This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

infected

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I have a friend's computer here that I think may be infected. I can't access the internet, and I cannot install MBAM or Hijackthis. Also cannot run Spybot. Adaware seems to run fine. I ran ad-aware and deleted everything found. Still having problems. Your help is greatly appreciated, Thank you, mike
Hi 111mike,

:welcome:

My name is NightWizard and I will be your helper. :)

While I go through your log, I would very much appreciate it if you read the following.

  • I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
  • If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
  • Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
  • Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.

Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.



Thanks for choosing WhatTheTech and I will be back with a fix shortly! :)


-NightWizard
Please download OTL from one of the following links
  • LINK 1
  • LINK 2
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in;

    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.
Hi 111Mike,

If you see my previous instructions please disregard them.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 3 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.

http://download.bleepingcomputer.com/grinler/rkill.exe
http://download.bleepingcomputer.com/grinler/rkill.com
http://download.bleepingcomputer.com/grinler/rkill.scr

Note:

You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

Once the tool has run, do NOT reboot the machine. Try immediately to run OTL and GMER.
Hi 111mike,

Sorry for the delay!

Could you please try running the scan in Safe Mode.

To get into safe Mode:
Reboot than tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu.

If you get an error please jot down what it says on a piece of paper and tell me what it says.

Thanks
here ye be, both reports


OTL logfile created on: 8/21/2010 9:02:45 AM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.00 Mb Total Physical Memory | 274.00 Mb Available Physical Memory | 61.00% Memory free
720.00 Mb Paging File | 604.00 Mb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.02 Gb Total Space | 56.17 Gb Free Space | 82.59% Space Free | Partition Type: NTFS
Drive D: | 6.50 Gb Total Space | 1.44 Gb Free Space | 22.22% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 3.74 Gb Total Space | 0.07 Gb Free Space | 1.84% Space Free | Partition Type: FAT32

Computer Name: YOUR-27E1513D96
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/08/18 08:17:40 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/06/24 22:32:44 | 001,193,848 | —- | M] (McAfee, Inc.) – c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/08/18 08:17:40 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
MOD - [2006/08/25 08:45:55 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 05:00:00 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe – (mcupdmgr.exe)
SRV - File not found [Auto | Stopped] – c:\program files\mcafee.com\agent\mcdetect.exe – (McDetect.exe)
SRV - File not found [On_Demand | Stopped] – C:\WINDOWS\System32\appmgmts.dll – (AppMgmt)
SRV - [2010/05/31 20:32:58 | 000,188,136 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - [2010/05/31 20:32:58 | 000,141,792 | —- | M] (McAfee, Inc.) [Unknown | Stopped] – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe – (mfevtp)
SRV - [2010/04/15 09:45:10 | 000,364,216 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2010/04/14 12:50:14 | 000,170,144 | —- | M] () [Unknown | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2008/08/29 10:00:30 | 000,033,752 | —- | M] (NOS Microsystems Ltd.) [Disabled | Stopped] – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper) getPlus®
SRV - [2008/01/08 12:02:16 | 001,213,728 | —- | M] (SupportSoft, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe – (sprtlisten)
SRV - [2008/01/08 12:02:12 | 000,394,608 | —- | M] (SupportSoft, Inc.) [Disabled | Stopped] – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe – (SupportSoft RemoteAssist)
SRV - [2007/10/25 15:27:54 | 000,266,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\installer\WLSetupSvc.exe – (WLSetupSvc)
SRV - [2007/10/18 11:31:54 | 000,098,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\Messenger\usnsvc.exe – (usnjsvc)
SRV - [2005/09/30 19:22:50 | 000,096,341 | —- | M] (Canon Inc.) [Auto | Stopped] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\intelppm.sys – (intelppm)
DRV - [2010/05/31 20:32:58 | 000,385,880 | —- | M] (McAfee, Inc.) [Kernel | Boot | Stopped] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2010/05/31 20:32:58 | 000,312,616 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2010/05/31 20:32:58 | 000,152,320 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2010/05/31 20:32:58 | 000,095,568 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2010/05/31 20:32:58 | 000,088,480 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2010/05/31 20:32:58 | 000,088,480 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2010/05/31 20:32:58 | 000,083,496 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2010/05/31 20:32:58 | 000,082,952 | —- | M] (McAfee, Inc.) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2010/05/31 20:32:58 | 000,055,456 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2010/05/31 20:32:58 | 000,051,688 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2007/08/31 15:20:04 | 000,198,528 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NdisWDM.sys – (NdisWDM)
DRV - [2005/06/07 22:44:36 | 001,235,968 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/04/20 11:00:56 | 002,317,696 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/04/14 21:12:12 | 000,175,616 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ftsata2.sys – (ftsata2)
DRV - [2005/03/09 18:09:18 | 000,870,912 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\iaStor.sys – (iaStor)
DRV - [2005/03/09 14:53:00 | 000,036,352 | —- | M] (Advanced Micro Devices) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2005/03/04 11:10:26 | 000,074,496 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2004/12/15 15:18:32 | 000,220,928 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2004/12/15 15:18:28 | 000,703,232 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/12/15 15:18:26 | 001,038,208 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/08/03 22:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/11/05 15:45:12 | 000,017,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\bb-run.sys – (bb-run)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/06/05 20:16:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{4BDBC82A-F1DF-48EA-B122-2FDFA429D493}: C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\{4BDBC82A-F1DF-48EA-B122-2FDFA429D493} [2010/08/14 12:38:37 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/02/15 16:02:45 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20100715192636.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [jvjexwdv] C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\bbodalndm\mxhlqkdshdw.exe ()
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Xbetoveh] C:\WINDOWS\amaginuk.DLL (Ask.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…irector7/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://zone.msn.com/bingame/chnz/default/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/24 22:32:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/08/19 11:39:09 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/17 11:22:14 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/08/16 21:41:39 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/16 21:41:37 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/16 21:41:36 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/14 13:00:23 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/08/14 12:59:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/08/14 12:40:54 | 000,000,000 | —D | C] – C:\Program Files\AnVi
[2010/06/05 20:17:18 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/06/05 20:17:17 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/06/05 20:08:32 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeclnk.sys
[2010/06/05 20:08:17 | 000,082,952 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2010/06/05 20:08:16 | 000,385,880 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfehidk.sys
[2010/06/05 20:08:16 | 000,312,616 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfefirek.sys
[2010/06/05 20:08:16 | 000,152,320 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeavfk.sys
[2010/06/05 20:08:16 | 000,095,568 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeapfk.sys
[2010/06/05 20:08:16 | 000,088,480 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfendisk.sys
[2010/06/05 20:08:16 | 000,083,496 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mferkdet.sys
[2010/06/05 20:08:16 | 000,055,456 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\cfwids.sys
[2010/06/05 20:08:16 | 000,051,688 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfebopk.sys
[2010/06/05 20:08:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/06/05 20:08:02 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2010/06/05 20:07:32 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2010/06/05 19:52:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2010/06/05 19:44:46 | 000,000,000 | —D | C] – C:\WINDOWS\Internet Logs
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/21 08:53:53 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/21 08:53:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/19 12:00:17 | 000,002,838 | —- | M] () – C:\WINDOWS\amocomeposuce.dll
[2010/08/19 11:58:02 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/19 11:57:50 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/19 11:56:26 | 001,930,896 | -H– | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/08/19 11:25:55 | 000,000,000 | —- | M] () – C:\WINDOWS\Mgavogepuwid.bin
[2010/08/19 11:21:30 | 000,002,838 | —- | M] () – C:\WINDOWS\ahelulineteriw.dll
[2010/08/19 08:25:48 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.scr
[2010/08/19 08:25:04 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.com
[2010/08/19 08:13:22 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.exe
[2010/08/18 21:48:03 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/18 21:46:00 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/08/18 21:41:03 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009UA.job
[2010/08/18 21:39:33 | 000,002,838 | —- | M] () – C:\WINDOWS\arahidonokecikot.dll
[2010/08/18 20:35:47 | 000,002,838 | —- | M] () – C:\WINDOWS\arutovunikan.dll
[2010/08/18 19:32:17 | 000,002,838 | —- | M] () – C:\WINDOWS\uminarohi.dll
[2010/08/18 18:28:34 | 000,002,838 | —- | M] () – C:\WINDOWS\edarubohojafabi.dll
[2010/08/18 17:24:47 | 000,002,838 | —- | M] () – C:\WINDOWS\ahahecehenuhe.dll
[2010/08/18 16:21:01 | 000,002,838 | —- | M] () – C:\WINDOWS\ulaculihiweke.dll
[2010/08/18 15:17:42 | 000,002,838 | —- | M] () – C:\WINDOWS\akihatehi.dll
[2010/08/18 14:41:02 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009Core.job
[2010/08/18 14:13:39 | 000,002,838 | —- | M] () – C:\WINDOWS\iqupogic.dll
[2010/08/18 13:10:45 | 000,002,838 | —- | M] () – C:\WINDOWS\awihobekeyojiy.dll
[2010/08/18 12:06:30 | 000,002,838 | —- | M] () – C:\WINDOWS\elefomohuxewote.dll
[2010/08/18 11:02:47 | 000,002,838 | —- | M] () – C:\WINDOWS\irupawuqewi.dll
[2010/08/18 08:17:40 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/17 15:25:29 | 000,002,838 | —- | M] () – C:\WINDOWS\awetepin.dll
[2010/08/17 14:21:55 | 000,002,838 | —- | M] () – C:\WINDOWS\ulolidupayazada.dll
[2010/08/17 10:52:16 | 000,002,838 | —- | M] () – C:\WINDOWS\urunusijegoh.dll
[2010/08/17 09:50:14 | 000,002,838 | —- | M] () – C:\WINDOWS\akefileyocozofuq.dll
[2010/08/17 08:44:39 | 000,002,838 | —- | M] () – C:\WINDOWS\alomocin.dll
[2010/08/16 21:41:45 | 000,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/14 12:53:52 | 000,002,838 | —- | M] () – C:\WINDOWS\erudeneq.dll
[2010/08/14 12:48:45 | 000,002,838 | —- | M] () – C:\WINDOWS\azejedec.dll
[2010/08/14 12:38:45 | 000,000,120 | —- | M] () – C:\WINDOWS\Uveyunikazub.dat
[2010/07/23 17:34:34 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/07/23 17:34:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/07/21 20:25:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/07/21 20:25:45 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2010/07/20 19:44:34 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2010/07/20 19:44:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/07/16 19:42:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/07/16 19:42:13 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2010/07/13 17:09:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/07/13 17:09:30 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2010/07/12 15:23:47 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2010/07/12 15:23:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/07/10 20:30:34 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2010/07/10 20:30:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/07/08 17:45:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/07/08 17:45:08 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2010/07/06 17:44:57 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2010/07/06 17:44:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/07/03 19:40:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/07/03 19:40:29 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2010/07/02 20:06:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/07/02 20:06:21 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2010/06/30 18:40:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/06/30 18:40:08 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2010/06/29 18:04:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/06/29 18:04:08 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2010/06/28 20:56:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/06/28 20:56:39 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2010/06/28 18:39:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/06/28 18:39:55 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2010/06/27 20:10:25 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2010/06/27 20:10:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/06/26 19:04:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/06/26 19:04:13 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2010/06/26 16:30:18 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/06/26 16:30:17 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/06/23 20:55:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/06/23 20:55:45 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2010/06/22 18:28:26 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2010/06/22 18:28:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/06/05 19:10:01 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/05/31 20:32:58 | 000,385,880 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfehidk.sys
[2010/05/31 20:32:58 | 000,312,616 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfefirek.sys
[2010/05/31 20:32:58 | 000,152,320 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeavfk.sys
[2010/05/31 20:32:58 | 000,095,568 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeapfk.sys
[2010/05/31 20:32:58 | 000,088,480 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfendisk.sys
[2010/05/31 20:32:58 | 000,083,496 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mferkdet.sys
[2010/05/31 20:32:58 | 000,082,952 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2010/05/31 20:32:58 | 000,055,456 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\cfwids.sys
[2010/05/31 20:32:58 | 000,051,688 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfebopk.sys
[2010/05/31 20:32:58 | 000,009,344 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeclnk.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/19 12:00:16 | 000,002,838 | —- | C] () – C:\WINDOWS\amocomeposuce.dll
[2010/08/19 11:39:05 | 000,363,520 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\rkill.exe
[2010/08/19 11:39:02 | 000,363,520 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\rkill.com
[2010/08/19 11:38:57 | 000,363,520 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\rkill.scr
[2010/08/19 11:21:28 | 000,002,838 | —- | C] () – C:\WINDOWS\ahelulineteriw.dll
[2010/08/18 21:39:32 | 000,002,838 | —- | C] () – C:\WINDOWS\arahidonokecikot.dll
[2010/08/18 20:35:47 | 000,002,838 | —- | C] () – C:\WINDOWS\arutovunikan.dll
[2010/08/18 19:32:16 | 000,002,838 | —- | C] () – C:\WINDOWS\uminarohi.dll
[2010/08/18 18:28:33 | 000,002,838 | —- | C] () – C:\WINDOWS\edarubohojafabi.dll
[2010/08/18 17:24:46 | 000,002,838 | —- | C] () – C:\WINDOWS\ahahecehenuhe.dll
[2010/08/18 16:21:01 | 000,002,838 | —- | C] () – C:\WINDOWS\ulaculihiweke.dll
[2010/08/18 15:17:41 | 000,002,838 | —- | C] () – C:\WINDOWS\akihatehi.dll
[2010/08/18 14:13:38 | 000,002,838 | —- | C] () – C:\WINDOWS\iqupogic.dll
[2010/08/18 13:10:41 | 000,002,838 | —- | C] () – C:\WINDOWS\awihobekeyojiy.dll
[2010/08/18 12:06:29 | 000,002,838 | —- | C] () – C:\WINDOWS\elefomohuxewote.dll
[2010/08/18 11:02:47 | 000,002,838 | —- | C] () – C:\WINDOWS\irupawuqewi.dll
[2010/08/17 15:25:29 | 000,002,838 | —- | C] () – C:\WINDOWS\awetepin.dll
[2010/08/17 14:21:55 | 000,002,838 | —- | C] () – C:\WINDOWS\ulolidupayazada.dll
[2010/08/17 10:52:16 | 000,002,838 | —- | C] () – C:\WINDOWS\urunusijegoh.dll
[2010/08/17 09:50:13 | 000,002,838 | —- | C] () – C:\WINDOWS\akefileyocozofuq.dll
[2010/08/17 08:44:35 | 000,002,838 | —- | C] () – C:\WINDOWS\alomocin.dll
[2010/08/16 21:41:45 | 000,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/14 12:53:52 | 000,002,838 | —- | C] () – C:\WINDOWS\erudeneq.dll
[2010/08/14 12:48:43 | 000,002,838 | —- | C] () – C:\WINDOWS\azejedec.dll
[2010/08/14 12:38:45 | 000,000,120 | —- | C] () – C:\WINDOWS\Uveyunikazub.dat
[2010/08/14 12:38:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Mgavogepuwid.bin
[2009/12/13 19:34:30 | 000,000,130 | —- | C] () – C:\WINDOWS\cfplogvw.INI
[2009/10/20 17:47:09 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2008/11/03 19:31:19 | 000,000,022 | —- | C] () – C:\WINDOWS\iexplore.ini
[2008/09/09 18:54:54 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/09/09 18:54:49 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2007/02/11 19:16:56 | 000,000,107 | —- | C] () – C:\WINDOWS\wpd99.drv
[2006/09/03 19:50:04 | 000,007,116 | —- | C] () – C:\WINDOWS\hpdj3740.ini
[2006/09/03 19:48:02 | 000,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2005/08/08 16:27:27 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/08/08 15:55:18 | 000,012,992 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/08/08 15:55:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/08/08 15:48:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/08/08 15:41:35 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/08/08 15:41:35 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/08/08 15:41:35 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/08/08 15:41:35 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/08/08 15:41:35 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/08/08 15:41:35 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/08/08 15:36:06 | 000,000,162 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/08/08 15:30:56 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/08 15:15:38 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/08/08 15:10:53 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/05/09 23:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/08/04 05:00:00 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\devenum(2).dll
[2004/08/04 05:00:00 | 000,014,336 | —- | C] () – C:\WINDOWS\System32\msdmo(2).dll
[2004/06/15 22:38:02 | 000,000,592 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini

========== LOP Check ==========

[2005/08/08 15:54:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SampleView
[2007/12/22 10:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ISPCOMP
[2008/11/03 19:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2007/11/27 22:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Netscape Internet Service
[2007/02/11 19:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2008/09/14 20:32:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/08/18 21:46:00 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/06/24 22:32:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2007/07/25 20:57:22 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2007/07/26 19:29:20 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2004/08/04 05:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/06/24 22:32:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/31 15:08:21 | 000,177,433 | —- | M] () – C:\hpfr3740.log
[2005/06/24 22:32:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/17 17:58:18 | 000,015,059 | —- | M] () – C:\JavaRa.log
[2008/09/17 21:28:28 | 000,000,004 | —- | M] () – C:\KLSA.DAT
[2005/06/24 22:32:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/11 17:35:26 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/21 08:52:45 | 352,321,536 | -HS- | M] () – C:\pagefile.sys
[2010/08/19 11:40:49 | 000,000,385 | —- | M] () – C:\rkill.log
[2009/06/06 23:23:56 | 000,000,000 | —- | M] () – C:\rollback.ini
[2010/07/13 17:09:30 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2010/07/16 19:42:13 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2010/07/20 19:44:34 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2010/07/21 20:25:45 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2010/07/23 17:34:34 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/06/22 18:28:26 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2010/06/23 20:55:45 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2010/06/26 16:30:18 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/06/26 19:04:13 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2010/06/27 20:10:25 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2010/06/28 18:39:55 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2010/06/28 20:56:39 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2010/06/29 18:04:08 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2010/06/30 18:40:08 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2010/07/02 20:06:21 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2010/07/03 19:40:29 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2010/07/06 17:44:57 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2010/07/08 17:45:08 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2010/07/10 20:30:34 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2010/07/12 15:23:47 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2010/07/13 17:09:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/07/16 19:42:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/07/20 19:44:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/07/21 20:25:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/07/23 17:34:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/06/22 18:28:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/06/23 20:55:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/06/26 16:30:17 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/06/26 19:04:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/06/27 20:10:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/06/28 18:39:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/06/28 20:56:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/06/29 18:04:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/06/30 18:40:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/07/02 20:06:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/07/03 19:40:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/07/06 17:44:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/07/08 17:45:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/07/10 20:30:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/07/12 15:23:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/06/07 10:21:28 | 001,358,454 | —- | M] () – C:\wrar39b2.exe

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/06/24 22:31:38 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/02/20 11:09:35 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/02/20 11:09:36 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/06/24 15:25:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/06/24 15:25:14 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/06/24 15:25:14 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2007/03/08 08:36:28 | 000,577,536 | —- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/04 05:00:00 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/04 05:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-09-16 04:50:54
< End of report >
[2010/08/21 09:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Desktop
[2010/08/21 08:58:50 | 000,172,032 | -H– | M] () – C:\Documents and Settings\Administrator\ntuser.dat.LOG
[2010/08/21 08:58:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Recent
[2010/08/21 08:53:53 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/21 08:53:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/19 12:00:17 | 000,002,838 | —- | M] () – C:\WINDOWS\amocomeposuce.dll
[2010/08/19 11:58:02 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/19 11:57:50 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/19 11:56:26 | 001,930,896 | -H– | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/08/19 11:38:13 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Administrator\Cookies
[2010/08/19 11:25:55 | 000,000,000 | —- | M] () – C:\WINDOWS\Mgavogepuwid.bin
[2010/08/19 11:21:30 | 000,002,838 | —- | M] () – C:\WINDOWS\ahelulineteriw.dll
[2010/08/19 08:25:48 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.scr
[2010/08/19 08:25:04 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.com
[2010/08/19 08:13:22 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.exe
[2010/08/18 21:48:03 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/18 21:46:00 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/08/18 21:41:03 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009UA.job
[2010/08/18 21:39:33 | 000,002,838 | —- | M] () – C:\WINDOWS\arahidonokecikot.dll
[2010/08/18 20:35:47 | 000,002,838 | —- | M] () – C:\WINDOWS\arutovunikan.dll
[2010/08/18 19:32:17 | 000,002,838 | —- | M] () – C:\WINDOWS\uminarohi.dll
[2010/08/18 18:28:34 | 000,002,838 | —- | M] () – C:\WINDOWS\edarubohojafabi.dll
[2010/08/18 17:24:47 | 000,002,838 | —- | M] () – C:\WINDOWS\ahahecehenuhe.dll
[2010/08/18 16:21:01 | 000,002,838 | —- | M] () – C:\WINDOWS\ulaculihiweke.dll
[2010/08/18 15:17:42 | 000,002,838 | —- | M] () – C:\WINDOWS\akihatehi.dll
[2010/08/18 14:41:02 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009Core.job
[2010/08/18 14:13:39 | 000,002,838 | —- | M] () – C:\WINDOWS\iqupogic.dll
[2010/08/18 13:10:45 | 000,002,838 | —- | M] () – C:\WINDOWS\awihobekeyojiy.dll
[2010/08/18 12:06:30 | 000,002,838 | —- | M] () – C:\WINDOWS\elefomohuxewote.dll
[2010/08/18 11:02:47 | 000,002,838 | —- | M] () – C:\WINDOWS\irupawuqewi.dll
[2010/08/18 08:17:40 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/17 15:25:29 | 000,002,838 | —- | M] () – C:\WINDOWS\awetepin.dll
[2010/08/17 14:21:55 | 000,002,838 | —- | M] () – C:\WINDOWS\ulolidupayazada.dll
[2010/08/17 10:52:16 | 000,002,838 | —- | M] () – C:\WINDOWS\urunusijegoh.dll
[2010/08/17 09:50:14 | 000,002,838 | —- | M] () – C:\WINDOWS\akefileyocozofuq.dll
[2010/08/17 08:44:39 | 000,002,838 | —- | M] () – C:\WINDOWS\alomocin.dll
[2010/08/16 21:56:25 | 000,000,000 | —D | M] – C:\Program Files\AnVi
[2010/08/16 21:41:47 | 000,000,000 | —D | M] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/16 21:41:45 | 000,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 21:41:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Desktop
[2010/08/14 13:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/08/14 12:59:29 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/08/14 12:53:52 | 000,002,838 | —- | M] () – C:\WINDOWS\erudeneq.dll
[2010/08/14 12:48:45 | 000,002,838 | —- | M] () – C:\WINDOWS\azejedec.dll
[2010/08/14 12:38:45 | 000,000,120 | —- | M] () – C:\WINDOWS\Uveyunikazub.dat
[2010/08/13 18:49:50 | 000,000,000 | —D | M] – C:\Program Files\Common Files\Java
[2010/08/13 18:49:23 | 000,000,000 | —D | M] – C:\Program Files\Java
[2010/07/16 17:40:11 | 000,000,000 | —D | M] – C:\Program Files\McAfee
[2010/06/06 15:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2010/06/05 20:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/06/05 20:17:17 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/06/05 20:09:00 | 000,000,000 | —D | M] – C:\Program Files\Common Files\Mcafee
[2010/06/05 20:08:09 | 000,000,000 | —D | M] – C:\Program Files\Common Files
[2010/06/05 20:08:02 | 000,000,000 | —D | M] – C:\Program Files\McAfee.com
[2010/06/05 19:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data
[2010/06/05 19:41:37 | 000,000,000 | —D | M] – C:\Program Files\Spybot - Search & Destroy
[2010/06/05 19:41:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2005/06/24 15:26:14 | 000,000,062 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\desktop.ini
[2005/06/24 15:26:14 | 000,000,062 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\desktop.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/21 08:53:53 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/21 08:53:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/19 12:00:17 | 000,002,838 | —- | M] () – C:\WINDOWS\amocomeposuce.dll
[2010/08/19 11:58:02 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/19 11:57:50 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/19 11:56:26 | 001,930,896 | -H– | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/08/19 11:25:55 | 000,000,000 | —- | M] () – C:\WINDOWS\Mgavogepuwid.bin
[2010/08/19 11:21:30 | 000,002,838 | —- | M] () – C:\WINDOWS\ahelulineteriw.dll
[2010/08/19 08:25:48 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.scr
[2010/08/19 08:25:04 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.com
[2010/08/19 08:13:22 | 000,363,520 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rkill.exe
[2010/08/18 21:48:03 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/18 21:46:00 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/08/18 21:41:03 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009UA.job
[2010/08/18 21:39:33 | 000,002,838 | —- | M] () – C:\WINDOWS\arahidonokecikot.dll
[2010/08/18 20:35:47 | 000,002,838 | —- | M] () – C:\WINDOWS\arutovunikan.dll
[2010/08/18 19:32:17 | 000,002,838 | —- | M] () – C:\WINDOWS\uminarohi.dll
[2010/08/18 18:28:34 | 000,002,838 | —- | M] () – C:\WINDOWS\edarubohojafabi.dll
[2010/08/18 17:24:47 | 000,002,838 | —- | M] () – C:\WINDOWS\ahahecehenuhe.dll
[2010/08/18 16:21:01 | 000,002,838 | —- | M] () – C:\WINDOWS\ulaculihiweke.dll
[2010/08/18 15:17:42 | 000,002,838 | —- | M] () – C:\WINDOWS\akihatehi.dll
[2010/08/18 14:41:02 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009Core.job
[2010/08/18 14:13:39 | 000,002,838 | —- | M] () – C:\WINDOWS\iqupogic.dll
[2010/08/18 13:10:45 | 000,002,838 | —- | M] () – C:\WINDOWS\awihobekeyojiy.dll
[2010/08/18 12:06:30 | 000,002,838 | —- | M] () – C:\WINDOWS\elefomohuxewote.dll
[2010/08/18 11:02:47 | 000,002,838 | —- | M] () – C:\WINDOWS\irupawuqewi.dll
[2010/08/18 08:17:40 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/17 15:25:29 | 000,002,838 | —- | M] () – C:\WINDOWS\awetepin.dll
[2010/08/17 14:21:55 | 000,002,838 | —- | M] () – C:\WINDOWS\ulolidupayazada.dll
[2010/08/17 10:52:16 | 000,002,838 | —- | M] () – C:\WINDOWS\urunusijegoh.dll
[2010/08/17 09:50:14 | 000,002,838 | —- | M] () – C:\WINDOWS\akefileyocozofuq.dll
[2010/08/17 08:44:39 | 000,002,838 | —- | M] () – C:\WINDOWS\alomocin.dll
[2010/08/16 21:41:45 | 000,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/14 12:53:52 | 000,002,838 | —- | M] () – C:\WINDOWS\erudeneq.dll
[2010/08/14 12:48:45 | 000,002,838 | —- | M] () – C:\WINDOWS\azejedec.dll
[2010/08/14 12:38:45 | 000,000,120 | —- | M] () – C:\WINDOWS\Uveyunikazub.dat
[2010/07/23 17:34:34 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/07/23 17:34:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== LOP Check ==========

[2005/08/08 15:54:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SampleView
[2007/12/22 10:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ISPCOMP
[2008/11/03 19:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2007/11/27 22:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Netscape Internet Service
[2007/02/11 19:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2008/09/14 20:32:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/08/18 21:46:00 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/06/24 22:32:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2007/07/25 20:57:22 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2007/07/26 19:29:20 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2004/08/04 05:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/06/24 22:32:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/31 15:08:21 | 000,177,433 | —- | M] () – C:\hpfr3740.log
[2005/06/24 22:32:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/17 17:58:18 | 000,015,059 | —- | M] () – C:\JavaRa.log
[2008/09/17 21:28:28 | 000,000,004 | —- | M] () – C:\KLSA.DAT
[2005/06/24 22:32:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/11 17:35:26 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/21 08:52:45 | 352,321,536 | -HS- | M] () – C:\pagefile.sys
[2010/08/19 11:40:49 | 000,000,385 | —- | M] () – C:\rkill.log
[2009/06/06 23:23:56 | 000,000,000 | —- | M] () – C:\rollback.ini
[2010/07/13 17:09:30 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2010/07/16 19:42:13 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2010/07/20 19:44:34 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2010/07/21 20:25:45 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2010/07/23 17:34:34 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/06/22 18:28:26 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2010/06/23 20:55:45 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2010/06/26 16:30:18 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/06/26 19:04:13 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2010/06/27 20:10:25 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2010/06/28 18:39:55 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2010/06/28 20:56:39 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2010/06/29 18:04:08 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2010/06/30 18:40:08 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2010/07/02 20:06:21 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2010/07/03 19:40:29 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2010/07/06 17:44:57 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2010/07/08 17:45:08 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2010/07/10 20:30:34 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2010/07/12 15:23:47 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2010/07/13 17:09:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/07/16 19:42:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/07/20 19:44:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/07/21 20:25:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/07/23 17:34:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/06/22 18:28:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/06/23 20:55:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/06/26 16:30:17 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/06/26 19:04:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/06/27 20:10:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/06/28 18:39:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/06/28 20:56:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/06/29 18:04:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/06/30 18:40:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/07/02 20:06:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/07/03 19:40:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/07/06 17:44:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/07/08 17:45:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/07/10 20:30:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/07/12 15:23:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/06/07 10:21:28 | 001,358,454 | —- | M] () – C:\wrar39b2.exe

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/06/24 22:31:38 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/02/20 11:09:35 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/02/20 11:09:36 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/06/24 15:25:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/06/24 15:25:14 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/06/24 15:25:14 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2007/03/08 08:36:28 | 000,577,536 | —- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/04 05:00:00 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/04 05:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-09-16 04:50:54

< End of report >





OTL Extras logfile


OTL Extras logfile created on: 8/21/2010 9:02:45 AM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.00 Mb Total Physical Memory | 274.00 Mb Available Physical Memory | 61.00% Memory free
720.00 Mb Paging File | 604.00 Mb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.02 Gb Total Space | 56.17 Gb Free Space | 82.59% Space Free | Partition Type: NTFS
Drive D: | 6.50 Gb Total Space | 1.44 Gb Free Space | 22.22% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 3.74 Gb Total Space | 0.07 Gb Free Space | 1.84% Space Free | Partition Type: FAT32

Computer Name: YOUR-27E1513D96
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MI1933~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe" = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe:*:Enabled:Compaq Connections – (Hewlett-Packard)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe" = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe:*:Enabled:Compaq Connections – (Hewlett-Packard)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1306C737-0AF4-46C7-B282-64E099304712}" = Smart Menus (Windows Live Toolbar)
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{4998FF95-709A-430A-B104-92A009ABB848}" = QuickConnect
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"{531D27E5-DE21-4777-9EDB-B7803087E7F3}" = Dynex Wireless G USB Network Adapter Setup
"{59932D51-F260-4EF6-A784-4F69659F1A62}" = Map Button (Windows Live Toolbar)
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{71CB529E-21A4-42AD-BF38-564F08988633}" = Windows Live Outlook Toolbar (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec Gateway
"{A63E18AC-B504-4045-AFE6-A279BBABB988}" = Qwest QuickAssist Desktop Tools
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AF5937B6-B68F-4197-8854-5079D5D1CC2B}" = QuickConnect
"{BE9FEFBA-F2F8-468B-A108-4356F73A3E9C}" = Office 2003 Tour
"{C6876FE6-A314-4628-B0D7-F3EE5E35C4B4}" = Windows Live Toolbar
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = Compaq Organize
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DF821FC5-C198-452B-A0D4-82433EFEAE9B}" = OneCare Advisor (Windows Live Toolbar)
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F901CA6D-A074-42D3-A11D-33AAE6FFD0C1}" = HP Deskjet 3740
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Display Driver" = ATI Display Driver
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Data Fax SoftModem with SmartCP
"CSCLIB" = Canon Camera Support Core Library
"getPlus®_ocx" = getPlus®_ocx
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Deskjet 3740 Series_Driver" = HP Deskjet 3740 Series
"HPOOVClient-5577497 Uninstaller" = Compaq Connections (remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Money2005b" = Microsoft Money 2005
"MSC" = McAfee AntiVirus Plus
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"QuickTime" = QuickTime
"QwestQuickCare_is1" = Qwest QuickCare 2.2
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"WIC" = Windows Imaging Component
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/21/2010 11:57:54 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:54 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:54 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:54 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:54 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:55 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:55 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:55 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 8/21/2010 11:57:58 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 8/21/2010 11:57:58 AM | Computer Name = YOUR-27E1513D96 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 8/21/2010 11:56:26 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 8/21/2010 11:56:26 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 8/21/2010 11:56:26 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 8/21/2010 11:56:26 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 8/21/2010 11:56:26 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 8/21/2010 11:56:26 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 8/21/2010 11:56:26 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 8/21/2010 11:57:05 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 8/21/2010 11:58:18 AM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 8/21/2010 12:04:40 PM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}


< End of report >
Hi 111mike,

Please do this scan in safemode as well and post the log here, we need to make sure nothing is trying to hide from us.


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
2010/08/23 13:54:34.0843 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23 2010/08/23 13:54:34.0843 ================================================================================ 2010/08/23 13:54:34.0843 SystemInfo: 2010/08/23 13:54:34.0843 2010/08/23 13:54:34.0843 OS Version: 5.1.2600 ServicePack: 2.0 2010/08/23 13:54:34.0906 Product type: Workstation 2010/08/23 13:54:34.0906 ComputerName: YOUR-27E1513D96 2010/08/23 13:54:34.0906 UserName: Compaq_Owner 2010/08/23 13:54:34.0906 Windows directory: C:\WINDOWS 2010/08/23 13:54:34.0906 System windows directory: C:\WINDOWS 2010/08/23 13:54:34.0906 Processor architecture: Intel x86 2010/08/23 13:54:34.0906 Number of processors: 1 2010/08/23 13:54:34.0906 Page size: 0x1000 2010/08/23 13:54:34.0906 Boot type: Normal boot 2010/08/23 13:54:34.0906 ================================================================================ 2010/08/23 13:54:37.0515 Initialize success 2010/08/23 13:54:40.0296 ================================================================================ 2010/08/23 13:54:40.0296 Scan started 2010/08/23 13:54:40.0296 Mode: Manual; 2010/08/23 13:54:40.0296 ================================================================================ 2010/08/23 13:54:42.0781 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2010/08/23 13:54:43.0078 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2010/08/23 13:54:43.0625 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 2010/08/23 13:54:43.0968 AFD (944ca435bfcfc82cc1ed9e3a7d731aa9) C:\WINDOWS\System32\drivers\afd.sys 2010/08/23 13:54:45.0515 ALCXWDM (781c5ec517c53f5214b61253b20c13c4) C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2010/08/23 13:54:46.0656 AmdK8 (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 2010/08/23 13:54:47.0781 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2010/08/23 13:54:49.0078 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2010/08/23 13:54:49.0484 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2010/08/23 13:54:50.0484 ati2mtag (b33a281dcdf455b069816790275050a7) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2010/08/23 13:54:51.0125 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2010/08/23 13:54:51.0625 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2010/08/23 13:54:52.0062 bb-run (7270d070173b20ac9487ea16bb08b45f) C:\WINDOWS\system32\DRIVERS\bb-run.sys 2010/08/23 13:54:52.0546 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2010/08/23 13:54:53.0109 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2010/08/23 13:54:53.0843 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2010/08/23 13:54:54.0359 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2010/08/23 13:54:54.0750 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2010/08/23 13:54:55.0109 cfwids (44e4a7dded054dd55ae995c3aed719ae) C:\WINDOWS\system32\drivers\cfwids.sys 2010/08/23 13:54:57.0781 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2010/08/23 13:54:59.0093 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 2010/08/23 13:55:00.0046 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 2010/08/23 13:55:00.0562 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2010/08/23 13:55:01.0531 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2010/08/23 13:55:02.0546 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2010/08/23 13:55:03.0296 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2010/08/23 13:55:03.0656 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 2010/08/23 13:55:03.0968 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 2010/08/23 13:55:04.0265 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 2010/08/23 13:55:04.0593 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2010/08/23 13:55:05.0078 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2010/08/23 13:55:05.0375 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2010/08/23 13:55:05.0671 ftsata2 (92e8443c7bf5c0137671cde080655dfc) C:\WINDOWS\system32\DRIVERS\ftsata2.sys 2010/08/23 13:55:06.0250 GEARAspiWDM (6f55305289a0765bd8ae8e8d32f17117) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 2010/08/23 13:55:06.0640 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2010/08/23 13:55:07.0140 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2010/08/23 13:55:07.0937 HSFHWBS2 (5df616addb75c1ad36c1f9e4de0f7654) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 2010/08/23 13:55:08.0437 HSF_DP (dfa8f86c0dbca7db948043aa3be6793b) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 2010/08/23 13:55:08.0937 HTTP (cb77bb47e67e84deb17ba29632501730) C:\WINDOWS\system32\Drivers\HTTP.sys 2010/08/23 13:55:09.0734 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2010/08/23 13:55:10.0046 iaStor (79ae2a97c120f282845d854d0f070ea9) C:\WINDOWS\system32\DRIVERS\iaStor.sys 2010/08/23 13:55:10.0562 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2010/08/23 13:55:11.0125 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 2010/08/23 13:55:11.0656 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys 2010/08/23 13:55:11.0937 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2010/08/23 13:55:12.0218 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2010/08/23 13:55:12.0500 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2010/08/23 13:55:12.0781 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2010/08/23 13:55:13.0078 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2010/08/23 13:55:13.0390 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2010/08/23 13:55:13.0687 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2010/08/23 13:55:14.0015 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2010/08/23 13:55:14.0343 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 2010/08/23 13:55:14.0625 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys 2010/08/23 13:55:15.0296 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 2010/08/23 13:55:15.0578 mfeapfk (b77e959e1c50d3e3a9d9ef423be62e09) C:\WINDOWS\system32\drivers\mfeapfk.sys 2010/08/23 13:55:16.0046 mfeavfk (e84596fcb591117f5597498a5f82ad97) C:\WINDOWS\system32\drivers\mfeavfk.sys 2010/08/23 13:55:16.0671 mfebopk (d40ce01e2d3fe0c079cd2d6b3e4b823b) C:\WINDOWS\system32\drivers\mfebopk.sys 2010/08/23 13:55:17.0109 mfefirek (3962c6a9e35c4319dcdab0497614fd69) C:\WINDOWS\system32\drivers\mfefirek.sys 2010/08/23 13:55:17.0500 mfehidk (e7ecf7872bf8f2897ae5a696d908c2f7) C:\WINDOWS\system32\drivers\mfehidk.sys 2010/08/23 13:55:17.0984 mfendisk (554dbbdc8c3b4f380b21269239bd29bb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys 2010/08/23 13:55:18.0156 mfendiskmp (554dbbdc8c3b4f380b21269239bd29bb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys 2010/08/23 13:55:18.0421 mferkdet (e411594ac94baef7f8ea991cc8f47fd1) C:\WINDOWS\system32\drivers\mferkdet.sys 2010/08/23 13:55:18.0765 mfetdi2k (1bfe4c4ccf8cd2d7deaffb424e691196) C:\WINDOWS\system32\drivers\mfetdi2k.sys 2010/08/23 13:55:19.0250 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2010/08/23 13:55:19.0531 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 2010/08/23 13:55:19.0812 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2010/08/23 13:55:20.0109 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2010/08/23 13:55:20.0562 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2010/08/23 13:55:21.0125 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2010/08/23 13:55:21.0468 MRxSmb (025af03ce51645c62f3b6907a7e2be5e) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2010/08/23 13:55:21.0968 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2010/08/23 13:55:22.0406 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2010/08/23 13:55:22.0812 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2010/08/23 13:55:23.0125 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2010/08/23 13:55:23.0406 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2010/08/23 13:55:23.0671 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2010/08/23 13:55:24.0015 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2010/08/23 13:55:24.0343 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2010/08/23 13:55:24.0640 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2010/08/23 13:55:24.0953 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2010/08/23 13:55:25.0234 NdisWDM (4805067d3ab326931caff6c71550f124) C:\WINDOWS\system32\DRIVERS\ndiswdm.sys 2010/08/23 13:55:25.0750 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2010/08/23 13:55:26.0046 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2010/08/23 13:55:26.0390 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2010/08/23 13:55:26.0734 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2010/08/23 13:55:27.0046 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2010/08/23 13:55:27.0390 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 2010/08/23 13:55:27.0718 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2010/08/23 13:55:28.0046 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2010/08/23 13:55:28.0296 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2010/08/23 13:55:28.0578 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2010/08/23 13:55:28.0890 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 2010/08/23 13:55:29.0187 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2010/08/23 13:55:29.0484 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2010/08/23 13:55:29.0750 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 2010/08/23 13:55:30.0281 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2010/08/23 13:55:30.0562 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 2010/08/23 13:55:32.0375 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2010/08/23 13:55:32.0828 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys 2010/08/23 13:55:33.0250 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2010/08/23 13:55:33.0656 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2010/08/23 13:55:35.0859 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2010/08/23 13:55:36.0437 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2010/08/23 13:55:37.0000 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2010/08/23 13:55:37.0468 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2010/08/23 13:55:37.0828 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2010/08/23 13:55:38.0218 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2010/08/23 13:55:38.0656 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 2010/08/23 13:55:39.0109 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/08/23 13:55:39.0656 RTL8023xp (7f0413bdd7d53eb4c7a371e7f6f84df1) C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys 2010/08/23 13:55:40.0359 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 2010/08/23 13:55:40.0859 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2010/08/23 13:55:41.0750 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\drivers\Serial.sys 2010/08/23 13:55:42.0281 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2010/08/23 13:55:43.0078 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 2010/08/23 13:55:43.0390 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 2010/08/23 13:55:43.0687 Srv (ea554a3ffc3f536fe8320eb38f5e4843) C:\WINDOWS\system32\DRIVERS\srv.sys 2010/08/23 13:55:44.0062 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2010/08/23 13:55:44.0375 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2010/08/23 13:55:45.0671 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2010/08/23 13:55:46.0343 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2010/08/23 13:55:46.0921 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2010/08/23 13:55:47.0171 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2010/08/23 13:55:47.0453 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2010/08/23 13:55:48.0031 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2010/08/23 13:55:48.0531 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 2010/08/23 13:55:48.0875 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2010/08/23 13:55:49.0140 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2010/08/23 13:55:49.0453 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2010/08/23 13:55:49.0718 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys 2010/08/23 13:55:50.0015 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2010/08/23 13:55:50.0328 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2010/08/23 13:55:50.0609 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2010/08/23 13:55:50.0906 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2010/08/23 13:55:51.0171 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2010/08/23 13:55:51.0468 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 2010/08/23 13:55:51.0750 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 2010/08/23 13:55:52.0093 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2010/08/23 13:55:52.0625 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 2010/08/23 13:55:52.0984 winachsf (473ee64c368ce2eed110376c11960259) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 2010/08/23 13:55:53.0546 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2010/08/23 13:55:53.0796 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2010/08/23 13:55:53.0906 ================================================================================ 2010/08/23 13:55:53.0906 Scan finished 2010/08/23 13:55:53.0906 ================================================================================
Hi 111mike,


Please read through these instructions to familarize yourself with what to expect when this tool runs.


Please download Combofix in SafeMode with networking, then reboot into SafeMode and run Combofix.


Please note: Should combofix reboot your computer, allow it to happen. Upon restart reboot back into safe mode. Let combofix finish. Once a log is produced please save it and reboot the computer into normal windows and post the log.



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here you go, Forgot to disable firewall the first time so I ran it again. Here are both logs Some of the fake alerts and porn icons no longer appear, but still can't access Internet, task manager.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI