This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rogue Antivirus problem

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, folks, I come here as a man at his wits end :-s I've got a pc that is infected with one or more of these programs and try as I might I can't seem to get rid of them. I've been able to get the actual programs themselves pretty much eradicated (I think?) but their legacy lives on in my mutilated internet connection and xp's inability to perform certain tasks (stuff like running MRT, basically anything that's security based refuses to launch) The problem was initially spotted by antivir, and I thought I'd cleaned it out with that but on next reboot NOTHING would work 'this file is infected, security risk, run our scanner blah blah blah' so I did some digging and found malwarebytes anti-malware which I duly run. After this, the pc allowed me back in to click on most stuff (except the aforementioned windows security programs) and it's in a semi-workable state… HOWEVER When I start the computer up, the internet (cabled LAN) connection is working fine then within less than an hour (sometimes only a coupla minutes) the Local area connection icon in the taskbar begins to show only one way traffic (sent packets, received packets stop entirely). It also returns received errors into the multi millions, constantly racking 'em up. Now, evidently there's something still extant on the system that's causing this internet lockdown - some leftover insidious code from the previous rogue software that has evidently not been fully removed. I can post whichever logs and the like people need to be able to help, just let me know what you think I should do I really can't wipe the pc (only to have to possibly have it resurface on re-install anyways) :-s NEXT….. More simple, perhaps, I also have a rootkit called 'biiu' on a laptop (scant information about this one online, but that's what antivir said it was). I think it's been partially removed but the internet on this system is a lot slower than it was and the wireless or lan (if being used) shows a LOT of upload activity when it's just idling. Has definitely calmed down a lot since the supposed killing but it still does big chunks in bouts and my skype call quality is always poorer than it used to be, leading me to think something is slaving my connection in some shape or form…. This is a lesser issue (for me) than the main one regarding the rogue antivirus, though, but any help would of course be greatly appreciated :-) Thanks for taking the time to read this, I hope someone out there can be of some assistance !
Oh, and I've been trying to run the tools suggested but it seems to have hung on the ODT stage up until now - it's actually running at the moment on the 5th attempt or thereabouts :-o I will post the log as soon as it's available
Okay, here's the OTL log:

OTL logfile created on: 22/08/2010 13:49:56 - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = D:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2096)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 85.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 152.66 Gb Total Space | 69.67 Gb Free Space | 45.64% Space Free | Partition Type: NTFS
Drive D: | 149.04 Gb Total Space | 6.87 Gb Free Space | 4.61% Space Free | Partition Type: NTFS
Drive E: | 6.76 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
Drive G: | 1.88 Gb Total Space | 1.56 Gb Free Space | 82.97% Space Free | Partition Type: FAT32
Drive H: | 684.39 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded

Computer Name: EXPERIEN-09C7EE
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - D:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - D:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Microsoft Corporation)
PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3SWK.EXE (CANON INC.)
PRC - D:\WINDOWS\system32\CAP3RSK.EXE (CANON INC.)
PRC - D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE (CANON INC.)


========== Modules (SafeList) ==========

MOD - D:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - D:\WINDOWS\abuyocadisa.dll ()
MOD - D:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll File not found
SRV - (wscsvc) – D:\WINDOWS\System32\wscsvc.dll File not found
SRV - (ERSvc) – D:\WINDOWS\System32\ersvc.dll File not found
SRV - (AntiVirService) – D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (FLEXnet Licensing Service) – D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (AntiVirSchedulerService) – D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (DAUpdaterSvc) – D:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (spupdsvc) – D:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (hamachi) – D:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (sptd) – D:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (avipbb) – D:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – D:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (AtiHdmiService) – D:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ati2mtag) – D:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (xusb21) – D:\WINDOWS\system32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (TPkd) – D:\WINDOWS\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (avgio) – D:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – D:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (mcdbus) – D:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (Uim_IM) – D:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (UimBus) – D:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (hotcore3) – D:\WINDOWS\system32\DRIVERS\hotcore3.sys (Paragon Software Group)
DRV - (HDAudBus) – D:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – D:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (usbaudio) USB Audio Driver (WDM) – D:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (SiSGbeXP) – D:\WINDOWS\system32\drivers\SiSGbeXP.sys (Silicon Integrated Systems Corp.)
DRV - (ATITool) – D:\WINDOWS\system32\drivers\ATITool.sys ()
DRV - (speedfan) – D:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (MTsensor) – D:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (giveio) – D:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie_rsearch.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}:1.9.1
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\extensions\\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}: D:\Documents and Settings\Administrator\Local Settings\Application Data\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1} [2010/08/19 16:54:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/07/29 11:26:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/07/30 15:51:40 | 000,000,000 | —D | M]

[2010/02/13 19:40:38 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/07/08 11:32:44 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\96fl69b1.default\extensions
[2010/08/22 13:39:03 | 000,000,000 | —D | M] – D:\Program Files\Mozilla Firefox\extensions
[2010/07/28 18:54:06 | 000,000,000 | —D | M] (Skype extension for Firefox) – D:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2008/05/05 21:06:41 | 000,365,056 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\npupd62.dll
[2010/01/13 23:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – D:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/08/21 12:01:46 | 000,000,736 | —- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CAP3ON] D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3ONN.EXE (CANON INC.)
O4 - HKLM..\Run: [Npawotolixaq] D:\WINDOWS\abuyocadisa.DLL ()
O4 - HKLM..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [XboxStat] D:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - Startup: D:\Documents and Settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Canon LASER SHOT LBP-1120 Status Window.LNK = D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE (CANON INC.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuFavorites = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowMyComputer = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowMyDocs = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowMyMusic = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowRun = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowSearch = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O13 - ftp Prefix: missing
O13 - gopher Prefix: missing
O13 - home Prefix: missing
O13 - mosaic Prefix: missing
O13 - www Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: D:\WINDOWS\Soap Bubbles.bmp
O24 - Desktop BackupWallPaper: D:\WINDOWS\Soap Bubbles.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/21 17:09:36 | 000,000,115 | R— | M] () - H:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2003/11/12 20:06:46 | 000,000,000 | R–D | M] - H:\autorun – [ CDFS ]
O32 - AutoRun File - [2003/10/21 17:09:36 | 000,036,864 | R— | M] () - H:\autorun.exe – [ CDFS ]
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\autorun.exe – [2003/10/21 17:09:36 | 000,036,864 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/08/22 13:47:49 | 000,575,488 | —- | C] (OldTimer Tools) – D:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/22 13:47:49 | 000,388,608 | —- | C] (Trend Micro Inc.) – D:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2010/08/21 22:39:51 | 000,000,000 | —D | C] – D:\Program Files\Edirol
[2010/08/21 16:20:12 | 000,000,000 | —D | C] – D:\OutputFolder
[2010/08/21 16:20:11 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Application Data\Digiarty
[2010/08/21 16:20:05 | 000,000,000 | —D | C] – D:\Program Files\Digiarty
[2010/08/21 15:58:57 | 000,000,000 | —D | C] – D:\Program Files\Wise Registry Cleaner
[2010/08/21 15:57:26 | 004,143,168 | —- | C] (WiseCleaner.com ) – D:\Documents and Settings\Administrator\Desktop\WRCFree.exe
[2010/08/21 15:03:05 | 000,000,000 | —D | C] – D:\Program Files\MUSHclient
[2010/08/21 12:02:05 | 000,000,000 | —D | C] – D:\ERDNT
[2010/08/19 22:49:06 | 000,089,360 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\VB5DB.DLL
[2010/08/19 22:49:06 | 000,026,096 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\xmlinst.exe
[2010/08/19 22:49:06 | 000,024,576 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\msxml3a.dll
[2010/08/19 22:44:44 | 000,000,000 | -H-D | C] – D:\Program Files\InstallShield Installation Information
[2010/08/19 22:44:44 | 000,000,000 | —D | C] – D:\Program Files\UBISOFT
[2010/08/19 21:07:35 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2010/08/19 21:07:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/19 21:07:28 | 000,020,952 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbam.sys
[2010/08/19 21:07:28 | 000,000,000 | —D | C] – D:\Program Files\Malwarebytes' Anti-Malware
[2010/08/19 21:07:28 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/19 16:54:01 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Local Settings\Application Data\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}
[2010/08/19 16:52:50 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Local Settings\Application Data\bfjjtynmq
[2010/08/19 16:52:12 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Application Data\3224D393E4F55B8D27B96100014C838D
[2010/08/10 15:10:08 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\My Documents\ARCDE FLYERS
[2010/08/09 18:38:58 | 000,000,000 | —D | C] – D:\Program Files\Armadillo Run
[2010/08/01 17:20:33 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\My Documents\NAKED BRUNCH
[2010/07/30 15:51:21 | 000,318,904 | —- | C] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\wmpfirefoxplugin.exe
[2010/07/29 18:56:25 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Desktop\ALIEN SWARM STUFF
[2010/07/28 19:28:33 | 000,014,640 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\spmsgXP_2k3.dll
[2010/07/28 19:28:24 | 001,112,288 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\WdfCoInstaller01007.dll
[2010/07/28 19:28:24 | 000,062,424 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\drivers\xusb21.sys
[2010/07/28 19:28:13 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Xbox 360 Accessories
[2010/07/28 19:27:38 | 007,515,000 | —- | C] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\Xbox360_32Eng.exe
[2010/07/28 18:53:59 | 000,000,000 | —D | C] – D:\Program Files\Common Files\Skype
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/22 13:50:24 | 000,784,896 | —- | M] () – D:\WINDOWS\System32\drivers\pqckz.sys
[2010/08/22 13:43:58 | 000,359,929 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\dds.scr
[2010/08/22 13:43:48 | 000,388,608 | —- | M] (Trend Micro Inc.) – D:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2010/08/22 13:43:28 | 000,575,488 | —- | M] (OldTimer Tools) – D:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/22 13:23:01 | 004,718,592 | —- | M] () – D:\Documents and Settings\Administrator\NTUSER.DAT
[2010/08/22 12:58:41 | 000,000,000 | —- | M] () – D:\WINDOWS\Jteduzon.bin
[2010/08/22 12:52:17 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2010/08/22 01:44:10 | 000,000,178 | -HS- | M] () – D:\Documents and Settings\Administrator\ntuser.ini
[2010/08/22 01:44:02 | 009,168,456 | -H– | M] () – D:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/08/22 01:38:15 | 003,589,293 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite_11.mp3
[2010/08/21 23:37:50 | 003,589,293 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\bucketoshiteproto.mp3
[2010/08/21 21:45:13 | 060,388,522 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\BRUNCHTRACK.mp3
[2010/08/21 16:06:43 | 004,718,592 | —- | M] () – D:\Documents and Settings\Administrator\NTUSER.bak
[2010/08/21 15:59:00 | 000,001,714 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Clear with 1 click.lnk
[2010/08/21 15:59:00 | 000,000,846 | —- | M] () – D:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Registry Cleaner.lnk
[2010/08/21 15:59:00 | 000,000,828 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Wise Registry Cleaner.lnk
[2010/08/21 15:53:44 | 004,143,168 | —- | M] (WiseCleaner.com ) – D:\Documents and Settings\Administrator\Desktop\WRCFree.exe
[2010/08/21 15:48:09 | 000,000,435 | —- | M] () – D:\WINDOWS\system.ini
[2010/08/21 15:48:09 | 000,000,076 | —- | M] () – D:\WINDOWS\win.ini
[2010/08/21 15:36:06 | 000,113,536 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3.sfk
[2010/08/21 15:32:53 | 000,026,992 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.sfk
[2010/08/21 14:56:36 | 003,293,587 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3
[2010/08/21 13:56:38 | 013,787,180 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.wav
[2010/08/21 13:56:38 | 000,026,992 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0.sfk
[2010/08/21 13:56:26 | 013,787,208 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0
[2010/08/21 13:56:10 | 002,502,220 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3
[2010/08/21 13:12:53 | 000,000,120 | —- | M] () – D:\WINDOWS\Ggafivumejab.dat
[2010/08/21 12:01:46 | 000,000,736 | —- | M] () – D:\WINDOWS\System32\drivers\etc\hosts
[2010/08/19 22:49:22 | 000,002,028 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\Ubisoft Product Registration.lnk
[2010/08/19 22:44:48 | 000,001,861 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Play Prince of Persia The Sands of Time.lnk
[2010/08/19 21:07:31 | 000,000,696 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/19 20:49:56 | 000,002,838 | —- | M] () – D:\WINDOWS\awalehizuqazaqe.dll
[2010/08/19 17:02:18 | 000,002,838 | —- | M] () – D:\WINDOWS\axusiyuw.dll
[2010/08/19 12:45:24 | 000,002,184 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2010/08/10 17:47:14 | 013,601,485 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\07 Destroy techno.mp3
[2010/08/10 17:47:13 | 013,664,295 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\06 Passing by.mp3
[2010/08/10 17:46:58 | 013,147,126 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Rusted nuts & bolts.mp3
[2010/08/10 17:46:53 | 013,016,260 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\03 Gucci.mp3
[2010/08/10 17:44:30 | 010,521,440 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Tymon & Negative A - Metaphysical.mp3
[2010/08/10 17:33:00 | 015,984,225 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\TYMON & ANDRE FRAUENSTEIN - ETHEREAL.mp3
[2010/08/10 17:32:33 | 014,700,717 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_-_Void_FINAL.mp3
[2010/08/10 17:29:18 | 013,324,606 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_+_Stormtrooper_-_Hurricane_FINAL.mp3
[2010/08/10 17:27:50 | 012,467,764 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\tymon - stay.mp3
[2010/08/10 17:27:16 | 012,930,643 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\rattle brain.mp3
[2010/08/10 17:26:04 | 011,011,189 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\tymon - nonlinear dynamics (MASTER).mp3
[2010/08/10 16:21:39 | 004,161,177 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2 copy.jpg
[2010/08/10 16:21:05 | 006,236,028 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1 copy.jpg
[2010/08/10 16:08:02 | 064,540,362 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2.psd
[2010/08/10 15:53:11 | 043,512,968 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1.psd
[2010/07/30 15:51:16 | 000,318,904 | —- | M] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\wmpfirefoxplugin.exe
[2010/07/29 21:41:25 | 001,382,454 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\0pp5hv50.bmp
[2010/07/29 21:40:38 | 000,826,614 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\axo9093y.bmp
[2010/07/29 21:18:59 | 000,307,254 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\y0w8s9le.bmp
[2010/07/29 11:57:11 | 000,002,404 | —- | M] () – D:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/28 19:28:39 | 000,000,000 | -H– | M] () – D:\WINDOWS\System32\drivers\Msft_Kernel_xusb21_01007.Wdf
[2010/07/28 19:28:37 | 000,000,000 | -H– | M] () – D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/07/28 19:27:43 | 007,515,000 | —- | M] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\Xbox360_32Eng.exe
[2010/07/26 01:09:47 | 000,134,208 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\IMG_26072010_010708.png
[2010/07/26 01:09:12 | 001,094,502 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\c9d1pb0d.bmp
[2010/07/26 01:07:25 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\nnosnpqz.bmp
[2010/07/26 01:07:17 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\04rxher6.bmp
[2010/07/26 01:06:55 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\acq18sqw.bmp
[2010/07/26 01:06:00 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\05xf3kqa.bmp
[2010/07/26 01:03:29 | 000,215,254 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\orula13r.bmp
[2010/07/26 01:03:19 | 001,166,454 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\bmg814ud.bmp
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/22 13:47:49 | 000,359,929 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\dds.scr
[2010/08/22 01:37:39 | 003,589,293 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite_11.mp3
[2010/08/21 23:37:14 | 003,589,293 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\bucketoshiteproto.mp3
[2010/08/21 21:44:21 | 060,388,522 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\BRUNCHTRACK.mp3
[2010/08/21 16:06:23 | 000,000,000 | -H– | C] () – D:\Documents and Settings\Administrator\NTUSER.rhk.LOG
[2010/08/21 15:59:00 | 000,001,714 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Clear with 1 click.lnk
[2010/08/21 15:59:00 | 000,000,846 | —- | C] () – D:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Registry Cleaner.lnk
[2010/08/21 15:59:00 | 000,000,828 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Wise Registry Cleaner.lnk
[2010/08/21 15:35:13 | 000,113,536 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3.sfk
[2010/08/21 14:56:15 | 003,293,587 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3
[2010/08/21 13:56:38 | 013,787,180 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.wav
[2010/08/21 13:56:38 | 000,026,992 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.sfk
[2010/08/21 13:56:27 | 000,026,992 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0.sfk
[2010/08/21 13:56:26 | 013,787,208 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0
[2010/08/21 13:56:08 | 002,502,220 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3
[2010/08/19 22:49:22 | 000,002,028 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\Ubisoft Product Registration.lnk
[2010/08/19 22:49:07 | 000,069,632 | —- | C] () – D:\WINDOWS\System32\xmltok.dll
[2010/08/19 22:49:07 | 000,036,864 | —- | C] () – D:\WINDOWS\System32\xmlparse.dll
[2010/08/19 22:49:07 | 000,035,840 | —- | C] () – D:\WINDOWS\System32\comdlg32.oca
[2010/08/19 22:49:06 | 000,029,184 | —- | C] () – D:\WINDOWS\System32\MSINET.oca
[2010/08/19 22:44:48 | 000,001,861 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Play Prince of Persia The Sands of Time.lnk
[2010/08/19 21:07:31 | 000,000,696 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/19 20:49:56 | 000,002,838 | —- | C] () – D:\WINDOWS\awalehizuqazaqe.dll
[2010/08/19 17:02:18 | 000,002,838 | —- | C] () – D:\WINDOWS\axusiyuw.dll
[2010/08/19 16:54:02 | 000,000,120 | —- | C] () – D:\WINDOWS\Ggafivumejab.dat
[2010/08/19 16:54:02 | 000,000,000 | —- | C] () – D:\WINDOWS\Jteduzon.bin
[2010/08/19 16:53:06 | 000,784,896 | —- | C] () – D:\WINDOWS\System32\drivers\pqckz.sys
[2010/08/10 17:30:13 | 010,521,440 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Tymon & Negative A - Metaphysical.mp3
[2010/08/10 17:30:10 | 013,147,126 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Rusted nuts & bolts.mp3
[2010/08/10 17:30:04 | 013,601,485 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\07 Destroy techno.mp3
[2010/08/10 17:30:01 | 013,664,295 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\06 Passing by.mp3
[2010/08/10 17:29:58 | 013,016,260 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\03 Gucci.mp3
[2010/08/10 17:10:43 | 013,324,606 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_+_Stormtrooper_-_Hurricane_FINAL.mp3
[2010/08/10 17:10:40 | 014,700,717 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_-_Void_FINAL.mp3
[2010/08/10 17:10:26 | 015,984,225 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\TYMON & ANDRE FRAUENSTEIN - ETHEREAL.mp3
[2010/08/10 17:10:13 | 012,467,764 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\tymon - stay.mp3
[2010/08/10 17:10:08 | 011,011,189 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\tymon - nonlinear dynamics (MASTER).mp3
[2010/08/10 17:10:04 | 012,930,643 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\rattle brain.mp3
[2010/08/10 16:21:35 | 004,161,177 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2 copy.jpg
[2010/08/10 16:20:53 | 006,236,028 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1 copy.jpg
[2010/08/10 16:07:59 | 064,540,362 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2.psd
[2010/08/10 15:53:08 | 043,512,968 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1.psd
[2010/07/29 21:40:08 | 001,382,454 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\0pp5hv50.bmp
[2010/07/29 21:39:42 | 000,826,614 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\axo9093y.bmp
[2010/07/29 21:18:33 | 000,307,254 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\y0w8s9le.bmp
[2010/07/28 19:28:39 | 000,000,000 | -H– | C] () – D:\WINDOWS\System32\drivers\Msft_Kernel_xusb21_01007.Wdf
[2010/07/28 19:28:37 | 000,000,000 | -H– | C] () – D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/07/26 01:09:41 | 000,134,208 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\IMG_26072010_010708.png
[2010/07/26 01:08:36 | 001,094,502 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\c9d1pb0d.bmp
[2010/07/26 01:06:10 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\nnosnpqz.bmp
[2010/07/26 01:06:05 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\04rxher6.bmp
[2010/07/26 01:05:37 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\acq18sqw.bmp
[2010/07/26 01:05:18 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\05xf3kqa.bmp
[2010/07/26 01:03:19 | 000,215,254 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\orula13r.bmp
[2010/07/26 01:01:56 | 001,166,454 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\bmg814ud.bmp
[2010/06/13 14:48:14 | 000,000,130 | —- | C] () – D:\WINDOWS\wininit.ini
[2010/05/22 22:10:34 | 000,000,008 | —- | C] () – D:\Documents and Settings\Administrator\Application Data\ofubwi.dat
[2010/03/24 17:53:49 | 000,322,248 | —- | C] () – D:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/03/08 13:34:40 | 000,354,816 | —- | C] () – D:\WINDOWS\System32\psisdecd.dll
[2010/03/01 15:09:40 | 000,000,116 | —- | C] () – D:\WINDOWS\NeroDigital.ini
[2010/02/23 14:44:52 | 000,000,474 | —- | C] () – D:\WINDOWS\kaillera.ini
[2010/02/13 19:40:03 | 000,462,848 | —- | C] () – D:\WINDOWS\System32\lame_enc.dll
[2010/02/13 19:28:35 | 000,005,810 | —- | C] () – D:\WINDOWS\System32\drivers\ASACPI.sys
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – D:\WINDOWS\System32\xlive.dll.cat
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – D:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelFrench.dll
[2008/05/06 13:00:00 | 000,190,976 | —- | C] () – D:\WINDOWS\abuyocadisa.dll
[2008/05/06 13:00:00 | 000,000,287 | —- | C] () – D:\WINDOWS\System32\Oeminfo.ini
[2006/11/10 14:08:50 | 000,024,064 | —- | C] () – D:\WINDOWS\System32\drivers\ATITool.sys
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – D:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/08/19 16:59:05 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\3224D393E4F55B8D27B96100014C838D
[2010/05/06 00:43:10 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Antares
[2010/03/26 14:31:28 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Armagetron
[2010/03/08 13:27:50 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\DAEMON Tools Lite
[2010/08/21 16:20:11 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Digiarty
[2010/03/02 15:57:23 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Facebook
[2010/08/19 17:00:51 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Giaseg
[2010/03/31 18:38:15 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\GlarySoft
[2010/08/19 22:35:16 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\GrabIt
[2010/05/22 05:33:17 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\ImgBurn
[2010/03/18 17:47:49 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\OpenOffice.org
[2010/03/24 17:11:59 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Orbit
[2010/06/11 17:02:30 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\PACE Anti-Piracy
[2010/05/09 16:58:13 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Propellerhead Software
[2010/03/24 18:00:45 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Publish Providers
[2010/05/09 16:53:48 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Rapid Evolution 2
[2010/03/26 12:50:37 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\runic games
[2010/03/24 19:20:51 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Sony
[2010/06/11 17:02:30 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Sony Creative Software
[2010/03/24 17:49:14 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Sony Setup
[2010/02/22 23:44:31 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\SynthMaker
[2010/05/19 15:07:36 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\uTorrent
[2010/08/19 20:37:31 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Vaxaoc
[2010/03/26 14:28:33 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Armagetron
[2010/04/05 20:27:44 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\BioWare
[2010/03/08 13:22:45 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/05/04 13:50:57 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Dragon's Eye Productions
[2010/02/13 23:46:10 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2010/06/11 17:02:30 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2010/04/15 14:16:55 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/05/09 16:58:13 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2010/03/24 17:55:45 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Sony
[2010/08/21 00:00:53 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Soulseek
[2010/03/29 17:42:22 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\TEMP

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: ATAPI.SYS >
[2008/05/06 13:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – D:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/05/06 13:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – D:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/05/06 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – D:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/05/06 13:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – D:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/09/18 15:28:56 | 000,446,464 | R— | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – D:\WINDOWS\system32\ATIDEMGX.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010/08/22 13:55:23 | 000,784,896 | —- | M] () Unable to obtain MD5 – D:\WINDOWS\system32\drivers\pqckz.sys

< %systemroot%\System32\config\*.sav >
[2010/02/13 19:27:30 | 000,069,632 | —- | M] () – D:\WINDOWS\system32\config\default.sav
[2010/02/13 19:27:30 | 000,868,352 | —- | M] () – D:\WINDOWS\system32\config\software.sav
[2010/02/13 19:27:30 | 000,696,320 | —- | M] () – D:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 1292 bytes -> D:\Documents and Settings\Administrator\Cookies:XkFoOYLArDEgrYHk4W
@Alternate Data Stream - 1269 bytes -> D:\Documents and Settings\All Users\Application Data\Microsoft:jYLK6hQuSAP9wxoLZVmQk2QPXLJX
@Alternate Data Stream - 1258 bytes -> D:\Documents and Settings\Administrator\Cookies:6AFxFFzWkH4COPBQHNimSs
@Alternate Data Stream - 1209 bytes -> D:\Documents and Settings\All Users\Application Data\Microsoft:viEbPUpBxSZYqCchQri4vYeG
@Alternate Data Stream - 119 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 1134 bytes -> D:\Documents and Settings\All Users\Application Data\Microsoft:mqRwsqvjbzk3NeHxaPlD

< End of report >
Hijackthis log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:58:11, on 22/08/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\spoolsv.exe D:\Program Files\Avira\AntiVir Desktop\sched.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\RTHDCPL.EXE D:\Program Files\Avira\AntiVir Desktop\avgnt.exe D:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe D:\Program Files\Avira\AntiVir Desktop\avguard.exe D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe D:\Program Files\Java\jre6\bin\jqs.exe D:\WINDOWS\system32\CAP3RSK.EXE D:\Program Files\Avira\AntiVir Desktop\avshadow.exe D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE D:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe D:\WINDOWS\system32\svchost.exe D:\Program Files\Steam\Steam.exe D:\WINDOWS\notepad.exe D:\WINDOWS\Explorer.EXE D:\Documents and Settings\Administrator\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [CAP3ON] D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3ONN.EXE O4 - HKLM\..\Run: [XboxStat] "D:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun O4 - HKLM\..\Run: [Npawotolixaq] rundll32.exe "D:\WINDOWS\abuyocadisa.dll",Startup O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user') O4 - Startup: OpenOffice.org 3.2.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe O4 - Global Startup: Canon LASER SHOT LBP-1120 Status Window.LNK = D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll O13 - DefaultPrefix: O13 - WWW Prefix: O13 - Home Prefix: O13 - Mosaic Prefix: O13 - FTP Prefix: O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe – End of file - 5506 bytes
DDS will not run, giving the error ' " D:\Windows\System32\Find.exe" ' is not recognised as an internal or external command, operable program or batch file. I've tried a few times, no dice :-s
Please, if anyone can help ! This pc is my work and I can''t continue till it's back to working normally :-( Connection just went again, when I click repair it says it's unable to complete, with the cause being that it cannot renew the IP address :-s
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    MOD - D:\WINDOWS\abuyocadisa.dll ()
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKLM..\Run: [Npawotolixaq] D:\WINDOWS\abuyocadisa.DLL ()
    O33 - MountPoints2\H\Shell - "" = AutoRun
    O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\autorun.exe – [2003/10/21 17:09:36 | 000,036,864 | R— | M] ()
    [2010/08/19 16:54:01 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Local Settings\Application Data\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}
    [2010/08/19 16:52:50 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Local Settings\Application Data\bfjjtynmq
    [2010/08/19 16:52:12 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Application Data\3224D393E4F55B8D27B96100014C838D
    [2010/08/22 13:50:24 | 000,784,896 | —- | M] () – D:\WINDOWS\System32\drivers\pqckz.sys
    [2010/08/22 12:58:41 | 000,000,000 | —- | M] () – D:\WINDOWS\Jteduzon.bin
    [2010/08/21 13:12:53 | 000,000,120 | —- | M] () – D:\WINDOWS\Ggafivumejab.dat
    [2010/08/19 20:49:56 | 000,002,838 | —- | M] () – D:\WINDOWS\awalehizuqazaqe.dll
    [2010/08/19 17:02:18 | 000,002,838 | —- | M] () – D:\WINDOWS\axusiyuw.dll
    [2010/05/22 22:10:34 | 000,000,008 | —- | C] () – D:\Documents and Settings\Administrator\Application Data\ofubwi.dat
    [2008/05/06 13:00:00 | 000,190,976 | —- | C] () – D:\WINDOWS\abuyocadisa.dll
    @Alternate Data Stream - 1292 bytes -> D:\Documents and Settings\Administrator\Cookies:XkFoOYLArDEgrYHk4W
    @Alternate Data Stream - 1269 bytes -> D:\Documents and Settings\All Users\Application Data\Microsoft:jYLK6hQuSAP9wxoLZVmQk2QPXLJX
    @Alternate Data Stream - 1258 bytes -> D:\Documents and Settings\Administrator\Cookies:6AFxFFzWkH4COPBQHNimSs
    @Alternate Data Stream - 1209 bytes -> D:\Documents and Settings\All Users\Application Data\Microsoft:viEbPUpBxSZYqCchQri4vYeG
    @Alternate Data Stream - 119 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
    @Alternate Data Stream - 1134 bytes -> D:\Documents and Settings\All Users\Application Data\Microsoft:mqRwsqvjbzk3NeHxaPlD
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT

please re-scan with OTL and post a fresh log, also please advise how the computer is running and if there are any outstanding issues.
Thank you so much for your reply - I'm doing as you instructed right now… Will post the logs as soon as I have them and let you know how things are looking.
>>>>>>>>>>>>>>FIRST SWEEP OF OTL AS INSTRUCTED

All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Npawotolixaq deleted successfully.
D:\WINDOWS\abuyocadisa.dll moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ not found.
File move failed. H:\autorun.exe scheduled to be moved on reboot.
D:\Documents and Settings\Administrator\Local Settings\Application Data\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}\chrome\content folder moved successfully.
D:\Documents and Settings\Administrator\Local Settings\Application Data\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}\chrome folder moved successfully.
D:\Documents and Settings\Administrator\Local Settings\Application Data\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1} folder moved successfully.
D:\Documents and Settings\Administrator\Local Settings\Application Data\bfjjtynmq folder moved successfully.
D:\Documents and Settings\Administrator\Application Data\3224D393E4F55B8D27B96100014C838D folder moved successfully.
File move failed. D:\WINDOWS\system32\drivers\pqckz.sys scheduled to be moved on reboot.
D:\WINDOWS\Jteduzon.bin moved successfully.
D:\WINDOWS\Ggafivumejab.dat moved successfully.
D:\WINDOWS\awalehizuqazaqe.dll moved successfully.
D:\WINDOWS\axusiyuw.dll moved successfully.
D:\Documents and Settings\Administrator\Application Data\ofubwi.dat moved successfully.
File D:\WINDOWS\abuyocadisa.dll not found.
ADS D:\Documents and Settings\Administrator\Cookies:XkFoOYLArDEgrYHk4W deleted successfully.
ADS D:\Documents and Settings\All Users\Application Data\Microsoft:jYLK6hQuSAP9wxoLZVmQk2QPXLJX deleted successfully.
ADS D:\Documents and Settings\Administrator\Cookies:6AFxFFzWkH4COPBQHNimSs deleted successfully.
ADS D:\Documents and Settings\All Users\Application Data\Microsoft:viEbPUpBxSZYqCchQri4vYeG deleted successfully.
ADS D:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF deleted successfully.
ADS D:\Documents and Settings\All Users\Application Data\Microsoft:mqRwsqvjbzk3NeHxaPlD deleted successfully.
========== COMMANDS ==========
D:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 110987 bytes

User: All Users

User: Default User

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 2285625124 bytes
->Temporary Internet Files folder emptied: 9642301 bytes
->Java cache emptied: 2234856 bytes
->FireFox cache emptied: 36271505 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 686956 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2778725 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 394617 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 2287196643 bytes

Total Files Cleaned = 4,411.00 mb


OTL by OldTimer - Version 3.2.10.0 log created on 08222010_161625

Files\Folders moved on Reboot…
File move failed. H:\autorun.exe scheduled to be moved on reboot.
File move failed. D:\WINDOWS\system32\drivers\pqckz.sys scheduled to be moved on reboot.

Registry entries deleted on Reboot…


>>>>>>>>>>>>>>>> SECOND SWEEP WITH OTL DONE AFTER REBOOT

OTL logfile created on: 22/08/2010 16:20:36 - Run 2
OTL by OldTimer - Version 3.2.10.0 Folder = D:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2096)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 152.66 Gb Total Space | 74.91 Gb Free Space | 49.07% Space Free | Partition Type: NTFS
Drive D: | 149.04 Gb Total Space | 9.86 Gb Free Space | 6.62% Space Free | Partition Type: NTFS
Drive E: | 6.76 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
Drive G: | 1.88 Gb Total Space | 1.56 Gb Free Space | 82.79% Space Free | Partition Type: FAT32
Drive H: | 684.39 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded

Computer Name: EXPERIEN-09C7EE
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - D:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - D:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - D:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Microsoft Corporation)
PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3SWK.EXE (CANON INC.)
PRC - D:\WINDOWS\system32\CAP3RSK.EXE (CANON INC.)
PRC - D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE (CANON INC.)


========== Modules (SafeList) ==========

MOD - D:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - D:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll File not found
SRV - (wscsvc) – D:\WINDOWS\System32\wscsvc.dll File not found
SRV - (ERSvc) – D:\WINDOWS\System32\ersvc.dll File not found
SRV - (AntiVirService) – D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (FLEXnet Licensing Service) – D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (AntiVirSchedulerService) – D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (DAUpdaterSvc) – D:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (spupdsvc) – D:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (hamachi) – D:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (sptd) – D:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (avipbb) – D:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – D:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (AtiHdmiService) – D:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ati2mtag) – D:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (xusb21) – D:\WINDOWS\system32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (TPkd) – D:\WINDOWS\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (avgio) – D:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – D:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (mcdbus) – D:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (Uim_IM) – D:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (UimBus) – D:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (hotcore3) – D:\WINDOWS\system32\DRIVERS\hotcore3.sys (Paragon Software Group)
DRV - (HDAudBus) – D:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – D:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (usbaudio) USB Audio Driver (WDM) – D:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (SiSGbeXP) – D:\WINDOWS\system32\drivers\SiSGbeXP.sys (Silicon Integrated Systems Corp.)
DRV - (ATITool) – D:\WINDOWS\system32\drivers\ATITool.sys ()
DRV - (speedfan) – D:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (MTsensor) – D:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (giveio) – D:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie_rsearch.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}:1.9.1
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\extensions\\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}: D:\Documents and Settings\Administrator\Local Settings\Application Data\{F51E5CBF-44D9-4E24-B99B-92F737DC1DA1}
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/07/29 11:26:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/07/30 15:51:40 | 000,000,000 | —D | M]

[2010/02/13 19:40:38 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/07/08 11:32:44 | 000,000,000 | —D | M] – D:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\96fl69b1.default\extensions
[2010/08/22 13:39:03 | 000,000,000 | —D | M] – D:\Program Files\Mozilla Firefox\extensions
[2010/07/28 18:54:06 | 000,000,000 | —D | M] (Skype extension for Firefox) – D:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2008/05/05 21:06:41 | 000,365,056 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\npupd62.dll
[2010/01/13 23:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – D:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/08/22 16:16:28 | 000,000,098 | —- | M]) - D:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM..\Run: [avgnt] D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CAP3ON] D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3ONN.EXE (CANON INC.)
O4 - HKLM..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [XboxStat] D:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - Startup: D:\Documents and Settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Canon LASER SHOT LBP-1120 Status Window.LNK = D:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE (CANON INC.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuFavorites = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowMyComputer = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowMyDocs = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowMyMusic = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowRun = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_ShowSearch = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O13 - ftp Prefix: missing
O13 - gopher Prefix: missing
O13 - home Prefix: missing
O13 - mosaic Prefix: missing
O13 - www Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: D:\WINDOWS\Soap Bubbles.bmp
O24 - Desktop BackupWallPaper: D:\WINDOWS\Soap Bubbles.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/21 17:09:36 | 000,000,115 | R— | M] () - H:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2003/11/12 20:06:46 | 000,000,000 | R–D | M] - H:\autorun – [ CDFS ]
O32 - AutoRun File - [2003/10/21 17:09:36 | 000,036,864 | R— | M] () - H:\autorun.exe – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/22 16:16:25 | 000,000,000 | —D | C] – D:\_OTL
[2010/08/22 13:47:49 | 000,575,488 | —- | C] (OldTimer Tools) – D:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/22 13:47:49 | 000,388,608 | —- | C] (Trend Micro Inc.) – D:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2010/08/21 22:39:51 | 000,000,000 | —D | C] – D:\Program Files\Edirol
[2010/08/21 16:20:12 | 000,000,000 | —D | C] – D:\OutputFolder
[2010/08/21 16:20:11 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Application Data\Digiarty
[2010/08/21 16:20:05 | 000,000,000 | —D | C] – D:\Program Files\Digiarty
[2010/08/21 15:58:57 | 000,000,000 | —D | C] – D:\Program Files\Wise Registry Cleaner
[2010/08/21 15:57:26 | 004,143,168 | —- | C] (WiseCleaner.com ) – D:\Documents and Settings\Administrator\Desktop\WRCFree.exe
[2010/08/21 15:03:05 | 000,000,000 | —D | C] – D:\Program Files\MUSHclient
[2010/08/21 12:02:05 | 000,000,000 | —D | C] – D:\ERDNT
[2010/08/19 22:49:06 | 000,089,360 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\VB5DB.DLL
[2010/08/19 22:49:06 | 000,026,096 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\xmlinst.exe
[2010/08/19 22:49:06 | 000,024,576 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\msxml3a.dll
[2010/08/19 22:44:44 | 000,000,000 | -H-D | C] – D:\Program Files\InstallShield Installation Information
[2010/08/19 22:44:44 | 000,000,000 | —D | C] – D:\Program Files\UBISOFT
[2010/08/19 21:07:35 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2010/08/19 21:07:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/19 21:07:28 | 000,020,952 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbam.sys
[2010/08/19 21:07:28 | 000,000,000 | —D | C] – D:\Program Files\Malwarebytes' Anti-Malware
[2010/08/19 21:07:28 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/10 15:10:08 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\My Documents\ARCDE FLYERS
[2010/08/09 18:38:58 | 000,000,000 | —D | C] – D:\Program Files\Armadillo Run
[2010/08/01 17:20:33 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\My Documents\NAKED BRUNCH
[2010/07/30 15:51:21 | 000,318,904 | —- | C] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\wmpfirefoxplugin.exe
[2010/07/29 18:56:25 | 000,000,000 | —D | C] – D:\Documents and Settings\Administrator\Desktop\ALIEN SWARM STUFF
[2010/07/28 19:28:33 | 000,014,640 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\spmsgXP_2k3.dll
[2010/07/28 19:28:24 | 001,112,288 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\WdfCoInstaller01007.dll
[2010/07/28 19:28:24 | 000,062,424 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\drivers\xusb21.sys
[2010/07/28 19:28:13 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Xbox 360 Accessories
[2010/07/28 19:27:38 | 007,515,000 | —- | C] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\Xbox360_32Eng.exe
[2010/07/28 18:53:59 | 000,000,000 | —D | C] – D:\Program Files\Common Files\Skype

========== Files - Modified Within 30 Days ==========

[2010/08/22 16:21:30 | 000,784,896 | —- | M] () – D:\WINDOWS\System32\drivers\pqckz.sys
[2010/08/22 16:18:10 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2010/08/22 16:17:04 | 004,718,592 | —- | M] () – D:\Documents and Settings\Administrator\NTUSER.DAT
[2010/08/22 16:17:04 | 000,000,178 | -HS- | M] () – D:\Documents and Settings\Administrator\ntuser.ini
[2010/08/22 16:16:28 | 000,000,098 | —- | M] () – D:\WINDOWS\System32\drivers\etc\Hosts
[2010/08/22 14:34:53 | 009,169,638 | -H– | M] () – D:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/08/22 13:43:58 | 000,359,929 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\dds.scr
[2010/08/22 13:43:48 | 000,388,608 | —- | M] (Trend Micro Inc.) – D:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2010/08/22 13:43:28 | 000,575,488 | —- | M] (OldTimer Tools) – D:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/22 01:38:15 | 003,589,293 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite_11.mp3
[2010/08/21 23:37:50 | 003,589,293 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\bucketoshiteproto.mp3
[2010/08/21 21:45:13 | 060,388,522 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\BRUNCHTRACK.mp3
[2010/08/21 16:06:43 | 004,718,592 | —- | M] () – D:\Documents and Settings\Administrator\NTUSER.bak
[2010/08/21 15:59:00 | 000,001,714 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Clear with 1 click.lnk
[2010/08/21 15:59:00 | 000,000,846 | —- | M] () – D:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Registry Cleaner.lnk
[2010/08/21 15:59:00 | 000,000,828 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Wise Registry Cleaner.lnk
[2010/08/21 15:53:44 | 004,143,168 | —- | M] (WiseCleaner.com ) – D:\Documents and Settings\Administrator\Desktop\WRCFree.exe
[2010/08/21 15:48:09 | 000,000,435 | —- | M] () – D:\WINDOWS\system.ini
[2010/08/21 15:48:09 | 000,000,076 | —- | M] () – D:\WINDOWS\win.ini
[2010/08/21 15:36:06 | 000,113,536 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3.sfk
[2010/08/21 15:32:53 | 000,026,992 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.sfk
[2010/08/21 14:56:36 | 003,293,587 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3
[2010/08/21 13:56:38 | 013,787,180 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.wav
[2010/08/21 13:56:38 | 000,026,992 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0.sfk
[2010/08/21 13:56:26 | 013,787,208 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0
[2010/08/21 13:56:10 | 002,502,220 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3
[2010/08/19 22:49:22 | 000,002,028 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\Ubisoft Product Registration.lnk
[2010/08/19 22:44:48 | 000,001,861 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Play Prince of Persia The Sands of Time.lnk
[2010/08/19 21:07:31 | 000,000,696 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/19 12:45:24 | 000,002,184 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2010/08/10 17:47:14 | 013,601,485 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\07 Destroy techno.mp3
[2010/08/10 17:47:13 | 013,664,295 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\06 Passing by.mp3
[2010/08/10 17:46:58 | 013,147,126 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Rusted nuts & bolts.mp3
[2010/08/10 17:46:53 | 013,016,260 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\03 Gucci.mp3
[2010/08/10 17:44:30 | 010,521,440 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Tymon & Negative A - Metaphysical.mp3
[2010/08/10 17:33:00 | 015,984,225 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\TYMON & ANDRE FRAUENSTEIN - ETHEREAL.mp3
[2010/08/10 17:32:33 | 014,700,717 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_-_Void_FINAL.mp3
[2010/08/10 17:29:18 | 013,324,606 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_+_Stormtrooper_-_Hurricane_FINAL.mp3
[2010/08/10 17:27:50 | 012,467,764 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\tymon - stay.mp3
[2010/08/10 17:27:16 | 012,930,643 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\rattle brain.mp3
[2010/08/10 17:26:04 | 011,011,189 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\tymon - nonlinear dynamics (MASTER).mp3
[2010/08/10 16:21:39 | 004,161,177 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2 copy.jpg
[2010/08/10 16:21:05 | 006,236,028 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1 copy.jpg
[2010/08/10 16:08:02 | 064,540,362 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2.psd
[2010/08/10 15:53:11 | 043,512,968 | —- | M] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1.psd
[2010/07/30 15:51:16 | 000,318,904 | —- | M] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\wmpfirefoxplugin.exe
[2010/07/29 21:41:25 | 001,382,454 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\0pp5hv50.bmp
[2010/07/29 21:40:38 | 000,826,614 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\axo9093y.bmp
[2010/07/29 21:18:59 | 000,307,254 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\y0w8s9le.bmp
[2010/07/29 11:57:11 | 000,002,404 | —- | M] () – D:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/28 19:28:39 | 000,000,000 | -H– | M] () – D:\WINDOWS\System32\drivers\Msft_Kernel_xusb21_01007.Wdf
[2010/07/28 19:28:37 | 000,000,000 | -H– | M] () – D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/07/28 19:27:43 | 007,515,000 | —- | M] (Microsoft Corporation) – D:\Documents and Settings\Administrator\Desktop\Xbox360_32Eng.exe
[2010/07/26 01:09:47 | 000,134,208 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\IMG_26072010_010708.png
[2010/07/26 01:09:12 | 001,094,502 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\c9d1pb0d.bmp
[2010/07/26 01:07:25 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\nnosnpqz.bmp
[2010/07/26 01:07:17 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\04rxher6.bmp
[2010/07/26 01:06:55 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\acq18sqw.bmp
[2010/07/26 01:06:00 | 000,968,870 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\05xf3kqa.bmp
[2010/07/26 01:03:29 | 000,215,254 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\orula13r.bmp
[2010/07/26 01:03:19 | 001,166,454 | —- | M] () – D:\Documents and Settings\Administrator\My Documents\bmg814ud.bmp

========== Files Created - No Company Name ==========

[2010/08/22 13:47:49 | 000,359,929 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\dds.scr
[2010/08/22 01:37:39 | 003,589,293 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite_11.mp3
[2010/08/21 23:37:14 | 003,589,293 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\bucketoshiteproto.mp3
[2010/08/21 21:44:21 | 060,388,522 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\BRUNCHTRACK.mp3
[2010/08/21 16:06:23 | 000,000,000 | -H– | C] () – D:\Documents and Settings\Administrator\NTUSER.rhk.LOG
[2010/08/21 15:59:00 | 000,001,714 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Clear with 1 click.lnk
[2010/08/21 15:59:00 | 000,000,846 | —- | C] () – D:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Registry Cleaner.lnk
[2010/08/21 15:59:00 | 000,000,828 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Wise Registry Cleaner.lnk
[2010/08/21 15:35:13 | 000,113,536 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3.sfk
[2010/08/21 14:56:15 | 003,293,587 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\bucketoshite.mp3
[2010/08/21 13:56:38 | 013,787,180 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.wav
[2010/08/21 13:56:38 | 000,026,992 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.sfk
[2010/08/21 13:56:27 | 000,026,992 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0.sfk
[2010/08/21 13:56:26 | 013,787,208 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3.sfap0
[2010/08/21 13:56:08 | 002,502,220 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\shite.mp3
[2010/08/19 22:49:22 | 000,002,028 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\Ubisoft Product Registration.lnk
[2010/08/19 22:49:07 | 000,069,632 | —- | C] () – D:\WINDOWS\System32\xmltok.dll
[2010/08/19 22:49:07 | 000,036,864 | —- | C] () – D:\WINDOWS\System32\xmlparse.dll
[2010/08/19 22:49:07 | 000,035,840 | —- | C] () – D:\WINDOWS\System32\comdlg32.oca
[2010/08/19 22:49:06 | 000,029,184 | —- | C] () – D:\WINDOWS\System32\MSINET.oca
[2010/08/19 22:44:48 | 000,001,861 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Play Prince of Persia The Sands of Time.lnk
[2010/08/19 21:07:31 | 000,000,696 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/19 16:53:06 | 000,784,896 | —- | C] () – D:\WINDOWS\System32\drivers\pqckz.sys
[2010/08/10 17:30:13 | 010,521,440 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Tymon & Negative A - Metaphysical.mp3
[2010/08/10 17:30:10 | 013,147,126 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Rusted nuts & bolts.mp3
[2010/08/10 17:30:04 | 013,601,485 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\07 Destroy techno.mp3
[2010/08/10 17:30:01 | 013,664,295 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\06 Passing by.mp3
[2010/08/10 17:29:58 | 013,016,260 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\03 Gucci.mp3
[2010/08/10 17:10:43 | 013,324,606 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_+_Stormtrooper_-_Hurricane_FINAL.mp3
[2010/08/10 17:10:40 | 014,700,717 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\Tymon_+_Waldhaus_-_Void_FINAL.mp3
[2010/08/10 17:10:26 | 015,984,225 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\TYMON & ANDRE FRAUENSTEIN - ETHEREAL.mp3
[2010/08/10 17:10:13 | 012,467,764 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\tymon - stay.mp3
[2010/08/10 17:10:08 | 011,011,189 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\tymon - nonlinear dynamics (MASTER).mp3
[2010/08/10 17:10:04 | 012,930,643 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\rattle brain.mp3
[2010/08/10 16:21:35 | 004,161,177 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2 copy.jpg
[2010/08/10 16:20:53 | 006,236,028 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1 copy.jpg
[2010/08/10 16:07:59 | 064,540,362 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER2.psd
[2010/08/10 15:53:08 | 043,512,968 | —- | C] () – D:\Documents and Settings\Administrator\Desktop\ARCADEFLYER1.psd
[2010/07/29 21:40:08 | 001,382,454 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\0pp5hv50.bmp
[2010/07/29 21:39:42 | 000,826,614 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\axo9093y.bmp
[2010/07/29 21:18:33 | 000,307,254 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\y0w8s9le.bmp
[2010/07/28 19:28:39 | 000,000,000 | -H– | C] () – D:\WINDOWS\System32\drivers\Msft_Kernel_xusb21_01007.Wdf
[2010/07/28 19:28:37 | 000,000,000 | -H– | C] () – D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/07/26 01:09:41 | 000,134,208 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\IMG_26072010_010708.png
[2010/07/26 01:08:36 | 001,094,502 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\c9d1pb0d.bmp
[2010/07/26 01:06:10 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\nnosnpqz.bmp
[2010/07/26 01:06:05 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\04rxher6.bmp
[2010/07/26 01:05:37 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\acq18sqw.bmp
[2010/07/26 01:05:18 | 000,968,870 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\05xf3kqa.bmp
[2010/07/26 01:03:19 | 000,215,254 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\orula13r.bmp
[2010/07/26 01:01:56 | 001,166,454 | —- | C] () – D:\Documents and Settings\Administrator\My Documents\bmg814ud.bmp
[2010/06/13 14:48:14 | 000,000,130 | —- | C] () – D:\WINDOWS\wininit.ini
[2010/03/24 17:53:49 | 000,322,248 | —- | C] () – D:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/03/08 13:34:40 | 000,354,816 | —- | C] () – D:\WINDOWS\System32\psisdecd.dll
[2010/03/01 15:09:40 | 000,000,116 | —- | C] () – D:\WINDOWS\NeroDigital.ini
[2010/02/23 14:44:52 | 000,000,474 | —- | C] () – D:\WINDOWS\kaillera.ini
[2010/02/13 19:40:03 | 000,462,848 | —- | C] () – D:\WINDOWS\System32\lame_enc.dll
[2010/02/13 19:28:35 | 000,005,810 | —- | C] () – D:\WINDOWS\System32\drivers\ASACPI.sys
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – D:\WINDOWS\System32\xlive.dll.cat
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – D:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelFrench.dll
[2008/05/06 13:00:00 | 000,000,287 | —- | C] () – D:\WINDOWS\System32\Oeminfo.ini
[2006/11/10 14:08:50 | 000,024,064 | —- | C] () – D:\WINDOWS\System32\drivers\ATITool.sys
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – D:\WINDOWS\System32\giveio.sys
< End of report >


I will run this for a while and see how things go, see if the internet drops…….. There certainly seems to be a shedload LESS traffic going to and fro. Hopefully this will have fixed the disconnection issue too ??

Thanks so much for your help so far :-)
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
go into task manager (Ctrl + Alt + Delete) look for processes PEV.exe, SED.exe, GREP.exe, CFxxx.exe if they are there > end process. delete the copy of combofix that you have on your desktop and download a fresh copy make certain your security programs are totally disabled or they will interfere. then reboot into safe mode (tap F8 upon reboot until an advanced menu appears > arrow up to safe mode) then run ComboFix in safe mode, make sure you reboot back into safe mode once the scanning is complete and if it auto reboots, so it can produce a log
Right, combofix is 'preparing to run' for the last 20 minutes :-s should it take this long ?? I'm running it in safe mode etc, redownloaded it - no error this time but as I say it's just hanging on the blue dos screen that says : Please wait. ComboFix is preparing to run. _ Nothing's happening, though, and there doesn't appear to be any hard drive activity. How long should I leave this ?
Also I have noticed that I am no longer able to access my steam client, it is running in the task manager but there is no steam logo in the taskbar and if I end the process then relaunch from the start menu it goes into the same state - task manager says it's running but it doesn't open :-s Could this have been affected by the tools I've used ? I've re-installed it and it's done the exact same thing :-o
more likely the infection causing issues.

let's try renaming combofix

delete the copy you have on your desktop

download a fresh copy and rename it to combo.com before saving it to your desktop.

make sure extensions are showing or you will end up with combo.com.exe


  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Click Apply, and then click OK.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI