This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect plus new ad tabs

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Step 1: My infection has 2 manifestations.

First, most of the time (but not all the time), my google results take me to ad sites. It appears that the sites I'm redirected to seem to be an intelligent redirect. It seems to be passing my google search words and then the ad site seems relevant.

Second, the other thing that has been happening is that I occasionally get random new tabs opening up in Firefox with ad sites. Sometimes these are caught by ad-aware or Avast antivirus as malicious, but sometimes not.

I tried your forums self-help for Google redirect but still have the problem.

I'm running Windows XP and use Firefox 3.5.11 as my browser.

Step 2: Logs from Gooredfix, TDSSKiller, and Hijackthis:

GooredFix.txt:
GooredFix by jpshortstuff (03.07.10.1)
Log created at 08:29 on 21/08/2010 (Owner)
Firefox version 3.5.11 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [18:55 03/06/2009]

C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\
[removed] [15:40 07/01/2010]
[removed] [17:36 06/06/2009]
[removed] [15:49 16/01/2010]
{07b2a769-ed19-4483-87ce-c643914c81bb} [14:20 28/05/2010]
{20a82645-c095-46ed-80e3-08825760534b} [22:44 26/05/2010]
{285da7e0-729d-11db-9fe1-0800200c9a66} [16:25 05/12/2009]
{55ab03e0-4736-11dd-ae16-0800200c9a66} [10:56 18/08/2010]
{77b819fa-95ad-4f2c-ac7c-486b356188a9} [16:09 18/06/2009]
{8ea9957e-2953-402f-80e0-bceb5f169d6f} [11:59 22/04/2010]
{a51fc040-e0ca-11dd-ad8b-0800200c9a66} [19:02 04/06/2009]
{c4dc572a-3295-40eb-b30f-b54aa4cdc4b7} [19:58 15/08/2010]
{dc572301-7619-498c-a57d-39143191b318} [13:46 17/06/2010]
{e2c58150-9d72-11dd-ad8b-0800200c9a66} [12:44 17/11/2009]
{f035aa18-ee32-4e6e-81d2-57e32867f8a7} [11:59 22/04/2010]
{feee3d1c-da92-4c21-8665-2425de7f53b7} [14:25 17/09/2009]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
(none)

-=E.O.F=-

TDSSKiller log:
2010/08/21 09:26:20.0046 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23
2010/08/21 09:26:20.0046 ================================================================================
2010/08/21 09:26:20.0046 SystemInfo:
2010/08/21 09:26:20.0046
2010/08/21 09:26:20.0046 OS Version: 5.1.2600 ServicePack: 3.0
2010/08/21 09:26:20.0046 Product type: Workstation
2010/08/21 09:26:20.0046 ComputerName: BARBORFAMILY
2010/08/21 09:26:20.0046 UserName: Owner
2010/08/21 09:26:20.0046 Windows directory: C:\WINDOWS
2010/08/21 09:26:20.0046 System windows directory: C:\WINDOWS
2010/08/21 09:26:20.0046 Processor architecture: Intel x86
2010/08/21 09:26:20.0046 Number of processors: 1
2010/08/21 09:26:20.0046 Page size: 0x1000
2010/08/21 09:26:20.0046 Boot type: Normal boot
2010/08/21 09:26:20.0046 ================================================================================
2010/08/21 09:26:20.0328 Initialize success
2010/08/21 09:26:39.0890 ================================================================================
2010/08/21 09:26:39.0890 Scan started
2010/08/21 09:26:39.0890 Mode: Manual;
2010/08/21 09:26:39.0890 ================================================================================
2010/08/21 09:26:40.0468 Aavmker4 (467f062f76e07512ecc1f5f60aab2988) C:\WINDOWS\system32\drivers\Aavmker4.sys
2010/08/21 09:26:40.0671 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/08/21 09:26:40.0781 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/08/21 09:26:40.0953 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
2010/08/21 09:26:41.0046 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/08/21 09:26:41.0125 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys
2010/08/21 09:26:41.0218 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2010/08/21 09:26:41.0796 ASPI (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\System32\DRIVERS\ASPI32.sys
2010/08/21 09:26:41.0906 aswFsBlk (0c0b08847f2f24baa7bd43d8f2c6c8b0) C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010/08/21 09:26:41.0968 aswMon2 (aa504fa592c9ed79174cb06b8ae340aa) C:\WINDOWS\system32\drivers\aswMon2.sys
2010/08/21 09:26:42.0015 aswRdr (f385ffd39165453fda96736aa3edfd9d) C:\WINDOWS\system32\drivers\aswRdr.sys
2010/08/21 09:26:42.0109 aswSP (45adea26bf613a54fed64ecdd12e58a7) C:\WINDOWS\system32\drivers\aswSP.sys
2010/08/21 09:26:42.0203 aswTdi (c4ee975c87176f1900662d2874233c7f) C:\WINDOWS\system32\drivers\aswTdi.sys
2010/08/21 09:26:42.0296 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/08/21 09:26:42.0390 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/08/21 09:26:42.0515 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/08/21 09:26:42.0609 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/08/21 09:26:42.0703 BANTExt (5d7be7b19e827125e016325334e58ff1) C:\WINDOWS\System32\Drivers\BANTExt.sys
2010/08/21 09:26:42.0781 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/08/21 09:26:42.0906 bvrp_pci (c915a416f265149471d74e0815c928b2) C:\WINDOWS\System32\drivers\bvrp_pci.sys
2010/08/21 09:26:43.0031 Cap713x (f13622ebb20258898f48e56edd4ce660) C:\WINDOWS\system32\DRIVERS\Cap713x.sys
2010/08/21 09:26:43.0125 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/08/21 09:26:43.0250 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/08/21 09:26:43.0421 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/08/21 09:26:43.0500 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/08/21 09:26:43.0578 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/08/21 09:26:44.0046 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/08/21 09:26:44.0171 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2010/08/21 09:26:44.0296 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2010/08/21 09:26:44.0390 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/08/21 09:26:44.0484 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/08/21 09:26:44.0625 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/08/21 09:26:44.0765 E100B (d57a8fc800b501ac05b10d00f66d127a) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2010/08/21 09:26:44.0921 exFat (3ef58f2eae3aecab45d682152db2f67d) C:\WINDOWS\system32\drivers\exFat.sys
2010/08/21 09:26:45.0000 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/08/21 09:26:45.0062 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2010/08/21 09:26:45.0140 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2010/08/21 09:26:45.0203 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2010/08/21 09:26:45.0296 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/08/21 09:26:45.0406 Fs_Rec (c865b83411d7347627a4beec22543fb1) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/08/21 09:26:45.0484 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/08/21 09:26:45.0562 GearAspiWDM (32a73a8952580b284a47290adb62032a) C:\WINDOWS\system32\drivers\GearAspiWDM.sys
2010/08/21 09:26:45.0656 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/08/21 09:26:45.0734 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/08/21 09:26:45.0890 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
2010/08/21 09:26:46.0031 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
2010/08/21 09:26:46.0171 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/08/21 09:26:46.0375 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/08/21 09:26:46.0484 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
2010/08/21 09:26:46.0656 IKFileSec (bb07262041a213fea5fccf0a9f90d85a) C:\WINDOWS\system32\drivers\ikfilesec.sys
2010/08/21 09:26:46.0703 IKSysFlt (b2581314d54f8de4262f0a51f7ba63d0) C:\WINDOWS\system32\drivers\iksysflt.sys
2010/08/21 09:26:46.0765 IKSysSec (6f544cd764f949170b46a4dab11673e2) C:\WINDOWS\system32\drivers\iksyssec.sys
2010/08/21 09:26:46.0875 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/08/21 09:26:47.0093 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/08/21 09:26:47.0203 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/08/21 09:26:47.0281 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/08/21 09:26:47.0375 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/08/21 09:26:47.0437 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/08/21 09:26:47.0515 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/08/21 09:26:47.0609 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/08/21 09:26:47.0687 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/08/21 09:26:47.0765 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/08/21 09:26:47.0890 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/08/21 09:26:47.0984 KSecDD (c6ebf1d6ad71df30db49b8d3287e1368) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/08/21 09:26:48.0125 Lavasoft Kernexplorer (32da3fde01f1bb080c2e69521dd8881e) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2010/08/21 09:26:48.0203 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
2010/08/21 09:26:48.0390 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2010/08/21 09:26:48.0484 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/08/21 09:26:48.0593 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2010/08/21 09:26:48.0656 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
2010/08/21 09:26:48.0734 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/08/21 09:26:48.0828 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/08/21 09:26:48.0921 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/08/21 09:26:49.0062 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/08/21 09:26:49.0140 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/08/21 09:26:49.0265 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/08/21 09:26:49.0343 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/08/21 09:26:49.0406 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/08/21 09:26:49.0453 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/08/21 09:26:49.0531 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/08/21 09:26:49.0593 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/08/21 09:26:49.0671 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/08/21 09:26:49.0734 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/08/21 09:26:49.0812 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/08/21 09:26:49.0906 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/08/21 09:26:50.0093 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/08/21 09:26:50.0156 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/08/21 09:26:50.0218 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/08/21 09:26:50.0296 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/08/21 09:26:50.0375 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/08/21 09:26:50.0468 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/08/21 09:26:50.0656 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/08/21 09:26:50.0890 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/08/21 09:26:51.0000 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/08/21 09:26:51.0187 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2010/08/21 09:26:51.0343 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/08/21 09:26:51.0437 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/08/21 09:26:51.0531 OMCI (cec7e2c6c1fa00c7ab2f5434f848ae51) C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
2010/08/21 09:26:51.0656 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2010/08/21 09:26:51.0734 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/08/21 09:26:51.0812 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/08/21 09:26:51.0890 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/08/21 09:26:52.0015 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2010/08/21 09:26:52.0109 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2010/08/21 09:26:52.0296 PdiPorts (3b2f443b8e23d17d46f0e43e2fc42cfe) C:\WINDOWS\system32\Drivers\PdiPorts.sys
2010/08/21 09:26:52.0625 Pivot (943f840611d33832308ec5310b616b57) C:\WINDOWS\system32\drivers\pivot.sys
2010/08/21 09:26:52.0718 pivotmou (998c58295288eedfbfe95e7f6cc94df4) C:\WINDOWS\system32\drivers\pivotmou.sys
2010/08/21 09:26:52.0796 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/08/21 09:26:52.0890 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
2010/08/21 09:26:52.0968 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/08/21 09:26:53.0031 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/08/21 09:26:53.0109 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2010/08/21 09:26:53.0500 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/08/21 09:26:53.0578 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/08/21 09:26:53.0640 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/08/21 09:26:53.0703 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/08/21 09:26:53.0796 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/08/21 09:26:53.0906 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/08/21 09:26:54.0000 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/08/21 09:26:54.0093 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/08/21 09:26:54.0265 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/08/21 09:26:54.0343 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/08/21 09:26:54.0437 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2010/08/21 09:26:54.0531 sermouse (1f16931c722c69e4a7866244796c66a0) C:\WINDOWS\system32\DRIVERS\sermouse.sys
2010/08/21 09:26:54.0640 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/08/21 09:26:54.0781 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/08/21 09:26:54.0890 SMALUSB (cb2cdd9099c09da1b9de84f553bf1dc0) C:\WINDOWS\system32\DRIVERS\smallogi.sys
2010/08/21 09:26:54.0984 smwdm (5018a9db5eb62e3edb3110f82f556285) C:\WINDOWS\system32\drivers\smwdm.sys
2010/08/21 09:26:55.0109 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/08/21 09:26:55.0203 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/08/21 09:26:55.0312 Srv (da852e3e0bf1cea75d756f9866241e57) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/08/21 09:26:55.0437 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
2010/08/21 09:26:55.0531 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/08/21 09:26:55.0609 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/08/21 09:26:55.0671 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/08/21 09:26:55.0906 symlcbrd (5220576ee29bea7c18dff9ecabf18bbc) C:\WINDOWS\system32\drivers\symlcbrd.sys
2010/08/21 09:26:56.0000 SymSnap (fea2d66aeb341e11fad6ff2d50b8ca40) C:\WINDOWS\system32\drivers\SymSnap.sys
2010/08/21 09:26:56.0171 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/08/21 09:26:56.0265 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/08/21 09:26:56.0375 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/08/21 09:26:56.0468 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/08/21 09:26:56.0562 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/08/21 09:26:56.0718 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/08/21 09:26:56.0906 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/08/21 09:26:57.0031 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/08/21 09:26:57.0109 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/08/21 09:26:57.0171 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/08/21 09:26:57.0234 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/08/21 09:26:57.0296 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/08/21 09:26:57.0359 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/08/21 09:26:57.0437 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/08/21 09:26:57.0531 V2IMount (deea641cc5f87867759856a52cbc0999) C:\WINDOWS\system32\drivers\V2IMount.sys
2010/08/21 09:26:57.0625 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/08/21 09:26:57.0750 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/08/21 09:26:57.0890 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/08/21 09:26:58.0015 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/08/21 09:26:58.0140 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2010/08/21 09:26:58.0328 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2010/08/21 09:26:58.0406 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/08/21 09:26:58.0515 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/08/21 09:26:58.0593 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/08/21 09:26:58.0718 {6080A529-897E-4629-A488-ABA0C29B635E} (fd1f4e9cf06c71c8d73a24acf18d8296) C:\WINDOWS\system32\drivers\ialmsbw.sys
2010/08/21 09:26:58.0812 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (d4d7331d33d1fa73e588e5ce0d90a4c1) C:\WINDOWS\system32\drivers\ialmkchw.sys
2010/08/21 09:26:58.0843 ================================================================================
2010/08/21 09:26:58.0843 Scan finished
2010/08/21 09:26:58.0843 ================================================================================


Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:34:13, on 8/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe
C:\Program Files\John's Background Switcher\BackgroundSwitcher.exe
C:\Program Files\RoboForm\RoboTaskBarIcon.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Spamihilator\spamihilator.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.barborsoftware.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboForm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboForm.dll
O4 - HKCU\..\Run: [BackgroundSwitcher] "C:\Program Files\John's Background Switcher\BackgroundSwitcher.exe"
O4 - HKCU\..\Run: [DesktopIconToy] C:\Program Files\Desktop Icon Toy\DesktopIconToy.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Bible Blips.lnk = C:\Program Files\BBlips\Bblips.exe
O4 - Startup: OccasionReminder.lnk = C:\Program Files\OccasionReminder\OccasionReminder.exe
O4 - Startup: Spamihilator.lnk = C:\Program Files\Spamihilator\spamihilator.exe
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Save Forms - file://C:\Program Files\RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\VideoGet\Plugins\VideoGet_IE.dll
O9 - Extra 'Tools' menuitem: Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\VideoGet\Plugins\VideoGet_IE.dll
O9 - Extra button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Freedom Bar - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Freedom Bar\Freedom Bar.exe
O9 - Extra 'Tools' menuitem: Freedom Bar 8.6-GDI+ - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Freedom Bar\Freedom Bar.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1A05E15-1590-4EBF-9E2F-E541656CB472}: Domain = cavtel.net
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)

–
End of file - 9012 bytes
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________

Lets see if a router reset fixes the redirect issues:

Router Reset
  • Please read this: Malware Silently Alters Wireless Router Settings

  • Consult this link to find out what is the default username and password of your router and note down them: Route Passwords

  • Then rest your router to it's factory default settings:

    "If your machine has been infected by one of these Zlob/DNSchanger Trojans, and your router settings have been altered, I would strongly recommend that you reset the router to its default configuration. Usually, this can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds)"


  • This is the difficult part.
    First get to the routers server. To do that type http:\\192.168.1.1 in the address bar and click Enter. You get the log in window.
    Fill in the password you have already found and you will get the configuration page.
    Configure the router to allow you to connect to your ISP server. In some routers it is done by a setup wizard. But you have to fill in the log in password your ISP has initially given to you.
    You can also call your ISP if you don't have your initial password.
    Don't forget to change the routers default password and set a strong password. Note down the password and keep it somewhere for future reference.

  • Please make sure of the following settings:
  • Go to Start -> Control Panel -> Double click on Network Connections.
  • Right click on your default connection (usually Local Area Connection or Wireless Network Connection) and select Properties.
  • Select the General tab.
  • Double click on Internet Protocol (TCP/IP).
  • Under General tab:
  • Select "Obtain an IP address automatically".
  • Select "Obtain DNS server address automatically".
[*]Click OK twice to save the settings.

[*]Reboot if you had to change any setting.



NEXT:



Flush the DNS cache
  • Click the Start logo in the bottom left corner of the screen
  • Click on Run
  • In the command window copy/paste the following
ipconfig /flushdns
  • then hit enter
  • Exit the command window.

After that, Reboot


If the redirects are still occurring do the following:


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    ipconfig /flushdns /c

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:




Scanning with GMER

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

Notes:
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.
Thanks for getting back to me so quickly. I have one other piece of info that I have discovered since my first post. The redirect of search engine results happens with more than just Google. I have had bing.com and the search at iwon.com also redirect to ad sites. Also, it happens in both Firefox and IE. 1) Now, the first step was to reset my router. My son and I set up this home network and are pretty familiar with the settings. So, we logged into it and everything was set to what it should be. Also, we have 2 wired and 2 wireless computers on this router and only this 1 PC is affected by this malware. And, the article that you linked to about this subject states, "Sunbelt also found that if there are multiple machines using the same router, all of the systems connected to that router will have their traffic hijacked." Since none of the other PC's are having their traffic hijacked, we felt safe to bypass that step. 2) The Network Connections settings were already set as you requested. 3) I performed the flush of the DNS cache and rebooted. The problem still existed. 4) and 5) These last 2 steps involve pasting in of log files, so I'll post them each in a separate reply.
4) I did the OTL step next. The output logs are below:

OTL.txt:

OTL logfile created on: 8/21/2010 5:00:52 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 458.00 Mb Available Physical Memory | 45.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2028 2028 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.75 Gb Total Space | 23.36 Gb Free Space | 20.90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 15.58 Mb Total Space | 15.25 Mb Free Space | 97.87% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BARBORFAMILY
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\John's Background Switcher\BackgroundSwitcher.exe (johnsadventures.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe (Auslogics)
PRC - C:\Program Files\RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Spamihilator\spamihilator.exe (Michel Krämer)
PRC - C:\Program Files\Desktop Icon Toy\DesktopIconToy.exe (iDeskSoft)
PRC - C:\Program Files\WordWeb\wweb32.exe (Antony Lewis)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\WINDOWS\system32\PSIService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (DfSdkS) – C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe (mst software GmbH, Germany)
SRV - (PdiService) – C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (ABBYY.Licensing.FineReader.Sprint.9.0) – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
SRV - (CSHelper) – C:\WINDOWS\system32\CSHelper.exe ()
SRV - (NovosoftBackupNetworkCoordinator) – C:\Program Files\ADrive Backup\BackupNetworkCoordinator.exe ()
SRV - (DTSRVC) – C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (NMSAccessU) – C:\Program Files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe ()
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (Norton Ghost) – C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)
SRV - (Diskeeper) – C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (nsak) – C:\DOCUME~1\Owner\LOCALS~1\Temp\00000081.nmc\nse\bin\nsak.sys File not found
DRV - (NDISKIO) – C:\DOCUME~1\Owner\LOCALS~1\Temp\00000dc5.nmc\nse\bin\ndiskio.sys File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (PdiPorts) – C:\WINDOWS\system32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (IKSysSec) – C:\WINDOWS\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)
DRV - (IKSysFlt) – C:\WINDOWS\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)
DRV - (IKFileSec) – C:\WINDOWS\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)
DRV - (Pivot) – C:\WINDOWS\system32\drivers\pivot.sys (Portrait Displays, Inc.)
DRV - (pivotmou) – C:\WINDOWS\system32\drivers\pivotmou.sys (Portrait Displays, Inc.)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (Cap713x) – C:\WINDOWS\system32\drivers\Cap713x.sys (Philips Semiconductors GmbH)
DRV - (SymSnap) – C:\WINDOWS\System32\drivers\SymSnap.sys (StorageCraft)
DRV - (V2IMount) – C:\WINDOWS\System32\drivers\V2iMount.sys (Symantec Corporation)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (bvrp_pci) – C:\WINDOWS\system32\drivers\bvrp_pci.sys ()
DRV - (SMALUSB) – C:\WINDOWS\system32\drivers\smallogi.sys (SMaL Camera Technologies, Inc.)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.barborsoftware.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://home.barborsoftware.com/"
FF - prefs.js..extensions.enabledItems: {f035aa18-ee32-4e6e-81d2-57e32867f8a7}:1.17
FF - prefs.js..extensions.enabledItems: {feee3d1c-da92-4c21-8665-2425de7f53b7}:1.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0.20091221
FF - prefs.js..extensions.enabledItems: [removed]:1.2.1
FF - prefs.js..extensions.enabledItems: {55ab03e0-4736-11dd-ae16-0800200c9a66}:1.0.8
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}:0.7.25
FF - prefs.js..extensions.enabledItems: {8ea9957e-2953-402f-80e0-bceb5f169d6f}:0.5.3
FF - prefs.js..extensions.enabledItems: {e2c58150-9d72-11dd-ad8b-0800200c9a66}:1.3.1
FF - prefs.js..extensions.enabledItems: {285da7e0-729d-11db-9fe1-0800200c9a66}:2.20091201
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/16 19:31:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/20 09:21:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 1.1.14\Extensions\\Components: C:\Program Files\mozilla.org\SeaMonkey\Components [2010/04/15 07:35:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 1.1.14\Extensions\\Plugins: C:\Program Files\mozilla.org\SeaMonkey\Plugins [2010/08/20 09:21:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.6\extensions\\Components: C:\Program Files\SeaMonkey\components [2010/08/04 13:37:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.6\extensions\\Plugins: C:\Program Files\SeaMonkey\plugins [2010/08/20 09:21:35 | 000,000,000 | —D | M]

[2010/01/20 12:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/01/20 12:59:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2010/08/20 21:43:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions
[2010/05/28 10:20:20 | 000,000,000 | —D | M] (Vista-aero) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
[2010/05/26 18:44:24 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/05 12:25:41 | 000,000,000 | —D | M] (Tinseltown) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{285da7e0-729d-11db-9fe1-0800200c9a66}
[2010/08/18 06:56:36 | 000,000,000 | —D | M] (Tab Focus) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{55ab03e0-4736-11dd-ae16-0800200c9a66}
[2009/06/18 12:09:53 | 000,000,000 | —D | M] (IE Tab) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2010/04/22 07:59:18 | 000,000,000 | —D | M] (XHTML Mobile Profile) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{8ea9957e-2953-402f-80e0-bceb5f169d6f}
[2009/06/04 15:02:43 | 000,000,000 | —D | M] (White bluePC) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{a51fc040-e0ca-11dd-ad8b-0800200c9a66}
[2010/08/15 15:58:37 | 000,000,000 | —D | M] (wmlbrowser) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}
[2010/06/17 09:46:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009/11/17 08:44:50 | 000,000,000 | —D | M] (Black Steel) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{e2c58150-9d72-11dd-ad8b-0800200c9a66}
[2010/04/22 07:59:20 | 000,000,000 | —D | M] (EWOQ Mobile Setup extension) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{f035aa18-ee32-4e6e-81d2-57e32867f8a7}
[2009/09/17 10:25:16 | 000,000,000 | —D | M] (EWOQ Rater Helper) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{feee3d1c-da92-4c21-8665-2425de7f53b7}
[2010/01/07 11:40:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\[removed]
[2009/06/06 13:36:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\[removed]
[2010/01/16 11:49:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\[removed]
[2010/05/28 10:20:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}\chrome\mozapps\extensions
[2009/12/05 12:25:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{285da7e0-729d-11db-9fe1-0800200c9a66}\chrome\mozapps\extensions
[2009/12/05 12:25:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xyzwfm44.default\extensions\{285da7e0-729d-11db-9fe1-0800200c9a66}\chrome\mozapps\extensions\CVS
[2010/01/20 12:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\SeaMonkey\Profiles\2s920hf8.default\extensions
[2009/06/03 14:55:24 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/08/20 09:19:43 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/08/04 09:57:12 | 000,294,912 | —- | M] (Musicnotes, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npmusicn.dll
[2008/09/15 11:52:06 | 000,376,832 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll

O1 HOSTS File: ([2010/08/18 14:01:30 | 000,000,762 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.0.4 HP000D9D1C974E
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboForm.dll (Siber Systems Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\RoboForm\RoboForm.dll (Siber Systems Inc.)
O4 - HKCU..\Run: [BackgroundSwitcher] C:\Program Files\John's Background Switcher\BackgroundSwitcher.exe (johnsadventures.com)
O4 - HKCU..\Run: [DesktopIconToy] C:\Program Files\Desktop Icon Toy\DesktopIconToy.exe (iDeskSoft)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe (Antony Lewis)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Bible Blips.lnk = C:\Program Files\BBlips\Bblips.exe (Barbor Software)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OccasionReminder.lnk = C:\Program Files\OccasionReminder\OccasionReminder.exe (Barbor Software)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Spamihilator.lnk = C:\Program Files\Spamihilator\spamihilator.exe (Michel Krämer)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Customize Menu - C:\Program Files\RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O8 - Extra context menu item: Save Forms - C:\Program Files\RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet; - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra Button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta ()
O9 - Extra 'Tools' menuitem : &Toolbar; Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta ()
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Freedom Bar - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Freedom Bar\Freedom Bar.exe (TAS Independent Programming)
O9 - Extra 'Tools' menuitem : Freedom Bar 8.6-GDI+ - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Freedom Bar\Freedom Bar.exe (TAS Independent Programming)
O15 - HKCU\..Trusted Domains: facebook.com ([login] https in Trusted sites)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Value error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - TPSvc.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/04 00:18:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69537929998893056)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/21 16:58:12 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/08/21 09:33:17 | 000,000,000 | —D | C] – C:\Program Files\Hijackthis
[2010/08/21 08:30:45 | 001,198,928 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2010/08/21 08:29:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GooredFix Backups
[2010/08/21 08:21:06 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
[2010/08/21 08:20:48 | 000,071,398 | —- | C] (jpshortstuff) – C:\Documents and Settings\Owner\Desktop\GooredFix.exe
[2010/08/20 15:42:23 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/08/20 10:27:42 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/08/20 09:22:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Foxit Software
[2010/08/20 09:21:33 | 000,000,000 | —D | C] – C:\Program Files\Foxit Software
[2010/08/19 22:59:55 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/18 17:10:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Nitro PDF
[2010/08/18 17:07:10 | 000,026,416 | —- | C] (Nitro PDF Software) – C:\WINDOWS\System32\nitrolocalmon.dll
[2010/08/18 17:07:10 | 000,017,712 | —- | C] (Nitro PDF Software) – C:\WINDOWS\System32\nitrolocalui.dll
[2010/08/18 17:06:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2010/08/18 17:03:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Downloaded Installations
[2010/08/18 16:31:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/08/18 16:31:57 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/18 14:46:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/18 14:46:48 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/18 14:46:48 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/18 13:10:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2010/08/18 11:45:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/08/17 07:08:23 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/08/17 07:01:20 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/08/16 11:13:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/08/16 08:51:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/08/16 08:45:42 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/08/16 08:45:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2010/08/15 22:49:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/08/15 22:44:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/08/14 09:10:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software
[2010/08/14 08:53:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/08/13 10:44:27 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/08/13 09:47:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/08/13 06:55:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia

========== Files - Modified Within 30 Days ==========

[2010/08/21 17:03:32 | 014,417,920 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/08/21 16:58:31 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/08/21 16:55:32 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/21 16:53:47 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/21 16:53:36 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/08/21 16:53:16 | 000,000,412 | —- | M] () – C:\WINDOWS\tasks\Auslogics Boost Speed Disk Defrag Start On Windows Logon.job
[2010/08/21 16:53:01 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/21 16:52:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/21 16:51:51 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/08/21 16:51:36 | 014,636,336 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/08/21 09:33:17 | 000,002,006 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/08/21 09:32:30 | 001,402,880 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.msi
[2010/08/21 08:21:06 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
[2010/08/21 08:20:52 | 000,071,398 | —- | M] (jpshortstuff) – C:\Documents and Settings\Owner\Desktop\GooredFix.exe
[2010/08/21 08:20:46 | 001,133,429 | —- | M] () – C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2010/08/20 16:01:36 | 000,173,176 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/20 15:58:01 | 000,472,376 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/20 15:57:18 | 016,252,928 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat.regbk109
[2010/08/20 15:54:04 | 000,000,115 | —- | M] () – C:\WINDOWS\System32\_WKERNEL.SYL
[2010/08/20 12:50:42 | 000,398,744 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/08/20 10:23:50 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/18 16:32:25 | 000,000,949 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/08/18 14:46:52 | 000,000,714 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/18 11:48:43 | 000,016,968 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/08/18 09:38:02 | 000,000,202 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/17 07:08:30 | 000,000,286 | RHS- | M] () – C:\boot.ini
[2010/08/16 22:59:22 | 000,001,284 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/16 22:59:22 | 000,000,216 | —- | M] () – C:\Boot.bak
[2010/08/16 09:49:10 | 001,198,928 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2010/08/15 22:54:57 | 000,000,523 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/08/15 16:30:11 | 000,036,864 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/15 15:52:22 | 000,000,430 | —- | M] () – C:\WINDOWS\rmp3c.ini
[2010/08/15 15:52:22 | 000,000,005 | —- | M] () – C:\WINDOWS\System32\SySrmp3.dat
[2010/08/14 08:53:51 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/14 00:30:56 | 000,001,706 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/08/14 00:30:53 | 000,002,639 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/08/11 07:41:23 | 000,501,702 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/11 07:41:23 | 000,441,552 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/11 07:41:23 | 000,071,488 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/06 09:20:24 | 000,000,645 | —- | M] () – C:\Documents and Settings\Owner\Desktop\AM-DeadLink.lnk
[2010/08/05 08:46:47 | 000,000,844 | —- | M] () – C:\Documents and Settings\Owner\Desktop\LioNBRIDGE Guidelines.lnk
[2010/08/03 18:55:34 | 000,000,072 | —- | M] () – C:\WINDOWS\eFaxView.ini
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
Here's more of OTL.txt (it wouldn't fit in 1 post):

========== Files Created - No Company Name ==========

[2010/08/21 09:32:25 | 001,402,880 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.msi
[2010/08/21 08:20:41 | 001,133,429 | —- | C] () – C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2010/08/20 15:56:31 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Owner\ntuser.dat.regan613.LOG
[2010/08/19 22:59:56 | 000,002,006 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/08/18 16:32:25 | 000,000,949 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/08/18 14:46:52 | 000,000,714 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/18 11:48:43 | 000,016,968 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/08/17 07:08:30 | 000,000,216 | —- | C] () – C:\Boot.bak
[2010/08/17 07:08:25 | 000,260,272 | —- | C] () – C:\cmldr
[2010/08/14 08:53:51 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/12 08:48:14 | 016,252,928 | —- | C] () – C:\Documents and Settings\Owner\ntuser.dat.regbk109
[2010/08/12 08:48:14 | 014,417,920 | —- | C] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/08/06 09:20:24 | 000,000,645 | —- | C] () – C:\Documents and Settings\Owner\Desktop\AM-DeadLink.lnk
[2010/08/05 08:46:47 | 000,000,844 | —- | C] () – C:\Documents and Settings\Owner\Desktop\LioNBRIDGE Guidelines.lnk
[2010/05/05 19:09:49 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/05/05 19:07:23 | 000,000,044 | —- | C] () – C:\WINDOWS\EPNX410.ini
[2010/03/10 21:06:28 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT09.ini
[2010/02/16 10:42:45 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\syoepk_lib0.dll
[2009/11/09 09:39:50 | 000,000,045 | —- | C] () – C:\WINDOWS\System32\_WDYSZYG.sys
[2009/10/14 22:43:10 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2009/09/19 22:30:10 | 000,003,567 | R— | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2009/09/19 22:30:10 | 000,000,146 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/09/19 22:28:45 | 000,000,776 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/09/19 22:24:01 | 000,003,826 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/06/12 22:02:14 | 000,000,034 | —- | C] () – C:\WINDOWS\ais.ini
[2009/04/16 11:47:39 | 000,000,054 | —- | C] () – C:\WINDOWS\CmdFile.INI
[2009/04/14 09:26:17 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/03/31 09:45:50 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/03/25 18:37:23 | 000,106,343 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\FASTWiz.log
[2009/02/27 17:20:18 | 000,000,075 | —- | C] () – C:\WINDOWS\TaxACT08.ini
[2008/12/08 17:09:06 | 000,000,133 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2008/10/30 11:39:18 | 000,000,141 | —- | C] () – C:\WINDOWS\System32\09wutili.sys
[2008/09/20 08:08:29 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\w32apiw.dll
[2008/06/24 18:43:09 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2008/06/24 18:41:22 | 000,000,018 | —- | C] () – C:\WINDOWS\Epson640.ini
[2008/06/13 10:22:49 | 000,000,043 | —- | C] () – C:\WINDOWS\iltwain.ini
[2008/05/18 23:19:47 | 000,027,648 | -HS- | C] () – C:\WINDOWS\System32\Smab0.dll
[2008/05/07 12:10:54 | 000,000,047 | —- | C] () – C:\WINDOWS\entpack.ini
[2008/05/07 07:41:44 | 000,000,131 | —- | C] () – C:\WINDOWS\chess.ini
[2008/04/17 12:46:06 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2008/04/03 09:24:47 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2008/03/29 23:17:53 | 000,000,164 | —- | C] () – C:\WINDOWS\RECMGRUN.INI
[2008/03/29 23:17:28 | 000,003,455 | —- | C] () – C:\WINDOWS\RECVCALL.INI
[2008/02/21 15:01:52 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/02/04 10:58:36 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\Oeminfo.ini
[2008/02/04 10:32:42 | 000,001,608 | —- | C] () – C:\WINDOWS\mgreg.ini
[2008/02/04 10:28:43 | 000,000,061 | —- | C] () – C:\WINDOWS\mgwin.ini
[2008/01/20 10:19:11 | 000,157,696 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/01/20 10:19:08 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/01/20 10:19:08 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/01/20 10:19:08 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/01/20 10:19:07 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/01/20 10:19:06 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2007/12/27 08:14:25 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\PosTickerLib.dll
[2007/11/16 19:45:17 | 000,000,430 | —- | C] () – C:\WINDOWS\rmp3c.ini
[2007/11/16 19:36:48 | 000,000,063 | —- | C] () – C:\WINDOWS\mp3torm.ini
[2007/11/16 17:13:01 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2007/11/16 12:14:06 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\cygz.dll
[2007/11/16 12:14:06 | 000,007,196 | —- | C] () – C:\WINDOWS\System32\INI_Pro_3GP_AAC.ini
[2007/11/16 12:14:06 | 000,005,028 | —- | C] () – C:\WINDOWS\System32\INI_Pro_3GP2_AAC.ini
[2007/11/16 12:14:06 | 000,003,045 | —- | C] () – C:\WINDOWS\System32\INI_Pro_iPod.ini
[2007/11/16 12:14:06 | 000,002,910 | —- | C] () – C:\WINDOWS\System32\INI_Pro_3GP_AMR.ini
[2007/11/16 12:14:06 | 000,001,964 | —- | C] () – C:\WINDOWS\System32\INI_QT_3GPP2_QVGA_AAC.ini
[2007/11/16 12:14:06 | 000,001,964 | —- | C] () – C:\WINDOWS\System32\INI_QT_3GPP2_QCIF_AAC.ini
[2007/11/16 12:14:06 | 000,001,814 | —- | C] () – C:\WINDOWS\System32\INI_QT_3GPP_QVGA_AAC.ini
[2007/11/16 12:14:06 | 000,001,814 | —- | C] () – C:\WINDOWS\System32\INI_QT_3GPP_QCIF_AMR.ini
[2007/11/16 12:14:06 | 000,001,814 | —- | C] () – C:\WINDOWS\System32\INI_QT_3GPP_QCIF_AAC.ini
[2007/11/16 12:14:06 | 000,000,036 | —- | C] () – C:\WINDOWS\System32\INI_Add_mfra.ini
[2007/11/16 12:14:05 | 000,001,814 | —- | C] () – C:\WINDOWS\System32\INI_QT_3GPP_QVGA_AMR.ini
[2007/11/15 20:27:56 | 000,598,016 | —- | C] () – C:\WINDOWS\System32\viscomqtde.dll
[2007/11/15 20:27:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\lame_encOLD.dll
[2007/10/26 11:52:00 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2007/08/31 14:10:38 | 000,000,037 | —- | C] () – C:\WINDOWS\marscam.ini
[2007/08/31 10:47:36 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\liplW7.dll
[2007/08/31 10:47:36 | 000,278,528 | —- | C] () – C:\WINDOWS\System32\liplPX.dll
[2007/08/31 10:47:36 | 000,278,528 | —- | C] () – C:\WINDOWS\System32\liplP6.dll
[2007/08/31 10:47:36 | 000,278,528 | —- | C] () – C:\WINDOWS\System32\liplM6.dll
[2007/08/31 10:47:35 | 000,290,816 | —- | C] () – C:\WINDOWS\System32\liplA6.dll
[2007/08/31 10:47:35 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\lipl.dll
[2007/05/11 15:37:04 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\CDVPreviewEx.dll
[2007/04/22 22:11:24 | 000,000,054 | —- | C] () – C:\WINDOWS\JascCmdFile.INI
[2007/04/02 11:20:53 | 000,000,057 | —- | C] () – C:\WINDOWS\DcmLtbox-WS.ini
[2007/03/09 19:33:14 | 000,000,004 | -H– | C] () – C:\WINDOWS\uccspecb.sys
[2007/03/03 11:35:23 | 000,000,065 | —- | C] () – C:\WINDOWS\WaterIllusion.ini
[2007/02/15 14:59:29 | 000,000,091 | —- | C] () – C:\WINDOWS\TaxACT06.ini
[2007/02/06 00:47:17 | 000,000,311 | —- | C] () – C:\WINDOWS\pdf2word.INI
[2007/02/05 16:14:48 | 000,000,052 | —- | C] () – C:\WINDOWS\pdf2text.INI
[2007/01/25 13:42:36 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\oggds.dll
[2007/01/25 13:42:36 | 000,112,128 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2007/01/25 13:42:36 | 000,061,952 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2007/01/25 13:42:36 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2007/01/23 17:31:08 | 000,000,072 | —- | C] () – C:\WINDOWS\eFaxView.ini
[2007/01/20 14:19:31 | 000,000,106 | —- | C] () – C:\WINDOWS\SSDESWDG.INI
[2007/01/19 16:36:39 | 000,000,718 | —- | C] () – C:\WINDOWS\SWDEPEND.INI
[2007/01/19 16:15:18 | 000,000,069 | —- | C] () – C:\WINDOWS\WINHLP32.INI
[2007/01/11 15:52:02 | 000,000,045 | —- | C] () – C:\WINDOWS\EPSC82.ini
[2007/01/05 20:34:59 | 000,000,131 | —- | C] () – C:\WINDOWS\EurekaLog.ini
[2007/01/02 17:41:03 | 000,000,210 | —- | C] () – C:\WINDOWS\System32\sr2spec.ini
[2007/01/02 17:22:39 | 000,000,011 | —- | C] () – C:\WINDOWS\exchng.ini
[2007/01/02 17:15:20 | 000,000,611 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/01/02 15:04:19 | 000,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/01/02 14:47:35 | 000,036,864 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/02 14:03:03 | 000,003,099 | —- | C] () – C:\WINDOWS\TVP3XDrv.ini
[2006/12/07 17:42:29 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2006/12/07 13:09:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\swunilog.ini
[2006/12/06 14:15:52 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2006/12/04 17:04:37 | 000,005,884 | —- | C] () – C:\WINDOWS\messer.ini
[2006/12/04 16:24:21 | 000,000,523 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/04 16:13:07 | 000,004,272 | R— | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2006/05/20 12:32:24 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\PDFreDirectMonNT.dll
[2005/09/23 08:52:14 | 000,207,872 | —- | C] () – C:\WINDOWS\System32\OneWay.dll
[2002/12/24 16:59:10 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\atsdrve.dll
[2002/09/10 11:10:05 | 000,495,616 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2002/07/05 10:12:06 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\authdvd.dll
[2002/06/02 11:05:40 | 000,038,912 | —- | C] () – C:\WINDOWS\System32\1Way.dll
[1998/08/16 06:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
[1998/06/13 23:53:26 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\Gif89.dll
[1997/07/11 01:00:00 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 01:00:00 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 01:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 01:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1997/01/12 01:00:00 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\DTCTRACE.DLL
[1996/12/23 01:00:00 | 000,445,952 | —- | C] () – C:\WINDOWS\System32\REPODBC.DLL
[1996/12/23 01:00:00 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\REPRC.DLL
[1996/12/11 01:00:00 | 000,009,216 | —- | C] () – C:\WINDOWS\System32\DMEM.DLL
[1995/08/11 05:50:00 | 000,020,208 | —- | C] () – C:\WINDOWS\System32\CRAMAPI.DLL

========== LOP Check ==========

[2010/01/27 17:24:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2008/09/30 13:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Amazon
[2009/02/11 12:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2007/12/04 15:15:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eBay
[2010/05/05 19:34:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2007/12/07 11:24:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Extreme Thumbnail Generator
[2007/12/30 19:55:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft(3)
[2007/12/30 19:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft(4)
[2010/08/18 11:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2007/02/27 10:43:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Icon Constructor 3
[2010/05/16 08:37:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2009/06/26 16:51:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\KLS Soft
[2007/12/11 16:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/03/01 19:32:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/08/18 17:06:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2007/12/19 15:50:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/06/04 10:41:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PearlMountainSoft
[2010/08/15 23:00:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/08/15 22:57:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2008/06/21 10:24:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Renaissance Learning
[2010/03/08 17:00:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\River Past G5
[2008/12/01 11:52:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/08/16 22:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/12/23 10:46:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spamihilator
[2010/03/24 16:59:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/05 19:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2007/09/12 14:24:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Watermark Factory
[2010/08/14 08:54:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/01/17 09:25:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Acreon
[2007/08/09 09:37:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AI Internet Solutions
[2007/11/03 09:44:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\aignes
[2010/03/08 16:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2009/08/13 08:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Anthropics
[2010/06/22 12:18:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Any Video Converter
[2009/08/18 08:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apowersoft
[2006/12/09 12:28:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AQUATRA
[2009/02/13 14:39:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ashampoo
[2009/11/15 09:59:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Auslogics
[2009/06/06 10:02:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BookmarkBridge
[2008/06/13 10:01:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CasaPortale.de
[2010/08/16 19:26:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CoreFTP
[2007/12/31 12:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2007/09/12 14:20:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CSOdessa
[2008/04/21 13:57:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberPower Audio Editing Lab
[2008/05/28 08:40:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DemoCreator
[2009/10/14 22:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DisplayTune
[2010/08/18 17:15:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Downloaded Installations
[2009/01/28 20:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Eltima Software
[2010/05/05 22:27:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EPSON
[2010/06/14 11:58:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Facebook
[2010/08/04 08:16:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FILEminimizerPictures
[2010/08/20 09:22:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Foxit Software
[2008/06/25 09:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2007/05/10 12:22:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2010/08/15 16:50:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2010/05/19 16:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\homebank
[2008/01/19 10:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IcoFX
[2007/01/02 19:02:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ieSpell
[2009/06/06 10:46:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IObit
[2008/06/30 08:24:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\johnsadventures.com
[2009/07/18 09:31:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\KLS Soft
[2010/05/25 16:41:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\kompozer.net
[2010/05/05 19:36:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leader Technologies
[2006/12/04 16:38:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/03/03 10:10:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Magic Collage
[2007/01/15 17:09:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MailWasher
[2010/08/16 22:55:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MailWasherPro
[2008/09/16 09:20:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\minimem
[2010/03/23 22:48:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Moyea
[2008/08/07 16:33:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
[2008/09/20 08:08:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\nCleaner
[2009/06/09 10:12:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NesterSoft
[2010/08/18 17:10:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nitro PDF
[2010/02/21 16:12:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Notepad++
[2008/11/08 14:03:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Novosoft
[2009/01/31 10:19:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Obsidium
[2008/05/21 08:47:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Orbit
[2007/01/29 13:52:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PDF reDirect
[2010/06/04 10:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PearlMountainSoft
[2008/04/19 10:26:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Photo! 3D ScreenSaver
[2008/04/21 09:51:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PngOptimizer
[2008/11/10 17:18:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\RetouchPilot
[2008/01/30 18:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\River Past G5
[2007/12/19 09:13:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sam Francke
[2010/01/12 20:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\scriptocean
[2007/04/23 08:14:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2008/01/19 10:42:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Softplicity
[2010/08/21 16:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spamihilator
[2007/08/30 00:07:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\StickIt
[2010/04/18 08:18:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SuperUtils.com
[2009/10/15 15:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2007/01/10 16:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Thunderbird
[2008/04/06 08:23:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Topaz Moment
[2010/01/12 23:32:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Usingit
[2008/04/21 17:05:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart
[2008/04/21 17:00:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart Digital Photo Viewer
[2009/12/10 00:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wallpaper Alterer
[2008/06/25 17:14:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Weather Pulse
[2008/07/09 22:17:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2008/07/09 19:10:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherWatcher
[2008/06/17 16:36:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherWatcherLive
[2008/11/10 17:20:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WirePilot
[2008/12/12 17:43:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WordWeb
[2010/04/26 18:02:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\XnView
[2010/01/03 09:30:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\YCanPDF
[2007/03/22 15:24:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Zoner
[2010/08/21 16:55:32 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/04/15 08:05:27 | 000,000,566 | —- | M] () – C:\WINDOWS\Tasks\Auslogics Boost Speed Disk Defrag Console Defragmentation.job
[2010/08/21 16:53:16 | 000,000,412 | —- | M] () – C:\WINDOWS\Tasks\Auslogics Boost Speed Disk Defrag Start On Windows Logon.job
[2010/08/21 16:53:36 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
[2008/01/01 11:22:20 | 000,000,140 | —- | M] () – C:\WINDOWS\Tasks\JkDefragTask.cmd

========== Purity Check ==========
Ok, OTL.txt wouldn't fit in 2 posts either! Here's more:

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/08/21 16:52:33 | 000,044,438 | —- | M] () – C:\aaw7boot.log
[2009/06/12 22:02:14 | 000,000,619 | —- | M] () – C:\ADS_ERR.DBF
[2010/01/27 15:36:47 | 000,001,064 | —- | M] () – C:\aswBoot.log
[2006/12/04 00:18:30 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2007/02/26 18:11:05 | 000,000,408 | —- | M] () – C:\AVSAudioDXfilters.xml
[2010/08/16 22:59:22 | 000,000,216 | —- | M] () – C:\Boot.bak
[2010/08/17 07:08:30 | 000,000,286 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/08/20 08:36:43 | 000,030,740 | —- | M] () – C:\Combo-Fix.txt
[2010/08/20 10:27:38 | 000,028,609 | —- | M] () – C:\ComboFix.txt
[2006/12/04 00:18:30 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/15 15:05:27 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2006/12/07 17:43:00 | 000,105,682 | —- | M] () – C:\ErrorScreenShot.jpg
[2010/06/02 19:06:26 | 000,000,602 | —- | M] () – C:\filelist.xml
[2009/08/29 08:33:01 | 000,005,046 | —- | M] () – C:\headerBat1.txt
[2009/08/29 08:33:01 | 000,005,046 | —- | M] () – C:\headerBat2.txt
[2007/04/23 11:34:53 | 000,000,098 | —- | M] () – C:\index.ini
[2007/01/22 12:13:12 | 000,000,282 | —- | M] () – C:\INSTALL.LOG
[2006/12/04 00:18:30 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/02/28 12:56:10 | 000,003,346 | —- | M] () – C:\move_after.xml
[2007/02/28 12:56:10 | 000,003,288 | —- | M] () – C:\move_before.xml
[2006/12/04 00:18:30 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/12/04 16:51:51 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/09 11:00:20 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/21 16:52:34 | 2126,512,128 | -HS- | M] () – C:\pagefile.sys
[2009/10/14 22:42:46 | 000,000,173 | —- | M] () – C:\pdisdk.log
[2009/10/14 22:43:15 | 000,000,184 | —- | M] () – C:\pivot.log
[2009/04/14 09:29:10 | 000,017,832 | —- | M] () – C:\pspbrwse.jbf
[2010/08/18 14:05:31 | 000,002,261 | —- | M] () – C:\rapport.txt
[2010/08/17 11:30:09 | 000,042,022 | —- | M] () – C:\TDSSKiller.2.4.1.2_17.08.2010_11.29.29_log.txt
[2010/08/21 08:31:55 | 000,041,796 | —- | M] () – C:\TDSSKiller.2.4.1.2_21.08.2010_08.31.05_log.txt
[2010/08/21 09:27:24 | 000,041,104 | —- | M] () – C:\TDSSKiller.2.4.1.2_21.08.2010_09.26.20_log.txt
[2007/01/19 16:21:53 | 000,003,126 | —- | M] () – C:\VS97SP2.LOG
[2007/01/19 16:24:15 | 000,003,088 | —- | M] () – C:\VS97SP3.LOG
[2009/08/29 08:33:01 | 000,000,000 | —- | M] () – C:\XBatIndices.txt
[2009/09/19 22:46:07 | 000,001,372 | —- | M] () – C:\_Sid.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/12/04 00:18:11 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/06/28 16:57:33 | 000,038,848 | —- | M] (ALWIL Software) – C:\WINDOWS\avastSS.scr
[2006/04/01 10:25:34 | 000,258,560 | —- | M] (Barbor Software) – C:\WINDOWS\Bible Blips V40.scr
[2008/09/01 15:13:14 | 003,226,624 | —- | M] (Extreme Internet Software) – C:\WINDOWS\Endless-Slideshow.scr
[2008/04/12 19:46:48 | 002,751,488 | —- | M] (VicMan Software) – C:\WINDOWS\Photo! 3D ScreenSaver.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >
I'm having a terrible time getting this OTL.txt file pasted in. It won't accept much of it at once.


< %systemroot%\System32\config\*.sav >
[2006/12/03 19:09:27 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/12/03 19:09:27 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/12/03 19:09:26 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/09 11:06:57 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/12/04 17:00:48 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/08/21 08:21:06 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
[2010/08/21 08:20:52 | 000,071,398 | —- | M] (jpshortstuff) – C:\Documents and Settings\Owner\Desktop\GooredFix.exe
[2010/08/21 16:58:31 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/08/16 09:49:10 | 001,198,928 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
There must be something in this last section of OTL.txt because it won't accept it in a post, but there's only about 50 lines left. I'll try attaching the whole text file as you suggested.

Attachments:

5) I did the scanning with GMER step. Here is the output log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-21 19:16:03
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\uftyrpow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF5706CD2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF5706B8E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF5707142]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF570706C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF5706764]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF5706C68]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF57066A4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF5706708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF5706D88]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF5707210]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF5706D48]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF5706EC8]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF5713B9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF57139C0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF5713AFA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntoskrnl.exe!ObInsertObject 8056503A 5 Bytes JMP F5710F6C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!NtCreateSection 805652B3 7 Bytes JMP F57139C4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FE4C 7 Bytes JMP F5713BA0 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ObMakeTemporaryObject 8059F8CA 5 Bytes JMP F570F5B4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwLoadDriver 805A3B73 7 Bytes JMP F5713AFE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[1164] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0092000A
.text C:\WINDOWS\System32\svchost.exe[1164] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0093000A
.text C:\WINDOWS\System32\svchost.exe[1164] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0091000C
.text C:\WINDOWS\System32\svchost.exe[1164] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 02C9000A
.text C:\WINDOWS\System32\svchost.exe[1164] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00E2000A
.text C:\WINDOWS\Explorer.EXE[1776] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[1776] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[1776] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)

Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

—- Registry - GMER 1.0.15 —-

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{14F2DB0E-3AC5-F9D2-E70D-307BA2B60D7F}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{14F2DB0E-3AC5-F9D2-E70D-307BA2B60D7F}@faccejpnebdh 0x68 0x61 0x61 0x66 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{14F2DB0E-3AC5-F9D2-E70D-307BA2B60D7F}@faccejpnebeg 0x68 0x61 0x61 0x66 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{87C83D9A-A3B0-E52E-0BA0-DFBE09BC57AC}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{87C83D9A-A3B0-E52E-0BA0-DFBE09BC57AC}@eanfjcgdhc 0x61 0x62 0x6D 0x67 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{87C83D9A-A3B0-E52E-0BA0-DFBE09BC57AC}@caainb 0x64 0x62 0x6D 0x68 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{87C83D9A-A3B0-E52E-0BA0-DFBE09BC57AC}@oajhjcnaoidlaagdcncpkenkchhckp 0x64 0x61 0x6A 0x6E …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{87C83D9A-A3B0-E52E-0BA0-DFBE09BC57AC}@oafgiocniidnpblfggcljalmajdmnf 0x6A 0x61 0x6B 0x6E …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{87C83D9A-A3B0-E52E-0BA0-DFBE09BC57AC}@napfgologibfdodmahificliemad 0x6A 0x61 0x61 0x6F …

—- EOF - GMER 1.0.15 —-
Hello,

The infection is probably playing havoc when you attempt to post the logs.

You'll need to attach this log for me to review rather than post it.

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini File not found
    DRV - (nsak) – C:\DOCUME~1\Owner\LOCALS~1\Temp\00000081.nmc\nse\bin\nsak.sys File not found
    DRV - (NDISKIO) – C:\DOCUME~1\Owner\LOCALS~1\Temp\00000dc5.nmc\nse\bin\ndiskio.sys File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Value error.)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
    O20 - Winlogon\Notify\TPSvc: DllName - TPSvc.dll - File not found
    O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    type C:\Combo-Fix.txt /c
    type C:\ComboFix.txt /c
    type C:\TDSSKiller.2.4.1.2_17.08.2010_11.29.29_log.txt /c
    type C:\TDSSKiller.2.4.1.2_21.08.2010_08.31.05_log.txt /c
    type C:\TDSSKiller.2.4.1.2_21.08.2010_09.26.20_log.txt /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
I'm reviewing your logs now. While I'm doing that can you please do the following:

Please download MBRCheck.exe to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

Enter 'Y' and hit ENTER for more options, or 'N' to exit:


Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI