This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Audio Virus Plays Random Advertisements

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Sorry for the lack of clarity, my computer knowledge isn't very extensive. What I mean is that if i was playing a video game for example, my computer would exit me out of the game and take me straight to windows. The reason it does this is for 3 reasons from what I can tell : 1. for the pop up 2. for the audio pop up. or 3. is when the Master Audio panel.

This link shows what panel I am talking about, sorry I do not have a digital camera on me. http://www.askdavetaylor.com/0-blog-pics/w…ume-control.png
As you can see, the second section of the control is called wave, this section has the volume turned all the way down randomly, and this is what causes the "windowing" when I am playing games or doing something else. This happens right when the background iexplorer starts that I can see in task manager, but there is no actual internet window that I can see. I hope that makes it a little bit more specific.
Thank you so much for your patience, I really appreciate it.

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 82.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 153.38 Gb Total Space | 25.55 Gb Free Space | 16.66% Space Free | Partition Type: NTFS
Drive D: | 3.86 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MARIO
Current User Name: Optimus
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Optimus\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\System Volume Information\Microsoft\smss.exe (Black Internet)
PRC - C:\System Volume Information\Microsoft\services.exe (Black Internet)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\AOL\1151188401\ee\aolsoftware.exe (America Online, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Optimus\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nvata) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "AIM Search"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;="

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/24 00:48:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/26 18:59:41 | 000,000,000 | —D | M]

[2009/11/15 19:40:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Extensions
[2009/08/12 00:04:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Extensions\[removed]
[2006/09/09 10:28:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Firefox\Profiles\5oxadeo9.default\extensions
[2010/06/26 19:01:04 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/26 18:59:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/26 18:59:30 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/26 11:22:39 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151188401\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\PROGRA~1\MI3AA1~1\wcescomm.exe File not found
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe File not found
O4 - Startup: C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://lioncam1.lmu.edu/activex/AMC.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/24 14:06:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/08/05 10:02:19 | 000,398,600 | R— | M] (Electronic Arts Inc.) - D:\Autorun.exe – [ UDF ]
O32 - AutoRun File - [2008/08/05 09:23:19 | 000,000,043 | R— | M] () - D:\Autorun.inf – [ UDF ]
O32 - AutoRun File - [2008/08/05 09:52:02 | 000,000,000 | R–D | M] - D:\autorun – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2006/06/24 14:06:35 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 90 Days ==========

[2010/06/26 19:00:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/06/26 18:59:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/06/26 18:59:46 | 000,000,000 | —D | C] – C:\Program Files\Sun
[2010/06/24 18:23:08 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/06/24 18:18:15 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/06/24 18:16:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/06/24 18:16:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/06/24 18:16:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/06/24 18:16:54 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/06/24 18:09:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/06/24 18:08:13 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/23 15:37:01 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2010/06/23 15:06:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Optimus\Recent
[2010/06/23 01:23:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Application Data\Malwarebytes
[2010/06/23 01:23:38 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/23 01:23:37 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/23 01:23:37 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/23 01:23:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/22 16:59:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\My Documents\Heroes of Newerth
[2010/06/22 16:58:35 | 000,000,000 | —D | C] – C:\WINDOWS\Logs
[2010/06/22 16:58:21 | 000,000,000 | —D | C] – C:\Program Files\Heroes of Newerth
[2010/05/08 18:34:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\WINDOWS
[2010/05/08 18:34:37 | 000,000,000 | —D | C] – C:\MAXIS
[2010/05/07 20:49:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\My Documents\My Spore Creations
[2010/05/07 20:49:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Application Data\SPORE
[2010/04/13 11:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Desktop\Copy of LOTRO_World_Tour_installer

========== Files - Modified Within 90 Days ==========

[2010/06/27 00:42:15 | 000,194,449 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/06/27 00:42:13 | 000,012,540 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/27 00:40:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/27 00:40:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/26 20:09:12 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Optimus\NTUSER.DAT
[2010/06/26 20:09:12 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Optimus\ntuser.ini
[2010/06/26 18:41:33 | 080,398,104 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\jdk-6u20-windows-i586.exe
[2010/06/26 18:35:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/26 11:22:44 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/26 11:22:39 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/24 18:18:21 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/06/24 18:14:45 | 000,000,666 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.lnk
[2010/06/24 18:10:00 | 003,719,852 | R— | M] () – C:\Documents and Settings\Optimus\Desktop\ComboFix.exe
[2010/06/24 18:03:52 | 000,000,562 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Optimus.job
[2010/06/24 11:05:45 | 000,001,464 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Roorepealscan
[2010/06/23 15:46:17 | 000,012,540 | —- | M] () – C:\WINDOWS\System32\wpa.bak
[2010/06/23 15:29:34 | 000,000,477 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/23 15:29:34 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/22 16:59:07 | 000,001,606 | —- | M] () – C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk
[2010/06/22 16:59:07 | 000,001,588 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Heroes of Newerth.lnk
[2010/06/19 15:43:26 | 000,000,751 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/06/09 11:07:34 | 000,169,896 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/08 22:19:46 | 000,036,483 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\YUP.jpg
[2010/06/03 17:09:31 | 000,025,444 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\fuckboston.jpg
[2010/05/28 22:52:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/07 20:49:28 | 000,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2010/05/06 09:25:22 | 000,002,515 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Microsoft Office Word 2007.lnk
[2010/05/05 22:08:29 | 000,013,688 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Sociology 100 Study Guide.docx
[2010/05/03 22:11:12 | 000,015,417 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Philosophy Study Guide.docx
[2010/05/03 11:03:34 | 000,013,080 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou58.docx
[2010/05/02 19:06:06 | 000,382,347 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\I speak directly to the people.docx
[2010/04/29 21:20:00 | 000,061,569 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.2FINAL.docx
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/29 14:17:50 | 000,946,286 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Drive for Muscularity, Body Image, Gym.pptx
[2010/04/28 23:03:04 | 000,012,728 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou57.docx
[2010/04/26 22:05:01 | 000,026,333 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\SOCFINALPAPER.docx
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[2010/04/25 22:06:46 | 000,025,682 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\In 1954 the U.docx
[2010/04/22 23:56:35 | 000,014,965 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Sociology Notes.docx
[2010/04/21 20:13:10 | 000,025,151 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.1.docx
[2010/04/21 19:39:41 | 000,013,766 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou56.docx
[2010/04/20 20:24:20 | 000,520,632 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\adriana_lima_169.jpg
[2010/04/20 15:38:26 | 000,024,428 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction.docx
[2010/04/19 23:07:18 | 000,017,722 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Walking through the grocery store.docx
[2010/04/18 19:21:41 | 000,014,609 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\This week we had to read about post modernism and Jean Baudrillard.docx
[2010/04/14 19:23:39 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Optimus\My Documents\~$lking through the grocery store.docx
[2010/04/13 08:33:11 | 000,014,705 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey (1).docx
[2010/04/12 21:45:45 | 000,014,645 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey.docx
[2010/04/12 21:39:40 | 002,120,876 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\SINGH#1.pdf
[2010/04/12 19:30:58 | 000,013,639 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Coverletter (1).docx
[2010/04/12 19:23:04 | 000,039,936 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Resume (1).doc
[2010/04/08 23:05:54 | 000,877,247 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\DMSCALE.pdf

========== Files Created - No Company Name ==========

[2010/06/26 18:37:47 | 080,398,104 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\jdk-6u20-windows-i586.exe
[2010/06/26 18:35:51 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/24 18:18:21 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/06/24 18:18:17 | 000,260,272 | —- | C] () – C:\cmldr
[2010/06/24 18:16:54 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/24 18:16:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/24 18:16:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/24 18:16:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/24 18:16:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/06/24 18:14:45 | 000,000,666 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.lnk
[2010/06/24 18:10:00 | 003,719,852 | R— | C] () – C:\Documents and Settings\Optimus\Desktop\ComboFix.exe
[2010/06/24 11:05:45 | 000,001,464 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Roorepealscan
[2010/06/23 15:30:08 | 000,256,000 | —- | C] () – C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\PowerReg Scheduler.exe
[2010/06/23 15:30:08 | 000,000,876 | —- | C] () – C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
[2010/06/22 16:59:07 | 000,001,606 | —- | C] () – C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk
[2010/06/22 16:59:06 | 000,001,588 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Heroes of Newerth.lnk
[2010/06/08 22:19:46 | 000,036,483 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\YUP.jpg
[2010/06/03 17:09:31 | 000,025,444 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\fuckboston.jpg
[2010/05/08 18:34:37 | 000,136,448 | —- | C] () – C:\WINDOWS\RMTOOLS.DLL
[2010/05/03 11:37:49 | 000,015,417 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Philosophy Study Guide.docx
[2010/05/02 19:36:54 | 000,013,080 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou58.docx
[2010/05/01 22:41:29 | 000,013,688 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Sociology 100 Study Guide.docx
[2010/04/29 12:24:01 | 000,946,286 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Drive for Muscularity, Body Image, Gym.pptx
[2010/04/28 22:09:34 | 000,382,347 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\I speak directly to the people.docx
[2010/04/26 21:59:41 | 000,012,728 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou57.docx
[2010/04/25 22:39:26 | 000,026,333 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\SOCFINALPAPER.docx
[2010/04/22 23:56:35 | 000,014,965 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Sociology Notes.docx
[2010/04/21 22:42:25 | 000,061,569 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.2FINAL.docx
[2010/04/21 20:13:10 | 000,025,151 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.1.docx
[2010/04/21 16:36:03 | 000,013,766 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou56.docx
[2010/04/20 20:24:20 | 000,520,632 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\adriana_lima_169.jpg
[2010/04/20 12:19:27 | 000,025,682 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\In 1954 the U.docx
[2010/04/18 19:21:40 | 000,014,609 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\This week we had to read about post modernism and Jean Baudrillard.docx
[2010/04/14 19:23:39 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Optimus\My Documents\~$lking through the grocery store.docx
[2010/04/13 08:33:11 | 000,014,705 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey (1).docx
[2010/04/12 22:11:51 | 000,017,722 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Walking through the grocery store.docx
[2010/04/12 21:39:40 | 002,120,876 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\SINGH#1.pdf
[2010/04/12 19:24:07 | 000,013,639 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Coverletter (1).docx
[2010/04/12 19:23:04 | 000,039,936 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Resume (1).doc
[2010/04/09 21:19:03 | 000,014,645 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey.docx
[2010/04/08 23:05:54 | 000,877,247 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\DMSCALE.pdf
[2009/06/10 08:29:34 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/06/10 08:29:34 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/06/10 08:29:34 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/06/10 08:29:32 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/11/18 13:44:40 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/12/18 19:17:38 | 000,137,544 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/05/27 21:49:01 | 000,000,047 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/03/31 16:46:15 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/09/13 14:21:44 | 000,000,173 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/08/31 16:52:19 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/08/14 14:20:26 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/06/24 15:31:19 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2006/06/24 14:27:14 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2006/06/24 14:13:17 | 000,000,269 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2006/06/24 14:12:58 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/06/24 14:12:55 | 000,005,309 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/06/24 14:12:53 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/06/01 17:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/06/01 17:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2009/09/08 20:12:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/05/12 09:40:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/17 19:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/06/24 15:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\acccore
[2009/09/08 17:35:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Aim
[2007/09/15 09:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\BitTorrent
[2007/04/07 18:32:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\GetRightToGo
[2007/09/12 21:27:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Leadertech
[2006/11/19 10:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\My Battle for Middle-earth™ II Files
[2009/12/24 18:49:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\runic games
[2006/10/11 21:50:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Simple Star
[2006/10/11 22:08:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Snapfish
[2010/05/07 20:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\SPORE
[2007/04/07 19:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Turbine
[2007/01/27 02:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Viewpoint

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/02/20 22:06:17 | 003,517,236 | —- | M] () – C:\01 The Second Coming.m4p
[2006/06/26 20:01:54 | 000,004,632 | —- | M] () – C:\0x0409.ini
[2006/06/26 20:01:55 | 000,740,864 | —- | M] () – C:\1033.MST
[2006/06/24 14:06:56 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/06/28 18:16:36 | 005,381,769 | —- | M] () – C:\Big tymers - Still Fly .mp3
[2010/06/23 15:29:34 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/24 18:18:21 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/06/26 11:23:43 | 000,014,749 | —- | M] () – C:\ComboFix.txt
[2006/06/24 14:06:56 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/09/12 16:05:58 | 000,000,127 | —- | M] () – C:\CountCyclesWMVDecLog.txt
[2009/06/16 12:02:19 | 000,000,197 | —- | M] () – C:\csb.log
[2006/07/02 10:27:27 | 003,035,371 | —- | M] () – C:\Destiny's Child - Survivor .mp3
[2006/07/06 14:20:15 | 008,522,092 | —- | M] () – C:\Imogen Heap - Speeding Cars.mp3
[2006/06/24 14:06:56 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/06/26 20:01:59 | 033,954,304 | —- | M] () – C:\iPod for Windows 2006-03-23.msi
[2006/06/29 22:59:36 | 005,919,056 | —- | M] () – C:\Mario - Let Me Love You.mp3
[2006/06/29 22:54:16 | 003,837,283 | —- | M] () – C:\Marvin Gaye - Lets Get It On.mp3
[2006/06/24 14:06:56 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/06/29 22:57:14 | 001,206,272 | —- | M] () – C:\National Anthem - American (Star Spangled Banner).mp3
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/14 17:39:07 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/06/27 00:40:39 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2009/06/16 11:58:24 | 000,001,519 | —- | M] () – C:\RHDSetup.log
[2006/07/06 14:25:43 | 005,861,729 | —- | M] () – C:\Sean Paul ft Keisha Cole - Give It Up To Me (remix).mp3

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2005/10/14 22:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 17:11:51 | 000,033,280 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\cryptdll.dll
[2008/04/13 17:11:55 | 000,094,720 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\iphlpapi.dll
[2008/04/13 17:11:59 | 002,843,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msi.dll
[2004/08/04 05:00:00 | 000,146,432 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msls31.dll
[2008/04/13 11:30:46 | 000,061,440 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msvcrt40.dll
[2008/04/13 17:12:03 | 000,237,056 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\rasapi32.dll
[2008/04/13 17:12:03 | 000,061,440 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\rasman.dll
[2008/04/13 17:12:04 | 000,433,664 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\riched20.dll
[2008/04/13 17:12:04 | 000,044,032 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\rtutils.dll
[2008/04/13 17:12:05 | 000,007,168 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\sensapi.dll
[2008/04/13 17:12:07 | 000,713,216 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\sxs.dll
[2008/04/13 17:12:07 | 000,181,760 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\tapi32.dll
[2008/04/13 17:12:10 | 000,022,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\wsock32.dll
[2008/04/13 10:39:24 | 002,897,920 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\xpsp2res.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/06/24 21:51:37 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/06/24 21:51:37 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/06/24 21:51:37 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 17:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 17:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\ws2_32.dll
< End of report >




ROOTREPEAL © AD, 2007-2010
==================================================
Report Save Time: 2010/06/27 00:59
Program Version: Version 2.0.0.0
Windows Version: Windows XP SP3
==================================================

STEALTH CODE
——————-
System 0xe2414c30 - Hidden Code [Driver: prodrv06, IRP: IRP_MJ_CLOSE]
System 0xe2414c30 - Hidden Code [Driver: prodrv06, IRP: IRP_MJ_CREATE]
System 0xe2414c30 - Hidden Code [Driver: prodrv06, IRP: IRP_MJ_DEVICE_CONTROL]
System 0xe1016a60 - Hidden Code [Driver: prohlp02, IRP: IRP_MJ_CLOSE]
System 0xe1016a60 - Hidden Code [Driver: prohlp02, IRP: IRP_MJ_CREATE]
System 0xe1016a60 - Hidden Code [Driver: prohlp02, IRP: IRP_MJ_DEVICE_CONTROL]
TeaTimer.exe 0x8a072998 - Hidden Handle [Index: 296, Type: Event]
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\System Volume Information\Microsoft\smss.exe (Black Internet)
    PRC - C:\System Volume Information\Microsoft\services.exe (Black Internet)
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
    O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log
Hi, Thanks Again. All processes killed ========== OTL ========== Process smss.exe killed successfully! Process services.exe killed successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: Default User User: LocalService User: NetworkService User: Optimus ->Flash cache emptied: 10600 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Optimus ->Temp folder emptied: 682249 bytes ->Temporary Internet Files folder emptied: 1373046 bytes ->Java cache emptied: 127542 bytes ->FireFox cache emptied: 89233966 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 672 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32045029 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 118.00 mb OTL by OldTimer - Version 3.2.7.0 log created on 06272010_112536 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi,

Thank you again for all your help, I am sorry this is becoming to be so difficult. My computer is running significantly faster, but I am still experiencing the same symptoms I have described to you earlier regarding the volume control and iexplorer running, that can only be seen through task manager. Here is the fresh log.

OTL logfile created on: 6/27/2010 12:25:36 PM - Run 3
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Optimus\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 82.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 153.38 Gb Total Space | 25.55 Gb Free Space | 16.66% Space Free | Partition Type: NTFS
Drive D: | 3.86 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MARIO
Current User Name: Optimus
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\System Volume Information\Microsoft\smss.exe (Black Internet)
PRC - C:\System Volume Information\Microsoft\services.exe (Black Internet)
PRC - C:\Documents and Settings\Optimus\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\AOL\1151188401\ee\aolsoftware.exe (America Online, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Optimus\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nvata) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "AIM Search"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;="

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/24 00:48:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/26 18:59:41 | 000,000,000 | —D | M]

[2009/11/15 19:40:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Extensions
[2009/08/12 00:04:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Extensions\[removed]
[2006/09/09 10:28:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Firefox\Profiles\5oxadeo9.default\extensions
[2010/06/26 19:01:04 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/26 18:59:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/26 18:59:30 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/27 11:25:36 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151188401\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\PROGRA~1\MI3AA1~1\wcescomm.exe File not found
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe File not found
O4 - Startup: C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://lioncam1.lmu.edu/activex/AMC.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/24 14:06:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/08/05 10:02:19 | 000,398,600 | R— | M] (Electronic Arts Inc.) - D:\Autorun.exe – [ UDF ]
O32 - AutoRun File - [2008/08/05 09:23:19 | 000,000,043 | R— | M] () - D:\Autorun.inf – [ UDF ]
O32 - AutoRun File - [2008/08/05 09:52:02 | 000,000,000 | R–D | M] - D:\autorun – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/27 11:25:57 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/06/27 11:25:36 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/26 19:00:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/06/26 18:59:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/06/26 18:59:46 | 000,000,000 | —D | C] – C:\Program Files\Sun
[2010/06/24 18:23:08 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/06/24 18:18:15 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/06/24 18:16:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/06/24 18:16:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/06/24 18:16:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/06/24 18:16:54 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/06/24 18:09:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/06/24 18:08:13 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/23 15:37:01 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2010/06/23 15:06:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Optimus\Recent
[2010/06/23 01:23:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Application Data\Malwarebytes
[2010/06/23 01:23:38 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/23 01:23:37 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/23 01:23:37 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/23 01:23:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/22 16:59:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\My Documents\Heroes of Newerth
[2010/06/22 16:58:35 | 000,000,000 | —D | C] – C:\WINDOWS\Logs
[2010/06/22 16:58:21 | 000,000,000 | —D | C] – C:\Program Files\Heroes of Newerth
[2010/05/08 18:34:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\WINDOWS
[2010/05/08 18:34:37 | 000,000,000 | —D | C] – C:\MAXIS
[2010/05/07 20:49:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\My Documents\My Spore Creations
[2010/05/07 20:49:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Application Data\SPORE
[2010/04/13 11:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Desktop\Copy of LOTRO_World_Tour_installer

========== Files - Modified Within 90 Days ==========

[2010/06/27 12:24:41 | 000,012,540 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/27 12:24:28 | 000,194,449 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/06/27 12:24:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/27 12:24:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/27 12:23:22 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Optimus\NTUSER.DAT
[2010/06/27 12:23:22 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Optimus\ntuser.ini
[2010/06/27 11:25:36 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2010/06/27 01:02:26 | 000,013,044 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\windows-volume-control.png
[2010/06/27 00:59:27 | 000,001,594 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\ddd
[2010/06/27 00:57:42 | 000,132,096 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\RootRepeal(2).exe
[2010/06/26 18:41:33 | 080,398,104 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\jdk-6u20-windows-i586.exe
[2010/06/26 18:35:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/26 11:22:44 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/24 18:18:21 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/06/24 18:14:45 | 000,000,666 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.lnk
[2010/06/24 18:10:00 | 003,719,852 | R— | M] () – C:\Documents and Settings\Optimus\Desktop\ComboFix.exe
[2010/06/24 18:03:52 | 000,000,562 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Optimus.job
[2010/06/24 11:05:45 | 000,001,464 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Roorepealscan
[2010/06/23 15:46:17 | 000,012,540 | —- | M] () – C:\WINDOWS\System32\wpa.bak
[2010/06/23 15:29:34 | 000,000,477 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/23 15:29:34 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/22 16:59:07 | 000,001,606 | —- | M] () – C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk
[2010/06/22 16:59:07 | 000,001,588 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Heroes of Newerth.lnk
[2010/06/19 15:43:26 | 000,000,751 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/06/09 11:07:34 | 000,169,896 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/08 22:19:46 | 000,036,483 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\YUP.jpg
[2010/06/03 17:09:31 | 000,025,444 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\fuckboston.jpg
[2010/05/28 22:52:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/07 20:49:28 | 000,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2010/05/06 09:25:22 | 000,002,515 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Microsoft Office Word 2007.lnk
[2010/05/05 22:08:29 | 000,013,688 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Sociology 100 Study Guide.docx
[2010/05/03 22:11:12 | 000,015,417 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Philosophy Study Guide.docx
[2010/05/03 11:03:34 | 000,013,080 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou58.docx
[2010/05/02 19:06:06 | 000,382,347 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\I speak directly to the people.docx
[2010/04/29 21:20:00 | 000,061,569 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.2FINAL.docx
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/29 14:17:50 | 000,946,286 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Drive for Muscularity, Body Image, Gym.pptx
[2010/04/28 23:03:04 | 000,012,728 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou57.docx
[2010/04/26 22:05:01 | 000,026,333 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\SOCFINALPAPER.docx
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[2010/04/25 22:06:46 | 000,025,682 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\In 1954 the U.docx
[2010/04/22 23:56:35 | 000,014,965 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Sociology Notes.docx
[2010/04/21 20:13:10 | 000,025,151 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.1.docx
[2010/04/21 19:39:41 | 000,013,766 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou56.docx
[2010/04/20 20:24:20 | 000,520,632 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\adriana_lima_169.jpg
[2010/04/20 15:38:26 | 000,024,428 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction.docx
[2010/04/19 23:07:18 | 000,017,722 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Walking through the grocery store.docx
[2010/04/18 19:21:41 | 000,014,609 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\This week we had to read about post modernism and Jean Baudrillard.docx
[2010/04/14 19:23:39 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Optimus\My Documents\~$lking through the grocery store.docx
[2010/04/13 08:33:11 | 000,014,705 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey (1).docx
[2010/04/12 21:45:45 | 000,014,645 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey.docx
[2010/04/12 21:39:40 | 002,120,876 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\SINGH#1.pdf
[2010/04/12 19:30:58 | 000,013,639 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Coverletter (1).docx
[2010/04/12 19:23:04 | 000,039,936 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Resume (1).doc
[2010/04/08 23:05:54 | 000,877,247 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\DMSCALE.pdf

========== Files Created - No Company Name ==========

[2010/06/27 01:02:25 | 000,013,044 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\windows-volume-control.png
[2010/06/27 00:59:27 | 000,001,594 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\ddd
[2010/06/27 00:57:41 | 000,132,096 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\RootRepeal(2).exe
[2010/06/26 18:37:47 | 080,398,104 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\jdk-6u20-windows-i586.exe
[2010/06/26 18:35:51 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/24 18:18:21 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/06/24 18:18:17 | 000,260,272 | —- | C] () – C:\cmldr
[2010/06/24 18:16:54 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/24 18:16:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/24 18:16:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/24 18:16:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/24 18:16:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/06/24 18:14:45 | 000,000,666 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.lnk
[2010/06/24 18:10:00 | 003,719,852 | R— | C] () – C:\Documents and Settings\Optimus\Desktop\ComboFix.exe
[2010/06/24 11:05:45 | 000,001,464 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Roorepealscan
[2010/06/23 15:30:08 | 000,256,000 | —- | C] () – C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\PowerReg Scheduler.exe
[2010/06/23 15:30:08 | 000,000,876 | —- | C] () – C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
[2010/06/22 16:59:07 | 000,001,606 | —- | C] () – C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk
[2010/06/22 16:59:06 | 000,001,588 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Heroes of Newerth.lnk
[2010/06/08 22:19:46 | 000,036,483 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\YUP.jpg
[2010/06/03 17:09:31 | 000,025,444 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\fuckboston.jpg
[2010/05/08 18:34:37 | 000,136,448 | —- | C] () – C:\WINDOWS\RMTOOLS.DLL
[2010/05/03 11:37:49 | 000,015,417 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Philosophy Study Guide.docx
[2010/05/02 19:36:54 | 000,013,080 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou58.docx
[2010/05/01 22:41:29 | 000,013,688 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Sociology 100 Study Guide.docx
[2010/04/29 12:24:01 | 000,946,286 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Drive for Muscularity, Body Image, Gym.pptx
[2010/04/28 22:09:34 | 000,382,347 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\I speak directly to the people.docx
[2010/04/26 21:59:41 | 000,012,728 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou57.docx
[2010/04/25 22:39:26 | 000,026,333 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\SOCFINALPAPER.docx
[2010/04/22 23:56:35 | 000,014,965 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Sociology Notes.docx
[2010/04/21 22:42:25 | 000,061,569 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.2FINAL.docx
[2010/04/21 20:13:10 | 000,025,151 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.1.docx
[2010/04/21 16:36:03 | 000,013,766 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou56.docx
[2010/04/20 20:24:20 | 000,520,632 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\adriana_lima_169.jpg
[2010/04/20 12:19:27 | 000,025,682 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\In 1954 the U.docx
[2010/04/18 19:21:40 | 000,014,609 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\This week we had to read about post modernism and Jean Baudrillard.docx
[2010/04/14 19:23:39 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Optimus\My Documents\~$lking through the grocery store.docx
[2010/04/13 08:33:11 | 000,014,705 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey (1).docx
[2010/04/12 22:11:51 | 000,017,722 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Walking through the grocery store.docx
[2010/04/12 21:39:40 | 002,120,876 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\SINGH#1.pdf
[2010/04/12 19:24:07 | 000,013,639 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Coverletter (1).docx
[2010/04/12 19:23:04 | 000,039,936 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Resume (1).doc
[2010/04/09 21:19:03 | 000,014,645 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey.docx
[2010/04/08 23:05:54 | 000,877,247 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\DMSCALE.pdf
[2009/06/10 08:29:34 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/06/10 08:29:34 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/06/10 08:29:34 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/06/10 08:29:32 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/11/18 13:44:40 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/12/18 19:17:38 | 000,137,544 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/05/27 21:49:01 | 000,000,047 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/03/31 16:46:15 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/09/13 14:21:44 | 000,000,173 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/08/31 16:52:19 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/08/14 14:20:26 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/06/24 15:31:19 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2006/06/24 14:27:14 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2006/06/24 14:13:17 | 000,000,269 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2006/06/24 14:12:58 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/06/24 14:12:55 | 000,005,309 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/06/24 14:12:53 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/06/01 17:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/06/01 17:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2009/09/08 20:12:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/05/12 09:40:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/17 19:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/06/24 15:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\acccore
[2009/09/08 17:35:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Aim
[2007/09/15 09:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\BitTorrent
[2007/04/07 18:32:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\GetRightToGo
[2007/09/12 21:27:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Leadertech
[2006/11/19 10:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\My Battle for Middle-earth™ II Files
[2009/12/24 18:49:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\runic games
[2006/10/11 21:50:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Simple Star
[2006/10/11 22:08:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Snapfish
[2010/05/07 20:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\SPORE
[2007/04/07 19:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Turbine
[2007/01/27 02:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Viewpoint

========== Purity Check ==========


< End of report >
Please do the following:

  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.



NEXT


  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    C:\System Volume Information\Microsoft\smss.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


do the same for the following file:

C:\System Volume Information\Microsoft\services.exe



NEXT


Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c "mbr -t" >Log.txt&Log.txt&del Log.txt


A Notepad file will open. Post the contents of Log.txt in your next reply.
VirSCAN.org Scanned Report :
Scanned time : 2010/06/28 08:32:20 (CST)
Scanner results: 44% Scanner(s) (16/36) found malware!
File Name : smss.exe
File Size : 31870 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 624d1b2df758544803fcb909805733d7
SHA1 : a06c4dfe74b89268899dd9e6274dfd49937511bf
Online report : http://virscan.org/report/04b27750ef749390…4fd93b7ae7.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.11 20100626080606 2010-06-26 39.89 Trojan.Win32.Vilsel!IK
AhnLab V3 2010.06.18.01 2010.06.18 2010-06-18 6.74 -
AntiVir 8.2.4.2 7.10.8.191 2010-06-27 3.17 TR/Vilsel.ahzq
Antiy 2.0.18 20100628.4796407 2010-06-28 0.02 -
Arcavir 2009 201006270216 2010-06-27 0.03 -
Authentium 5.1.1 201006271203 2010-06-27 1.32 -
AVAST! 4.7.4 100627-1 2010-06-27 0.00 Win32:Cycler-H [Trj]
AVG 8.5.793 271.1.1/2967 2010-06-28 0.23 Generic18.RUJ
BitDefender 7.90123.6328108 7.32449 2010-06-28 3.80 Trojan.Generic.4298312
ClamAV 0.96.1 11264 2010-06-27 0.01 -
Comodo 3.13.579 5238 2010-06-27 1.26 -
CP Secure 1.3.0.5 2010.06.26 2010-06-26 0.00 -
Dr.Web 5.0.2.3300 2010.06.28 2010-06-28 8.51 -
F-Prot 4.4.4.56 20100627 2010-06-27 1.41 -
F-Secure 7.02.73807 2010.06.27.01 2010-06-27 10.89 Trojan-Clicker.Win32.Cycler.ajtx [AVP]
Fortinet 4.1.133 12.88 2010-06-27 0.21 -
GData 21.421/21.155 20100628 2010-06-28 12.42 Trojan-Clicker.Win32.Cycler.ajtx [Engine:A]
ViRobot 20100626 2010.06.26 2010-06-26 1.24 -
Ikarus T3.1.01.84 2010.06.27.76150 2010-06-27 6.94 Trojan.Win32.Vilsel
JiangMin 13.0.900 2010.06.27 2010-06-27 24.80 Trojan/Vilsel.ixg
Kaspersky 5.5.10 2010.06.27 2010-06-27 0.08 Trojan-Clicker.Win32.Cycler.ajtx
KingSoft 2009.2.5.15 2010.6.27.18 2010-06-27 9.08 -
McAfee 5400.1158 6026 2010-06-27 16.52 Downloader-BZH
Microsoft 1.5902 2010.06.28 2010-06-28 17.57 -
Norman 6.05.10 6.05.00 2010-06-27 6.01 W32/Suspicious_Gen2.BFLTA
Panda 9.05.01 2010.06.27 2010-06-27 11.43 -
Trend Micro 9.120-1004 7.270.06 2010-06-27 0.04 -
Quick Heal 10.00 2010.06.26 2010-06-26 4.12 -
Rising 20.0 22.53.04.05 2010-06-25 1.63 -
Sophos 3.07.1 4.54 2010-06-28 3.71 Troj/Unruy-Gen
Sunbelt 3.9.2426.2 6508 2010-06-25 10.73 Trojan.Win32.Generic!BT
Symantec 1.3.0.24 20100615.005 2010-06-15 0.05 -
nProtect 20100627.02 8805752 2010-06-27 30.21 Trojan.Generic.4298312
The Hacker 6.5.2.0 v00304 2010-06-25 0.76 -
VBA32 3.12.12.5 20100625.0804 2010-06-25 3.01 -
VirusBuster 4.5.11.10 10.126.105/20405772010-06-27 2.73 Trojan.DL.Unruy.JK



VirSCAN.org Scanned Report :
Scanned time : 2010/06/28 08:47:18 (CST)
Scanner results: 44% Scanner(s) (16/36) found malware!
File Name : services.exe
File Size : 25818 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 6522ac76ff77d1d2f20beee8be6d4feb
SHA1 : f33d7e29ca54ad8dd79ac586e6b3e7dd39d3cb51
Online report : http://virscan.org/report/899e994cff2a8e21…29a87d9648.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.11 20100626080606 2010-06-26 5.74 Trojan.Win32.Vilsel!IK
AhnLab V3 2010.06.18.01 2010.06.18 2010-06-18 1.24 -
AntiVir 8.2.4.2 7.10.8.191 2010-06-27 0.28 TR/Vilsel.ahzq
Antiy 2.0.18 20100628.4796407 2010-06-28 0.02 -
Arcavir 2009 201006270216 2010-06-27 0.03 -
Authentium 5.1.1 201006271203 2010-06-27 1.38 -
AVAST! 4.7.4 100627-1 2010-06-27 0.00 Win32:Cycler-H [Trj]
AVG 8.5.793 271.1.1/2967 2010-06-28 0.24 Generic18.RUJ
BitDefender 7.90123.6328108 7.32449 2010-06-28 3.81 Trojan.Generic.4298312
ClamAV 0.96.1 11264 2010-06-27 0.01 -
Comodo 3.13.579 5238 2010-06-27 0.93 -
CP Secure 1.3.0.5 2010.06.26 2010-06-26 0.00 -
Dr.Web 5.0.2.3300 2010.06.28 2010-06-28 8.54 -
F-Prot 4.4.4.56 20100627 2010-06-27 1.39 -
F-Secure 7.02.73807 2010.06.27.01 2010-06-27 0.16 Trojan-Clicker.Win32.Cycler.ajtx [AVP]
Fortinet 4.1.133 12.88 2010-06-27 0.18 -
GData 21.421/21.155 20100628 2010-06-28 7.05 Trojan-Clicker.Win32.Cycler.ajtx [Engine:A]
ViRobot 20100626 2010.06.26 2010-06-26 0.38 -
Ikarus T3.1.01.84 2010.06.27.76150 2010-06-27 6.95 Trojan.Win32.Vilsel
JiangMin 13.0.900 2010.06.27 2010-06-27 1.32 Trojan/Vilsel.ixg
Kaspersky 5.5.10 2010.06.27 2010-06-27 0.08 Trojan-Clicker.Win32.Cycler.ajtx
KingSoft 2009.2.5.15 2010.6.27.18 2010-06-27 1.10 -
McAfee 5400.1158 6026 2010-06-27 16.35 Downloader-BZH
Microsoft 1.5902 2010.06.28 2010-06-28 6.80 -
Norman 6.05.10 6.05.00 2010-06-27 6.01 -
Panda 9.05.01 2010.06.27 2010-06-27 2.54 -
Trend Micro 9.120-1004 7.270.06 2010-06-27 0.03 -
Quick Heal 10.00 2010.06.26 2010-06-26 1.59 -
Rising 20.0 22.53.04.05 2010-06-25 1.26 -
Sophos 3.07.1 4.54 2010-06-28 3.61 Troj/Unruy-Gen
Sunbelt 3.9.2426.2 6508 2010-06-25 9.05 Trojan.Win32.Generic!BT
Symantec 1.3.0.24 20100615.005 2010-06-15 0.05 -
nProtect 20100627.02 8805752 2010-06-27 7.97 Trojan.Generic.4298312
The Hacker 6.5.2.0 v00305 2010-06-27 0.31 Trojan/Clicker.Cycler.ajtx
VBA32 3.12.12.5 20100625.0804 2010-06-25 2.83 -
VirusBuster 4.5.11.10 10.126.105/20405772010-06-27 2.36 Trojan.DL.Unruy.JK



Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
Hi

You have a fairly new bootkit infection, sorry I missed it first time around, it's difficult to detect.
at least we have found the culprits,

Please do the following:


Download a fresh copy of ComboFix (delete the copy of combofix that you have on your desktop if you haven't already uninstalled it)


Link 1



then do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Virus_Spyware_and_Malware_Removal_f27.html

Collect::
C:\System Volume Information\Microsoft\smss.exe 
C:\System Volume Information\Microsoft\services.exe

MBR::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



This may or maynot work

We might need to fix the MBR in the recovery console, but we'll try this first

please run the MBR command after combofix as well
Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c "mbr -t" >Log.txt&Log.txt&del Log.txt

A Notepad file will open. Post the contents of Log.txt in your next reply.
Hi,

Thank you for all your help! No need for apologies, i greatly appreciate all your time and effort.

ComboFix 10-06-27.03 - Optimus 06/27/2010 19:16:59.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2617 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Optimus\Desktop\CFScript.txt

file zipped: c:\system volume information\Microsoft\services.exe
file zipped: c:\system volume information\Microsoft\smss.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\system volume information\Microsoft\services.exe
c:\system volume information\Microsoft\smss.exe

.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 )))))))))))))))))))))))))))))))
.

2010-06-27 18:25 . 2010-06-27 18:25 ——– d—–w- C:\_OTL
2010-06-27 02:00 . 2010-06-27 02:00 ——– d—–w- c:\program files\Common Files\Java
2010-06-27 01:59 . 2010-06-27 01:59 ——– d—–w- c:\program files\Sun
2010-06-27 01:59 . 2010-06-27 01:59 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-23 22:37 . 2010-06-23 22:37 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\Optimus\Application Data\Malwarebytes
2010-06-23 08:23 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-23 08:23 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-22 23:58 . 2008-10-10 11:52 452440 —-a-w- c:\windows\system32\d3dx10_40.dll
2010-06-22 23:58 . 2008-10-10 11:52 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll
2010-06-22 23:58 . 2008-10-10 11:52 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2010-06-22 23:58 . 2010-06-22 23:58 ——– d—–w- c:\windows\Logs
2010-06-22 23:58 . 2010-06-22 23:59 ——– d—–w- c:\program files\Heroes of Newerth

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 02:23 . 2006-07-27 20:12 ——– d—–w- c:\program files\Steam
2010-06-27 18:16 . 2010-06-27 18:16 503808 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2af84d0c-n\msvcp71.dll
2010-06-27 18:16 . 2010-06-27 18:16 499712 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2af84d0c-n\jmc.dll
2010-06-27 18:16 . 2010-06-27 18:16 348160 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2af84d0c-n\msvcr71.dll
2010-06-27 18:16 . 2010-06-27 18:16 61440 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-709cfa19-n\decora-sse.dll
2010-06-27 18:16 . 2010-06-27 18:16 12800 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-709cfa19-n\decora-d3d.dll
2010-06-27 01:59 . 2006-06-26 23:54 ——– d—–w- c:\program files\Java
2010-06-27 01:35 . 2006-09-06 03:28 ——– d—–w- c:\program files\Common Files\Adobe
2010-06-27 01:06 . 2006-06-24 21:44 ——– d—–w- c:\program files\Warcraft III
2010-06-25 00:22 . 2007-10-26 22:00 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-06-23 22:37 . 2010-06-23 22:37 3584 —-a-r- c:\documents and settings\Optimus\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-06-23 22:36 . 2009-12-16 22:48 ——– d—–w- c:\program files\MSECACHE
2010-06-23 22:23 . 2007-06-20 04:34 ——– d—–w- c:\program files\Google
2010-06-23 21:56 . 2006-06-24 21:13 ——– d—–w- c:\program files\Common Files\InstallShield
2010-06-23 21:56 . 2006-06-24 21:21 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-23 08:16 . 2009-08-26 04:53 ——– d—–w- c:\program files\LimeWire
2010-06-23 08:12 . 2006-11-08 05:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-23 08:00 . 2009-05-15 00:12 ——– d—–w- c:\program files\CCleaner
2010-06-23 01:57 . 2006-06-25 21:38 ——– d—–w- c:\program files\WC3Banlist
2010-06-23 01:55 . 2006-11-18 22:57 ——– d—–w- c:\program files\Electronic Arts
2010-06-17 06:57 . 2006-06-25 16:34 ——– d—–w- c:\program files\World of Warcraft
2010-06-09 08:15 . 2007-09-10 06:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-08 03:49 . 2010-05-08 03:49 ——– d—–w- c:\documents and settings\Optimus\Application Data\SPORE
2010-05-08 03:49 . 2006-08-14 21:19 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-05-02 05:22 . 2004-08-04 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 17:50 . 2006-08-29 03:39 ——– d—–w- c:\documents and settings\Optimus\Application Data\OpenOffice.org2
2010-04-20 05:30 . 2004-08-04 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-16 16:09 . 2004-08-04 12:00 667136 —-a-w- c:\windows\system32\wininet.dll
2010-04-16 16:09 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2010-04-14 15:57 . 2009-11-09 19:46 79488 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2010-05-08 1238352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2009-05-15 1103216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"HostManager"="c:\program files\Common Files\AOL\1151188401\ee\AOLSoftware.exe" [2006-05-10 50760]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
[BU]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aim6.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.11.0-enUS-downloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\[removed]\\team fortress classic\\hl.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6108-to-2.0.2.6144-enUS-downloader.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6144-to-2.0.2.6178-enUS-downloader.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.3.6282-to-2.0.3.6299-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\left 4 dead demo\\left4dead.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\america's army 3\\Binaries\\AA3Game.exe"=
"c:\\Program Files\\Heroes of Newerth\\hon.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard Downloader

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/8/2009 8:12 PM 24652]
.
Contents of the 'Scheduled Tasks' folder

2010-05-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34]

2010-06-25 c:\windows\Tasks\Norton Security Scan for Optimus.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-12 14:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://lioncam1.lmu.edu/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Optimus\Application Data\Mozilla\Firefox\Profiles\5oxadeo9.default\
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;=
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-27 19:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:26,fc,c1,ca,41,a1,9b,41,7b,e3,87,70,66,de,ee,2c,f2,f2,7c,49,5c,5f,54,
16,04,c6,27,74,f4,bc,e6,df,83,9d,a4,79,f6,2a,21,f3,9a,8a,b7,a0,b4,8a,78,32,\
"??"=hex:f0,21,15,d4,32,f9,f5,39,34,a4,1c,86,43,ce,d9,df

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:8b,f7,b7,24,e0,f4,3b,7c,50,28,8c,77,aa,e3,23,9b,fd,4c,23,5b,36,
7a,c4,21,4a,55,8a,2e,37,93,88,0f,f5,e6,71,fd,7d,79,fb,ac,2d,c6,7f,81,1d,00,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
———————— Other Running Processes ————————
.
c:\system volume information\Microsoft\services.exe
c:\windows\system32\nvsvc32.exe
c:\system volume information\Microsoft\smss.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\msiexec.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2010-06-27 19:29:27 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-28 02:29
ComboFix2.txt 2010-06-26 18:23
ComboFix3.txt 2010-06-25 01:38

Pre-Run: 27,411,509,248 bytes free
Post-Run: 27,423,145,984 bytes free

- - End Of File - - 0D65C770866ADE6DCB50597FC999B0F6



Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
OK

That didn't work

so we need to fix the MBR in the recovery console

Please do the following:

Earlier on ComboFix installed the Recovery Console. We're going to use that now.

Reboot your machine and when the Boot Menu flashes up - select "Microsoft Windows Recovery Console"
(you need to be very fast with the arrow key as you only have a couple of seconds before it defaults to the windows XP bootup)

[external image: Posted Image]

[external image: Posted Image]

When you get to the above screen, take note of the number that references your operating system.
If it's '1' like the picture above, type 1 and press Enter

[external image: Posted Image]

Next type FIXMBR

[external image: Posted Image]

If it ask if you're sure you want to write a new MBR, answer 'Y'

Then type EXIT to reboot the machine.



NEXT:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Audio_Virus_Plays_Random_Advertisements_t112790.html&view=findpost&p=662661#entry662661
KillAll::

Collect::
C:\System Volume Information\Microsoft\smss.exe
C:\System Volume Information\Microsoft\services.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi, Sorry for making your job harder, but my keyboard isn't responding at all until I get to the user sign in at windows. The arrow keys/enter key is not responding at all. I even tried it on the screen that lets me choose safe mode or normal mode and my keyboard still wouldnt respond. Any ideas as to why?
or a ps2 adapter.

there is another tool we can try that has been used on this infection with some success.

Try this:

Download Bootkit remover to your desktop
This is a rar file if you do not have a program to open it then download and install Peazip

Extract Remover.exe to your desktop

Double click Remover.exe to run it.

It will show a Black screen with some data on it

Right click on the screen and select > Select All

Press Control+C

Now open a notepad and press Control+V

Post the resultant log here please
Bootkit Remover version 1.0.0.1 © 2009 eSage Lab www.esagelab.com \\.\C: -> \\.\PhysicalDrive0 MD5: 33651d4929a84a7ab9d65c115ce1bdc0 Size Device Name MBR Status ——————————————– 153 GB \\.\PhysicalDrive0 Unknown boot code Unknown boot code has been found on some of your physical disks. To inspect the boot code manually, dump the master boot sector: remover.exe dump [output_file] To disinfect the master boot sector, use the following command: remover.exe fix Press any key to quit…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI