note:
The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.


NEXT



Clean Java Cache & Temporary Files
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT:



Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it in your next reply.


NEXT:



OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    [2010/06/01 21:29:49 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Brandon Miles\Desktop\mbam-setup-1.46.exe
    [2010/05/29 07:16:38 | 000,000,020 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\vqdlkr.dat
    :Files
    C:\Documents and Settings\Brandon Miles\Shared\jaimee hammer cute girl has orgasm on webcam.mpg
    C:\Program Files\Morpheus\morpheustoolbar.exe
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Windows installed the updates overnight and restarted my computer. Will this affect anything, or should I continue as directed? Thanks,
Small problem - when I download the JRE file, the link is listed as a .exe file, but it downloads to my desktop as an EFW file. It will not open. Suggestions?
Try doing this:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
When the download is complete, close your browser.
  • Double-click on the saved file ( jre-6u20-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer (version 6 update 20).
  • Make sure you uninstall all old Java installations from Add and Remove after obtaining the latest update.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI