This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

>Slow to start, It takes forever to boot

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:18:11 PM, on 8/14/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Systweak Memory Optimizer] c:\program files\advanced system optimizer\memtuneup.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/The%20Clumsy's/Images/stg_drm.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1223437391171
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1223437425703
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Mystery P.I. - The New York Fortune\Images\armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

–
End of file - 5089 bytes
Hi poohlet2,

Sorry for the delay!

:welcome:

My name is NightWizard and I will be your helper. :)

While I go through your log, I would very much appreciate it if you read the following.

  • I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
  • If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
  • Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
  • Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.

Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.



Thanks for choosing WhatTheTech and I will be back with a fix shortly! :)


-NightWizard
Hi poohlet2,

Please do the following scans and post the requested logs:

1. OTL Custom Scan:
Please download OTL from one of the following links
  • LINK 1
  • LINK 2
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in;

    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.



2. GMER Scan:
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



In your next reply please include:

  • The 2 OTL logs.
  • The GMER log.

Cheers
OTL logfile created on: 8/22/2010 6:37:00 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Gene\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 10.69 Gb Free Space | 28.68% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LAPTOPGENE
Current User Name: Gene
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/08/22 18:34:41 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gene\My Documents\Downloads\OTL.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2008/05/26 22:19:14 | 000,123,904 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2007/06/22 11:56:22 | 000,119,024 | —- | M] (Systweak Inc) – C:\Program Files\Advanced System Optimizer\memtuneup.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/08/22 18:34:41 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gene\My Documents\Downloads\OTL.exe
MOD - [2006/08/25 11:45:55 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 08:00:00 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - File not found [On_Demand | Stopped] – C:\WINDOWS\System32\appmgmts.dll – (AppMgmt)
SRV - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2009/06/03 08:46:36 | 000,092,008 | —- | M] (TomTom) [Disabled | Stopped] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2007/11/06 16:22:26 | 000,092,792 | —- | M] (CACE Technologies) [On_Demand | Stopped] – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)


========== Driver Services (SafeList) ==========

DRV - File not found [File_System | Boot | Stopped] – C:\WINDOWS\System32\DRIVERS\Lbd.sys – (Lbd)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\Gene\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2010/03/25 21:30:22 | 000,151,216 | —- | M] (Microsoft Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\MpFilter.sys – (MpFilter)
DRV - [2009/10/18 18:06:49 | 000,229,224 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\VMM.sys – (vmm)
DRV - [2008/11/25 17:18:26 | 000,008,704 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\epmntdrv.sys – (epmntdrv)
DRV - [2008/11/25 17:18:22 | 000,003,072 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\EuGdiDrv.sys – (EuGdiDrv)
DRV - [2008/02/05 01:50:44 | 000,059,960 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\VMNetSrv.sys – (VPCNetS2)
DRV - [2007/11/06 16:22:06 | 000,034,064 | —- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\npf.sys – (NPF)
DRV - [2004/08/04 21:05:20 | 000,341,760 | R— | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2004/08/04 08:00:00 | 000,040,320 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nmnt.sys – (nm)
DRV - [2004/08/03 18:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/07/08 07:02:18 | 000,067,840 | R— | M] (Texas Instruments) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\tifm21.sys – (tifm21)
DRV - [2004/06/11 07:03:27 | 001,041,536 | R— | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/06/11 07:03:27 | 000,682,624 | R— | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/06/11 07:03:27 | 000,199,552 | R— | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWICH.sys – (HSFHWICH)
DRV - [2004/04/29 10:10:06 | 000,274,688 | R— | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\camchal.sys – (CAMCHALA)
DRV - [2004/04/29 10:09:20 | 000,292,352 | R— | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\camcaud.sys – (CAMCAUD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home?AF=14542
IE - HKCU\..\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF;=14542"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - prefs.js..network.proxy.type: 2


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009/01/02 10:32:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/26 07:41:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/26 07:41:35 | 000,000,000 | —D | M]

[2009/08/02 19:28:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Mozilla\Extensions
[2009/08/02 19:28:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Mozilla\Extensions\[removed]
[2010/08/15 18:53:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Mozilla\Firefox\Profiles\ojn692dh.default\extensions
[2010/08/15 14:23:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gene\Application Data\Mozilla\Firefox\Profiles\ojn692dh.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/22 09:10:24 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/12/16 23:27:14 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/15 13:27:37 | 000,002,226 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml

O1 HOSTS File: ([2010/08/14 19:49:04 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (myBabylon English Toolbar) - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Systweak Memory Optimizer] c:\Program Files\Advanced System Optimizer\memtuneup.exe (Systweak Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/The%20Clumsy's/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3253534D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/3…980/wms9dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1223437391171 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1223437425703 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file://C:\Program Files\Mystery P.I. - The New York Fortune\Images\armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/07 22:39:27 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 90 Days ==========

[2010/08/20 21:18:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\My Documents\VIDEO_TS
[2010/08/15 19:18:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Brunhilda_spintop
[2010/08/15 18:47:45 | 000,000,000 | —D | C] – C:\Program Files\Brunhilda and the Dark Crystal
[2010/08/15 13:30:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\dvdcss
[2010/08/15 13:29:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Local Settings\Application Data\Babylon
[2010/08/15 13:28:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\vlc
[2010/08/15 13:28:26 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/08/15 13:28:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Local Settings\Application Data\myBabylon_English
[2010/08/15 13:28:03 | 000,000,000 | —D | C] – C:\Program Files\myBabylon_English
[2010/08/15 13:27:38 | 000,000,000 | —D | C] – C:\Program Files\Babylon
[2010/08/15 13:27:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Babylon
[2010/08/15 13:27:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Babylon
[2010/08/15 13:25:55 | 000,000,000 | —D | C] – C:\Program Files\VLC Player
[2010/08/14 20:54:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\MysteriousCaseOfJekyllAndHyde
[2010/08/14 20:51:33 | 000,000,000 | —D | C] – C:\Program Files\The Mysterious Case of Dr. Jekyll and Mr. Hyde
[2010/08/14 20:50:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/08/14 19:44:05 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/08/14 19:42:09 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/08/14 19:42:09 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/08/14 19:42:09 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/08/14 19:42:09 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/08/14 19:42:03 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/08/14 19:41:49 | 000,000,000 | —D | C] – C:\Qoobox
[2010/08/14 18:36:14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Gene\Recent
[2010/07/30 23:01:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Friday's games
[2010/07/17 22:26:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Legends of pirates
[2010/07/16 20:21:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\SprillBermudeEng
[2010/07/15 19:08:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\TMInc
[2010/07/13 19:33:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\BlitPop
[2010/07/08 20:49:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Floodlight Games
[2010/07/08 20:49:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Floodlight Games
[2010/07/06 20:57:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Boolat Games
[2010/06/25 21:40:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Paige Harper and the Tome of Mystery
[2010/06/24 20:33:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\VampireSaga
[2010/06/12 15:29:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\Lazy Turtle Games
[2010/06/05 21:53:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Desktop\Repair tools
[2010/06/05 21:43:25 | 000,000,000 | —D | C] – C:\Program Files\LSoft Technologies
[2010/06/05 19:44:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\InfraRecorder
[2010/06/05 19:44:07 | 000,000,000 | —D | C] – C:\Program Files\InfraRecorder
[2010/05/30 01:13:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\FlyWheelGames
[2010/05/28 21:22:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Gene\Application Data\FreezeTag
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/22 18:28:12 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C736C09E-34A4-4142-82A3-084F213952CD}.job
[2010/08/22 18:10:16 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/22 18:10:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/22 09:44:08 | 004,456,448 | —- | M] () – C:\Documents and Settings\Gene\NTUSER.DAT
[2010/08/22 09:44:08 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Gene\ntuser.ini
[2010/08/21 13:55:10 | 011,201,566 | -H– | M] () – C:\Documents and Settings\Gene\Local Settings\Application Data\IconCache.db
[2010/08/20 19:11:41 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/17 19:17:46 | 000,014,248 | —- | M] () – C:\Documents and Settings\Gene\My Documents\svchost_viewer_ver_0.3.0.0_RC1.zip
[2010/08/17 13:25:52 | 000,001,548 | —- | M] () – C:\Documents and Settings\Gene\Desktop\memtest to burn.irp
[2010/08/15 18:49:44 | 000,000,841 | —- | M] () – C:\Documents and Settings\Gene\Desktop\Brunhilda and the Dark Crystal.lnk
[2010/08/15 18:49:44 | 000,000,180 | —- | M] () – C:\Documents and Settings\Gene\Desktop\More SpinTop Games.url
[2010/08/15 13:28:48 | 000,000,667 | —- | M] () – C:\Documents and Settings\Gene\Desktop\VLC Player.lnk
[2010/08/15 13:28:42 | 000,000,816 | —- | M] () – C:\Documents and Settings\Gene\Application Data\Microsoft\Internet Explorer\Quick Launch\Babylon.lnk
[2010/08/14 20:53:59 | 000,000,987 | —- | M] () – C:\Documents and Settings\Gene\Desktop\The Mysterious Case of Dr. Jekyll and Mr. Hyde.lnk
[2010/08/14 20:11:26 | 157,026,448 | —- | M] () – C:\Documents and Settings\Gene\Desktop\BrunhildaandtheDarkCrystalSetup.exe
[2010/08/14 20:05:16 | 065,063,880 | —- | M] () – C:\Documents and Settings\Gene\Desktop\TheMysteriousCaseofDrJekyllandMrHydeSetup.exe
[2010/08/14 19:49:16 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/14 19:49:04 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/14 19:44:17 | 000,000,425 | RHS- | M] () – C:\boot.ini
[2010/08/14 19:35:29 | 003,817,397 | R— | M] () – C:\Documents and Settings\Gene\Desktop\ComboFix.exe
[2010/08/14 18:51:52 | 001,402,880 | —- | M] () – C:\Documents and Settings\Gene\Desktop\HiJackThis.msi
[2010/07/14 22:11:03 | 000,251,392 | —- | M] () – C:\Documents and Settings\Gene\Desktop\Graduate Survey.doc
[2010/06/28 21:48:46 | 000,000,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/06/23 19:46:15 | 000,537,910 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/23 19:46:15 | 000,467,316 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/06/23 19:46:15 | 000,080,076 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/06/15 22:09:25 | 000,000,764 | —- | M] () – C:\Documents and Settings\Gene\Application Data\com.koingosw.MysteryIslandII.xml
[2010/06/10 07:28:58 | 000,334,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/09 08:31:38 | 000,000,063 | —- | M] () – C:\WINDOWS\vbaddin.ini
[2010/06/05 19:44:12 | 000,000,778 | —- | M] () – C:\Documents and Settings\Gene\Application Data\Microsoft\Internet Explorer\Quick Launch\InfraRecorder.lnk
[2010/06/05 19:44:12 | 000,000,760 | —- | M] () – C:\Documents and Settings\All Users\Desktop\InfraRecorder.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/20 20:52:49 | 000,014,248 | —- | C] () – C:\Documents and Settings\Gene\My Documents\svchost_viewer_ver_0.3.0.0_RC1.zip
[2010/08/17 13:25:51 | 000,001,548 | —- | C] () – C:\Documents and Settings\Gene\Desktop\memtest to burn.irp
[2010/08/15 18:49:44 | 000,000,841 | —- | C] () – C:\Documents and Settings\Gene\Desktop\Brunhilda and the Dark Crystal.lnk
[2010/08/15 13:28:48 | 000,000,667 | —- | C] () – C:\Documents and Settings\Gene\Desktop\VLC Player.lnk
[2010/08/15 13:28:42 | 000,000,816 | —- | C] () – C:\Documents and Settings\Gene\Application Data\Microsoft\Internet Explorer\Quick Launch\Babylon.lnk
[2010/08/14 20:53:59 | 000,000,987 | —- | C] () – C:\Documents and Settings\Gene\Desktop\The Mysterious Case of Dr. Jekyll and Mr. Hyde.lnk
[2010/08/14 20:11:26 | 157,026,448 | —- | C] () – C:\Documents and Settings\Gene\Desktop\BrunhildaandtheDarkCrystalSetup.exe
[2010/08/14 20:05:23 | 065,063,880 | —- | C] () – C:\Documents and Settings\Gene\Desktop\TheMysteriousCaseofDrJekyllandMrHydeSetup.exe
[2010/08/14 19:44:13 | 000,260,272 | —- | C] () – C:\cmldr
[2010/08/14 19:42:09 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/08/14 19:42:09 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/08/14 19:42:09 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/08/14 19:42:09 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/08/14 19:42:09 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/08/14 19:35:19 | 003,817,397 | R— | C] () – C:\Documents and Settings\Gene\Desktop\ComboFix.exe
[2010/08/14 18:51:52 | 001,402,880 | —- | C] () – C:\Documents and Settings\Gene\Desktop\HiJackThis.msi
[2010/07/14 22:11:02 | 000,251,392 | —- | C] () – C:\Documents and Settings\Gene\Desktop\Graduate Survey.doc
[2010/06/15 21:58:27 | 000,000,764 | —- | C] () – C:\Documents and Settings\Gene\Application Data\com.koingosw.MysteryIslandII.xml
[2010/06/05 19:44:12 | 000,000,778 | —- | C] () – C:\Documents and Settings\Gene\Application Data\Microsoft\Internet Explorer\Quick Launch\InfraRecorder.lnk
[2010/06/05 19:44:12 | 000,000,760 | —- | C] () – C:\Documents and Settings\All Users\Desktop\InfraRecorder.lnk
[2009/04/26 22:40:41 | 000,000,011 | —- | C] () – C:\WINDOWS\EuBcd.ini
[2009/03/23 19:44:28 | 000,472,064 | —- | C] () – C:\WINDOWS\System32\NTFSFormat.dll
[2009/03/23 19:44:28 | 000,139,776 | —- | C] () – C:\WINDOWS\System32\NTFSCopy.dll
[2009/03/23 19:44:28 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\Partition.dll
[2009/03/23 19:44:28 | 000,086,528 | —- | C] () – C:\WINDOWS\System32\NTFSLib.dll
[2009/03/23 19:44:28 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ResizeNTFS.dll
[2009/03/23 19:44:28 | 000,061,952 | —- | C] () – C:\WINDOWS\System32\FatResizeMove.dll
[2009/03/23 19:44:28 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\FileSystemCheck.dll
[2009/03/23 19:44:28 | 000,031,744 | —- | C] () – C:\WINDOWS\System32\FatLib.dll
[2009/03/23 19:44:28 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\NTFSFileSystemAnalyser.dll
[2009/03/23 19:44:28 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\FatFormat.dll
[2009/03/23 19:44:28 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\Fixup.dll
[2009/03/23 19:44:28 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\SectorCopy.dll
[2009/03/23 19:44:28 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\FileSystemAnalyser.dll
[2009/03/23 19:44:27 | 000,180,736 | —- | C] () – C:\WINDOWS\System32\DeviceManager.dll
[2009/03/23 19:44:27 | 000,068,096 | —- | C] () – C:\WINDOWS\System32\Device.dll
[2009/03/23 19:44:27 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\FatCopy.dll
[2009/03/23 19:44:27 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\FATFileSystemAnalyser.dll
[2009/03/23 19:44:27 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2009/03/23 19:44:27 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\DeviceAdapter.dll
[2009/03/23 19:44:27 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2009/03/23 19:44:27 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\CallbackOperator.dll
[2009/03/23 19:44:27 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2009/03/23 12:53:29 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\msblcd32.dll
[2009/01/27 23:56:19 | 000,000,100 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/12/11 17:47:35 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/28 21:36:01 | 000,000,023 | —- | C] () – C:\WINDOWS\.ini
[2008/10/28 21:14:29 | 000,005,632 | —- | C] () – C:\Documents and Settings\Gene\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/09 11:59:35 | 000,000,074 | —- | C] () – C:\Documents and Settings\Gene\Application Data\evplay.prf
[2008/10/09 11:23:29 | 000,000,165 | —- | C] () – C:\WINDOWS\startUp manager.INI
[2007/11/06 16:19:28 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2002/06/10 17:34:34 | 001,310,720 | —- | C] () – C:\WINDOWS\System32\Veceng52.dll
[2002/06/10 17:29:42 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\arrgrid.dll
[2002/05/21 15:29:58 | 000,245,760 | —- | C] () – C:\WINDOWS\System32\bmw.dll

========== LOP Check ==========

[2009/06/23 13:09:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2010/08/15 13:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Babylon
[2010/07/13 19:33:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BlitPop
[2009/09/06 10:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2009/05/05 11:09:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2010/05/11 21:59:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Deadtime Stories
[2009/06/23 18:49:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2009/06/20 15:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2010/07/08 20:49:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Floodlight Games
[2009/06/20 08:27:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FloodLightGames
[2009/06/22 16:01:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/12/06 00:23:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gamers Digital
[2010/08/06 23:07:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii
[2009/06/21 19:04:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii Games
[2009/07/26 14:51:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hitpointstudios
[2009/06/17 09:25:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HoverBee Studios
[2010/07/07 01:25:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intenium
[2010/03/15 17:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2009/12/20 18:07:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/07/17 23:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mushroom Age
[2009/08/26 20:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/06/24 14:53:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NeptunesAdve
[2009/08/09 18:21:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/06/16 01:24:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayPond
[2009/07/25 19:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/07/04 12:02:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2009/06/17 06:02:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTopV1005
[2009/06/16 02:25:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SugarGames
[2010/08/10 19:44:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/01/31 00:54:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\The Mirror Mysteries
[2009/07/16 20:38:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TheRace_dev
[2009/08/04 19:17:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/05/09 18:40:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Try2
[2009/06/24 17:55:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Alawar
[2010/08/15 13:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Babylon
[2009/06/23 17:15:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\BloodTies
[2010/07/06 20:57:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Boolat Games
[2010/05/10 21:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Boomzap
[2010/08/15 19:19:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Brunhilda_spintop
[2009/08/30 18:25:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\CallingID
[2009/07/04 09:27:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\cerasus.media
[2009/06/20 15:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Flood Light Games
[2010/07/08 20:49:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Floodlight Games
[2009/06/20 08:27:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\FloodLightGames
[2010/05/30 01:13:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\FlyWheelGames
[2010/06/07 22:00:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\FreezeTag
[2010/07/30 23:01:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Friday's games
[2010/05/11 10:38:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Fugazo
[2010/06/21 19:27:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\funkitron
[2009/12/06 00:23:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Gamers Digital
[2009/06/21 19:04:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Gogii Games
[2010/06/05 20:03:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\InfraRecorder
[2009/08/09 19:17:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\IronCode
[2009/06/01 19:34:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\iWin
[2010/06/12 15:29:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Lazy Turtle Games
[2010/07/17 22:49:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Legends of pirates
[2009/01/01 12:01:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\LimeWire
[2009/06/27 23:48:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\MagicBall4
[2010/08/14 20:54:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\MysteriousCaseOfJekyllAndHyde
[2010/05/08 04:28:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Nevosoft Games
[2010/06/25 21:58:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Paige Harper and the Tome of Mystery
[2009/08/09 18:21:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\PlayFirst
[2009/06/13 01:33:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Playrix Entertainment
[2009/02/14 17:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\RapidTyping
[2009/06/14 04:11:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Righteous Kill
[2009/06/16 08:38:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\RobinsonCrusoeOM
[2010/05/16 15:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Silverback Productions
[2009/06/10 17:04:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\SpinTop
[2010/05/28 21:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\SpinTop Games
[2010/07/16 20:21:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\SprillBermudeEng
[2008/10/07 23:21:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Systweak
[2009/12/06 17:33:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\TitanicMystery
[2010/07/15 19:08:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\TMInc
[2009/08/02 19:28:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\TomTom
[2010/05/09 18:40:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Try2
[2010/04/14 03:56:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Uniblue
[2010/06/24 20:33:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\VampireSaga
[2009/07/29 22:13:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Windows Desktop Search
[2009/12/20 17:59:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Windows Search
[2008/10/14 22:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Gene\Application Data\Wireshark
[2010/08/22 18:43:00 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C736C09E-34A4-4142-82A3-084F213952CD}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/09/06 10:39:10 | 000,065,997 | —- | M] () – C:\aaw7boot.log
[2008/10/07 22:39:27 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/11 23:28:04 | 000,076,272 | —- | M] () – C:\bar.emf
[2009/11/04 21:15:58 | 000,000,355 | —- | M] () – C:\Boot.bak
[2010/08/14 19:44:17 | 000,000,425 | RHS- | M] () – C:\boot.ini
[2006/11/02 05:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2009/03/24 01:06:35 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2008/10/07 22:58:01 | 000,036,053 | —- | M] () – C:\caavsetupLog.txt
[2009/09/06 10:42:31 | 000,906,532 | —- | M] () – C:\caisslog.txt
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/08/14 19:52:33 | 000,008,920 | —- | M] () – C:\ComboFix.txt
[2008/10/07 22:39:27 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/03/17 07:41:22 | 000,171,136 | RHS- | M] () – C:\grldr
[2008/10/28 21:12:36 | 000,000,217 | —- | M] () – C:\INSTALL.LOG
[2008/10/07 22:39:27 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/16 20:34:06 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2010/08/20 21:08:45 | 000,021,607 | —- | M] () – C:\mcdbp.log
[2008/10/07 22:39:27 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 08:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/08/22 18:10:01 | 754,974,720 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/10/07 22:38:47 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/10/07 18:24:49 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/10/07 18:24:49 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/10/07 18:24:49 | 000,880,640 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2007/03/08 11:36:28 | 000,577,536 | —- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 – C:\WINDOWS\system32\user32.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/04 08:00:00 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\system32\ws2_32.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/04 08:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\system32\ws2help.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-13 12:06:05

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0084EC0C
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2C22C34B
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4C255337
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1C94526F
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E667B1E3
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3E01678
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9E9BA8D0
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:179D1352
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B2AAF611
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:88B0DDFD
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B7F2E188
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:302D4BF4
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:41EEBD4F
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93AD83DB
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8C08E7E
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BC82B99A
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B30D9A49
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A4E01E1F
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A79F77B
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2EAA80CB
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:16B7E8FC
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DAFD610F
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:337FC984
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:12922EE8
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C03F5109
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:64648EF8
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:13095727
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:851F7DE0
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F6424B89
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B2778D0
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:55F37770
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FD537E5A
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:814692DF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9E00596C
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4CF2A6CC
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:264DE5E7
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4A7C296A
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:41B3EF33
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CE0AE44
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A1165550
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8F09BC2E
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F822B7ED
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CAB5D296
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9B27D3A9
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:53500A7C
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:19FFCB77
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F1E651F6
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D8055233
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8807C278
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3C77A608
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CBAB7F7
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C60A173
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F1C0B203
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3E69E337
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F5096B56
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:688A9637
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B746464
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8BB2EC84
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:15FBBE31
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA17833A
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EB825D08
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:77A023CE
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3325D6E9
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7F24D3D8
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D71580D
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5A99DEB7
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D650D56C
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:67C9F690
< End of report >

OTL Extras logfile created on: 8/22/2010 6:37:00 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Gene\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 10.69 Gb Free Space | 28.68% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LAPTOPGENE
Current User Name: Gene
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Documents and Settings\Gene\My Documents\Downloads\vlc_setup.exe" = C:\Documents and Settings\Gene\My Documents\Downloads\vlc_setup.exe:*:Enabled:VLC Media Player – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1CD0C3C5-809D-4CFC-904A-1B67C6243637}" = Debugging Tools for Windows (x86)
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24BEAAF1-DD65-41D3-80A1-23BEA03A84FD}" = A+ 2006 601 and 602 Premium Total Tester
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{634F6989-4BB5-4EF2-AF6F-C15700F81494}}_is1" = Advanced System Optimizer
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A9C89180-E3B6-4451-A788-0BDC8A5EF34A}_is1" = class paperwork
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{B27901FA-F157-4049-B1EC-BC43890A1DCC}" = Active@ File Recovery
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Brunhilda and the Dark Crystal" = Brunhilda and the Dark Crystal
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_8086&DEV;_24C6&SUBSYS;_3080103C" = SoftV92 Data Fax Modem with SmartCP
"Conexant PCI Audio" = Conexant AC-Link Audio
"EASEUS Partition Manager Home Edition_is1" = EASEUS Partition Manager 3.0 Home Edition
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ExamView Player" = ExamView Player
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InfraRecorder" = InfraRecorder
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"myBabylon_English Toolbar" = myBabylon English Toolbar
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PokerStars.net" = PokerStars.net
"RapidTyping" = RapidTyping
"RealPlayer 6.0" = RealPlayer
"The Mysterious Case of Dr. Jekyll and Mr. Hyde" = The Mysterious Case of Dr. Jekyll and Mr. Hyde
"TomTom HOME" = TomTom HOME 2.6.4.1641
"VectorEngineer Quick-Tools" = VectorEngineer Quick-Tools
"VISPRO" = Microsoft Office Visio Professional 2007
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinPcapInst" = WinPcap 4.0.2
"Wireshark" = Wireshark 1.0.3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/13/2010 9:15:57 PM | Computer Name = LAPTOPGENE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 7/14/2010 10:11:25 PM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 | ID = 5000
Description = EventType officelifeboathang, P1 winword.exe, P2 12.0.6535.5000, P3
ntdll.dll, P4 5.1.2600.3520, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

Error - 8/12/2010 7:33:32 PM | Computer Name = LAPTOPGENE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/12/2010 7:33:32 PM | Computer Name = LAPTOPGENE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/15/2010 1:19:45 PM | Computer Name = LAPTOPGENE | Source = Application Error | ID = 1000
Description = Faulting application infrarecorder.exe, version 0.50.0.0, faulting
module unknown, version 0.0.0.0, fault address 0x00c601bf.

Error - 8/15/2010 1:19:50 PM | Computer Name = LAPTOPGENE | Source = Application Error | ID = 1001
Description = Fault bucket 1995298311.

Error - 8/20/2010 8:20:46 PM | Computer Name = LAPTOPGENE | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/20/2010 8:20:52 PM | Computer Name = LAPTOPGENE | Source = Application Hang | ID = 1001
Description = Fault bucket 452615105.

Error - 8/20/2010 9:16:52 PM | Computer Name = LAPTOPGENE | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/20/2010 9:16:53 PM | Computer Name = LAPTOPGENE | Source = Application Hang | ID = 1001
Description = Fault bucket 126648864.

[ OSession Events ]
Error - 6/15/2009 8:08:13 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:16 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:19 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 58
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:22 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:26 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 8
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:31 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:36 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:41 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 25
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/15/2009 8:08:59 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 23
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/20/2009 6:54:43 AM | Computer Name = LAPTOPGENE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 26
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 8/20/2010 9:16:48 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 8/20/2010 9:16:48 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 8/20/2010 9:16:48 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 8/20/2010 9:16:48 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 8/20/2010 9:53:54 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 8/20/2010 11:05:41 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 8/21/2010 1:40:34 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 8/21/2010 2:11:31 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 8/22/2010 8:59:14 AM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 8/22/2010 6:10:33 PM | Computer Name = LAPTOPGENE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd


< End of report >

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-22 21:52:58
Windows 5.1.2600 Service Pack 2
Running: 26i2zhy3.exe; Driver: C:\DOCUME~1\Gene\LOCALS~1\Temp\uxdyraow.sys


—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\tifm21.sys entry point in "init" section [0xB98DCF00]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\SearchIndexer.exe[388] kernel32.dll!WriteFile 7C810D97 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
Hi poohlet2,


Please work your way through the following:


1. OTL FIX
———————————

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    FF - prefs.js..network.proxy.type: 2
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found
    O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found
    O16 - DPF: {3253534D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/3…980/wms9dmo.cab (Reg Error: Key error.)
    O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB (Reg Error: Key error.)
    
    :Files
    
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • After rebooting, please post the OTL you are presented with on startup.


2. MALWAREBYTES SCAN
———————————————-

Please launch Malwarebytes Anti-malware.
  • Once the program has loaded click the "Update taband then "Check for Updates" if any are found they will be downloaded. When prompted click Ok to install the updates.
  • After updating navigate to the main menu and check Perform Full Scan, then click Scan.
    The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.


3. COMBOFIX LOG
———————————————-

I see you have previously ran Combofix, I would like to take a look at the log to see if anything was removed or if it can reveal anything else.

Please click Start > My Computer > C drive and open "ComboFix.txt" and paste the contents in your next reply.


In your next reply please include:
  • The OTL log.
  • The MBAM log.
  • The Combofix log.
Cheers! :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI