This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Arggh! Google redirects are driving me batty!

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having problems with being re-directed to other random websites every time I try to use google! I went through all the steps listed under the Removal Instructions you had listed, rebooted and still no dice. I did all the other scans you requested and will post the results. Any help will be great! I am not so computer savvy as you can probably already see….or I would not be infected! :) I am not sure which scans you are looking for, so here is the OTL logfile. If you need the other 2 I can add them later! Thank you!

OTL logfile created on: 13/09/2010 8:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Users\Lucky 13\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 179.50 Gb Total Space | 124.53 Gb Free Space | 69.37% Space Free | Partition Type: NTFS
Drive D: | 1011.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 275.70 Gb Free Space | 29.60% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LUCKY13-PC
Current User Name: Lucky 13
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Lucky 13\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
PRC - C:\Program Files\Novatel Wireless\NovaCore\Server\NvtlSrvr.exe ()
PRC - C:\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Java\jre1.6.0\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Lucky 13\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.20533_none_4634c4a0218d65c1\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (SBSDWSCService) – C:\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)


========== Driver Services (SafeList) ==========

DRV - (TpChoice) – C:\Windows\System32\DRIVERS\TpChoice.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (NuidFltr) – C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\Windows\System32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\Windows\System32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\Windows\System32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWUSBCDFIL) – C:\Windows\System32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (BRCMDECO) – C:\Windows\System32\drivers\BRCMHD32.sys (Broadcom Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (NETw4v32) Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.3
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 17:27:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 17:27:14 | 000,000,000 | —D | M]

[2010/06/23 19:20:06 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Extensions
[2010/09/12 18:25:47 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions
[2010/09/12 18:25:38 | 000,000,000 | —D | M] (NoScript) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/08/30 12:41:07 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/08/05 17:54:07 | 000,000,000 | —D | M] (No name found) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/06/23 19:19:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/09/05 15:44:04 | 000,416,890 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14390 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Adobe PDF Link Helper) - {74E41E96-1F6A-2C83-7A24-6FFA07F64C77} - C:\Windows\System32\ccmlua.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] File not found
O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [MCStart] C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [tscui] C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Lucky 13\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lucky 13\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/01/31 19:51:24 | 000,000,033 | -HS- | M] () - F:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{993fd453-7f2e-11df-b206-001b384af900}\Shell - "" = AutoRun
O33 - MountPoints2\{993fd453-7f2e-11df-b206-001b384af900}\Shell\AutoRun\command - "" = E:\AutoLaunch.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/09/09 17:25:53 | 000,000,000 | —D | C] – C:\Program Files\Golden Trails - The New Western Rush2
[2010/09/09 17:14:39 | 000,000,000 | —D | C] – C:\ProgramData\WildWestQuest2
[2010/09/08 16:11:20 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Roaming\Awem
[2010/09/08 16:11:12 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Couple
[2010/09/08 16:08:56 | 000,000,000 | —D | C] – C:\Program Files\Golden Trails - The New Western Rush
[2010/09/08 14:18:13 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\WinZip
[2010/08/30 06:58:09 | 000,000,000 | —D | C] – C:\Spybot - Search & Destroy
[2010/08/30 06:58:09 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/30 06:49:20 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/29 19:02:35 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\Windows Server
[2010/08/21 21:16:24 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Wedding Married in Manhattan
[2010/08/19 19:04:22 | 000,000,000 | —D | C] – C:\Program Files\Games
[2010/08/18 22:14:43 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\Oberon Games
[2010/08/18 18:12:40 | 000,000,000 | —D | C] – C:\Program Files\Hide And Secret
[2010/08/18 18:10:43 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Wedding
[2010/08/16 10:54:10 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Roaming\PlayFirst
[2010/08/16 10:54:10 | 000,000,000 | —D | C] – C:\ProgramData\PlayFirst
[2010/08/16 10:53:15 | 000,000,000 | —D | C] – C:\Program Files\Mystery of Shark Island
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/13 20:40:43 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/13 20:40:43 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/13 20:37:11 | 006,029,312 | -HS- | M] () – C:\Users\Lucky 13\NTUSER.DAT
[2010/09/13 19:05:05 | 000,000,348 | —- | M] () – C:\Windows\tasks\At3.job
[2010/09/13 18:12:36 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/13 17:49:33 | 000,720,952 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/13 17:49:33 | 000,626,246 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/13 17:49:33 | 000,109,370 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/13 17:40:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | M] () – C:\hiberfil.sys
[2010/09/13 16:24:11 | 000,002,529 | —- | M] () – C:\Users\Lucky 13\Desktop\HiJackThis.lnk
[2010/09/13 16:11:40 | 000,007,647 | —- | M] () – C:\Users\Lucky 13\Desktop\hijackthis3
[2010/09/13 16:09:08 | 327,113,461 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/09/13 13:21:11 | 000,000,348 | —- | M] () – C:\Windows\tasks\At2.job
[2010/09/13 01:28:08 | 000,000,348 | —- | M] () – C:\Windows\tasks\At4.job
[2010/09/10 07:49:05 | 000,000,348 | —- | M] () – C:\Windows\tasks\At1.job
[2010/09/09 23:49:52 | 000,043,008 | —- | M] () – C:\Users\Lucky 13\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/09 17:26:53 | 000,001,970 | —- | M] () – C:\Users\Lucky 13\Desktop\Golden Trails - The New Western Rush.lnk
[2010/09/09 17:13:08 | 000,001,920 | —- | M] () – C:\Users\Lucky 13\Desktop\Wild West Quest 2.lnk
[2010/09/08 14:11:42 | 000,000,913 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding.lnk
[2010/09/05 15:44:04 | 000,416,890 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/09/05 09:42:02 | 000,002,069 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding 6 Bella Italia.lnk
[2010/08/30 08:15:20 | 000,000,875 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100830-082415.backup
[2010/08/30 08:14:26 | 000,416,917 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100830-081520.backup
[2010/08/30 08:09:59 | 000,000,680 | —- | M] () – C:\Users\Lucky 13\AppData\Local\d3d9caps.dat
[2010/08/30 08:07:32 | 000,000,552 | —- | M] () – C:\Users\Lucky 13\AppData\Local\d3d8caps.dat
[2010/08/30 06:58:20 | 000,000,820 | —- | M] () – C:\Users\Lucky 13\Desktop\Spybot - Search & Destroy.lnk
[2010/08/26 07:14:43 | 005,316,736 | —- | M] () – C:\Users\Lucky 13\Desktop\The Chakachas - Jungle Fever.- DJ Luis Mario 'Flaco' Orellana.mp3
[2010/08/22 17:59:52 | 000,001,185 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Married in Manhattan - Shortcut.lnk
[2010/08/19 19:04:59 | 000,002,066 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Viva Las Vegas.lnk
[2010/08/18 18:18:04 | 000,001,999 | —- | M] () – C:\Users\Public\Desktop\Private Eye - Greatest Unsolved Mysteries.lnk
[2010/08/18 18:18:04 | 000,001,536 | —- | M] () – C:\Users\Public\Desktop\More great games.lnk
[2010/08/16 09:53:40 | 000,000,949 | —- | M] () – C:\Users\Lucky 13\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/13 17:40:31 | 2137,448,448 | -HS- | C] () – C:\hiberfil.sys
[2010/09/13 16:11:40 | 000,007,647 | —- | C] () – C:\Users\Lucky 13\Desktop\hijackthis3
[2010/09/09 17:26:53 | 000,001,970 | —- | C] () – C:\Users\Lucky 13\Desktop\Golden Trails - The New Western Rush.lnk
[2010/09/09 17:13:08 | 000,001,920 | —- | C] () – C:\Users\Lucky 13\Desktop\Wild West Quest 2.lnk
[2010/09/08 14:11:42 | 000,000,913 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding.lnk
[2010/08/30 13:24:02 | 000,002,069 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding 6 Bella Italia.lnk
[2010/08/30 13:23:13 | 000,000,348 | —- | C] () – C:\Windows\tasks\At4.job
[2010/08/30 13:23:12 | 000,000,348 | —- | C] () – C:\Windows\tasks\At3.job
[2010/08/30 13:23:10 | 000,000,348 | —- | C] () – C:\Windows\tasks\At2.job
[2010/08/30 13:23:05 | 000,000,348 | —- | C] () – C:\Windows\tasks\At1.job
[2010/08/30 08:09:59 | 000,000,680 | —- | C] () – C:\Users\Lucky 13\AppData\Local\d3d9caps.dat
[2010/08/30 08:07:32 | 000,000,552 | —- | C] () – C:\Users\Lucky 13\AppData\Local\d3d8caps.dat
[2010/08/30 06:58:20 | 000,000,820 | —- | C] () – C:\Users\Lucky 13\Desktop\Spybot - Search & Destroy.lnk
[2010/08/30 06:49:20 | 000,002,529 | —- | C] () – C:\Users\Lucky 13\Desktop\HiJackThis.lnk
[2010/08/26 06:50:44 | 005,316,736 | —- | C] () – C:\Users\Lucky 13\Desktop\The Chakachas - Jungle Fever.- DJ Luis Mario 'Flaco' Orellana.mp3
[2010/08/22 17:59:52 | 000,001,185 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Married in Manhattan - Shortcut.lnk
[2010/08/19 19:04:59 | 000,002,066 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Viva Las Vegas.lnk
[2010/08/18 18:18:04 | 000,001,999 | —- | C] () – C:\Users\Public\Desktop\Private Eye - Greatest Unsolved Mysteries.lnk
[2010/08/16 09:53:40 | 000,000,949 | —- | C] () – C:\Users\Lucky 13\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2010/08/13 11:48:09 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/08/10 16:38:50 | 000,034,308 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2010/07/08 16:50:26 | 000,043,008 | —- | C] () – C:\Users\Lucky 13\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/23 19:11:15 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2010/06/23 19:11:15 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2010/06/23 19:11:15 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2010/06/23 19:11:15 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2010/06/23 09:56:15 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2010/06/23 09:56:15 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2010/06/23 09:56:15 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2010/06/23 09:56:15 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2010/06/23 09:56:15 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2010/06/23 09:56:15 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/09/26 23:33:57 | 000,036,864 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll
[2007/09/26 23:15:57 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2007/09/26 21:57:53 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/09/26 02:25:11 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/09/26 02:25:11 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2007/09/26 02:25:11 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1329.dll
[2007/09/26 02:25:11 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/03/06 17:54:04 | 000,995,328 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2006/12/05 14:05:06 | 000,114,688 | —- | C] () – C:\Windows\System32\TosBtAcc.dll
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:57:48 | 000,180,224 | —- | C] () – C:\Windows\System32\ccmlua.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/11/23 15:55:42 | 000,024,576 | —- | C] () – C:\Windows\System32\SPCtl.dll
[2005/07/22 22:30:20 | 000,065,536 | —- | C] () – C:\Windows\System32\TosCommAPI.dll

========== LOP Check ==========

[2010/08/09 12:59:55 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Anarchy
[2010/09/08 16:11:20 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Awem
[2010/08/05 17:54:06 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/08/11 09:52:56 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\FloodLightGames
[2010/08/13 14:41:54 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Magic Academy
[2010/08/08 22:18:48 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\MysteryStudio
[2010/08/16 10:54:10 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\PlayFirst
[2010/06/23 21:28:30 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Research In Motion
[2010/09/10 07:49:05 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At1.job
[2010/09/13 13:21:11 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At2.job
[2010/09/13 19:05:05 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At3.job
[2010/09/13 01:28:08 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At4.job
[2010/09/05 15:38:32 | 000,032,480 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2006/11/02 03:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2007/09/26 17:57:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | M] () – C:\hiberfil.sys
[2010/09/13 17:40:29 | 2451,374,080 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/06/25 12:25:25 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/10 20:27:11 | 000,000,365 | -HS- | M] () – C:\Users\Lucky 13\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-03 07:36:51

========== Alternate Data Streams ==========

@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:C7F08EA3
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:317F7381
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:9E999B93
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:3B5038B1
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:5D59B736
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:E40EED9B
< End of report >

OTL Extras logfile created on: 13/09/2010 8:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Users\Lucky 13\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 179.50 Gb Total Space | 124.53 Gb Free Space | 69.37% Space Free | Partition Type: NTFS
Drive D: | 1011.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 275.70 Gb Free Space | 29.60% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LUCKY13-PC
Current User Name: Lucky 13
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{745679E8-6D91-4C36-844E-A76183D5B83E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{807AD8C1-C976-4FC0-BF4B-2158B3A28090}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{FBD8C3BD-F78C-433D-AC4D-6652F1676173}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{07BB4D84-BE7E-45ED-B145-9A474700F590}" = Mobile Broadband Generic Drivers
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{145E18EC-4BBB-4A0C-9381-564ABB871FE9}" = Mobile Connect Basic
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{65D4DAA8-3611-4322-8E69-27880AFD90EC}" = reminder
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6B9C32DB-DBCD-45A8-B901-3A92A99A2474}" = InstallVC90Support
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA HD DVD PLAYER
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{B2F3FB19-D848-479C-818E-130ABC9366DB}" = BlackBerry Device Software Updater
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B49DDCCE-BF8E-4A4C-8503-6DA24BF49D06}" = NovaCore SDK Installer
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E90C9405-DDC3-4DEB-95C8-DAAAAF69BB3E}" = Pop Art Studio 5.1
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"5 Spots II_is1" = 5 Spots II
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agatha Christie Death On The Nile_is1" = Agatha Christie Death On The Nile
"BCM70010" = Broadcom High Definition Video Decoder [removed]
"BFGC" = Big Fish Games: Game Manager
"BFG-Murder She Wrote" = Murder, She Wrote
"BFG-Redrum - Time Lies" = Redrum: Time Lies
"Big City Adventure - San Francisco" = Big City Adventure - San Francisco (remove only)
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Dream Day Couple_is1" = Dream Day Couple
"Dream Day Wedding - Viva Las Vegas 1.00" = Dream Day Wedding - Viva Las Vegas 1.00
"Dream Day Wedding 6 Bella Italia 1.00" = Dream Day Wedding 6 Bella Italia 1.00
"Dream Day Wedding Married in Manhattan" = Dream Day Wedding Married in Manhattan
"Dream Day Wedding_is1" = Dream Day Wedding
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.7
"Golden Trails - The New Western Rush_is1" = Golden Trails - The New Western Rush
"Golden Trails - The New Western Rush1.0" = Golden Trails - The New Western Rush
"HDMI" = Intel® Graphics Media Accelerator Driver
"Hide And Secret_is1" = Hide And Secret
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Magic Academy" = Magic Academy (remove only)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mirror Magic_is1" = Mirror Magic
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"Mystery Case Files - Ravenhearst" = Mystery Case Files - Ravenhearst (remove only)
"Mystery Solitaire - Secret Island" = Mystery Solitaire - Secret Island (remove only)
"OnlinePlay" = OnlinePlay 1.0
"Paparazzi" = Paparazzi (remove only)
"Private Eye - Greatest Unsolved Mysteries" = Private Eye - Greatest Unsolved Mysteries (remove only)
"PROHYBRIDR" = 2007 Microsoft Office system
"ProInst" = Intel® PROSet/Wireless Software
"REDRUM Dead Diary FINAL 1.00" = REDRUM Dead Diary FINAL 1.00
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.0
"Wild West Quest 2 1.00" = Wild West Quest 2 1.00
"Windows Media Encoder 9" = Windows Media Encoder 9 Series

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 05/09/2010 5:43:07 PM | Computer Name = Lucky13-PC | Source = EventSystem | ID = 4609
Description =

Error - 05/09/2010 5:53:18 PM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =

Error - 07/09/2010 1:19:06 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program plugin-container.exe version 1.9.2.3855 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 3594 Start Time: 01cb4d7bc77b16c0 Termination Time: 54

Error - 10/09/2010 1:55:03 AM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program CEC_MAIN.exe version 1.7.8000.182 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 12c4 Start Time: 01cb4d4410b8dc4b Termination Time: 202

Error - 10/09/2010 7:49:39 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program Andy.exe version 1.0.3827.20241 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 139fd0 Start Time: 01cb5142c0b0c220 Termination Time: 28

Error - 10/09/2010 7:49:46 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program Andy.exe version 1.0.3827.20241 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 139f8c Start Time: 01cb5142bc2baf30 Termination Time: 88

Error - 11/09/2010 1:12:06 AM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =

Error - 13/09/2010 6:09:56 PM | Computer Name = Lucky13-PC | Source = EventSystem | ID = 4609
Description =

Error - 13/09/2010 7:49:33 PM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =

Error - 13/09/2010 10:38:17 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.12.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: bbe0 Start Time: 01cb53b5b2bd9ce0 Termination Time: 7

[ System Events ]
Error - 16/07/2010 9:05:14 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.153 for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server [removed] (The DHCP Server
sent a DHCPNACK message).

Error - 17/07/2010 9:24:15 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server [removed] (The DHCP Server
sent a DHCPNACK message).

Error - 17/07/2010 9:25:07 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server 192.168.168.254 (The DHCP
Server sent a DHCPNACK message).

Error - 18/07/2010 8:36:49 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.168.124 for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 19/07/2010 5:29:45 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 19/07/2010 5:30:49 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%121. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 19/07/2010 6:42:41 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 19/07/2010 10:13:47 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 19/07/2010 10:46:54 AM | Computer Name = Lucky13-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/07/2010 10:46:54 AM | Computer Name = Lucky13-PC | Source = Service Control Manager | ID = 7009
Description =


< End of report >
Hello there, Lucky13pinupgirl

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in FIVE(5) days. :)
Hello,

Is there anything else you need to be able to help me?

Yes, I would need you to do the following in sequence. :)

Disabling Windows Defender
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)

Disabling TeaTimer

  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and click OK any prompts.
  • Restart your computer.
===================================================

1. All tools MUST be run from the executable. (.exe)
With Admin Rights (Right click, choose "Run as Administrator")


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
TDSSKiller log
GMER log

Good Day!
Ok I did the scans you requested. The Spybot came up with nothing infected. Here are the other logs you requested. I had some problems running the Gmer scan, and ran it in safemode. I am not sure if that has an effect on the outcome of the scan or not. Thank you! I look forward to your reply! :D



2010/09/14 12:08:58.0250 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44
2010/09/14 12:08:58.0250 ================================================================================
2010/09/14 12:08:58.0250 SystemInfo:
2010/09/14 12:08:58.0250
2010/09/14 12:08:58.0250 OS Version: 6.0.6000 ServicePack: 0.0
2010/09/14 12:08:58.0250 Product type: Workstation
2010/09/14 12:08:58.0250 ComputerName: LUCKY13-PC
2010/09/14 12:08:58.0251 UserName: Lucky 13
2010/09/14 12:08:58.0251 Windows directory: C:\Windows
2010/09/14 12:08:58.0251 System windows directory: C:\Windows
2010/09/14 12:08:58.0251 Processor architecture: Intel x86
2010/09/14 12:08:58.0251 Number of processors: 2
2010/09/14 12:08:58.0251 Page size: 0x1000
2010/09/14 12:08:58.0251 Boot type: Normal boot
2010/09/14 12:08:58.0251 ================================================================================
2010/09/14 12:08:58.0708 Initialize success
2010/09/14 12:09:15.0408 ================================================================================
2010/09/14 12:09:15.0408 Scan started
2010/09/14 12:09:15.0408 Mode: Manual;
2010/09/14 12:09:15.0408 ================================================================================
2010/09/14 12:09:16.0756 ACPI (84fc6df81212d16be5c4f441682feccc) C:\Windows\system32\drivers\acpi.sys
2010/09/14 12:09:17.0093 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2010/09/14 12:09:17.0303 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2010/09/14 12:09:17.0503 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2010/09/14 12:09:17.0581 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2010/09/14 12:09:17.0863 AFD (5d24caf8efd924a875698ff28384db8b) C:\Windows\system32\drivers\afd.sys
2010/09/14 12:09:18.0511 AgereSoftModem (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys
2010/09/14 12:09:18.0837 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
2010/09/14 12:09:19.0103 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2010/09/14 12:09:19.0181 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
2010/09/14 12:09:19.0328 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
2010/09/14 12:09:19.0371 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
2010/09/14 12:09:19.0418 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2010/09/14 12:09:19.0459 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
2010/09/14 12:09:19.0733 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2010/09/14 12:09:19.0863 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2010/09/14 12:09:19.0973 AsyncMac (e86cf7ce67d5de898f27ef884dc357d8) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/09/14 12:09:20.0096 atapi (b35cfcef838382ab6490b321c87edf17) C:\Windows\system32\drivers\atapi.sys
2010/09/14 12:09:20.0400 Beep (ac3dd1708b22761ebd7cbe14dcc3b5d7) C:\Windows\system32\drivers\Beep.sys
2010/09/14 12:09:20.0834 bowser (913cd06fbe9105ce6077e90fd4418561) C:\Windows\system32\DRIVERS\bowser.sys
2010/09/14 12:09:20.0995 BRCMDECO (673375439606cbc0fbff1fa57337f55a) C:\Windows\system32\DRIVERS\BRCMHD32.sys
2010/09/14 12:09:21.0115 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2010/09/14 12:09:21.0183 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2010/09/14 12:09:21.0408 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2010/09/14 12:09:21.0465 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2010/09/14 12:09:21.0551 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2010/09/14 12:09:21.0606 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2010/09/14 12:09:21.0723 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2010/09/14 12:09:22.0134 cdfs (6c3a437fc873c6f6a4fc620b6888cb86) C:\Windows\system32\DRIVERS\cdfs.sys
2010/09/14 12:09:22.0396 cdrom (8d1866e61af096ae8b582454f5e4d303) C:\Windows\system32\DRIVERS\cdrom.sys
2010/09/14 12:09:22.0720 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
2010/09/14 12:09:22.0852 CLFS (1b84fd0937d3b99af9ba38ddff3daf54) C:\Windows\system32\CLFS.sys
2010/09/14 12:09:22.0972 CmBatt (ed97ad3df1b9005989eaf149bf06c821) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/09/14 12:09:23.0256 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
2010/09/14 12:09:23.0543 Compbatt (722936afb75a7f509662b69b5632f48a) C:\Windows\system32\DRIVERS\compbatt.sys
2010/09/14 12:09:23.0633 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2010/09/14 12:09:24.0026 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2010/09/14 12:09:24.0411 DfsC (a7179de59ae269ab70345527894ccd7c) C:\Windows\system32\Drivers\dfsc.sys
2010/09/14 12:09:24.0672 disk (841af4c4d41d3e3b2f244e976b0f7963) C:\Windows\system32\drivers\disk.sys
2010/09/14 12:09:24.0934 drmkaud (ee472cd2c01f6f8e8aa1fa06ffef61b6) C:\Windows\system32\drivers\drmkaud.sys
2010/09/14 12:09:25.0256 DXGKrnl (334988883de69adb27e2cf9f9715bbdb) C:\Windows\System32\drivers\dxgkrnl.sys
2010/09/14 12:09:25.0446 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2010/09/14 12:09:25.0817 Ecache (0efc7531b936ee57fdb4e837664c509f) C:\Windows\system32\drivers\ecache.sys
2010/09/14 12:09:26.0132 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2010/09/14 12:09:26.0406 fastfat (84a317cb0b3954d3768cdcd018dbf670) C:\Windows\system32\drivers\fastfat.sys
2010/09/14 12:09:26.0675 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
2010/09/14 12:09:26.0975 FileInfo (65773d6115c037ffd7ef8280ae85eb9d) C:\Windows\system32\drivers\fileinfo.sys
2010/09/14 12:09:27.0187 Filetrace (c226dd0de060745f3e042f58dcf78402) C:\Windows\system32\drivers\filetrace.sys
2010/09/14 12:09:27.0354 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/09/14 12:09:27.0416 FltMgr (a6a8da7ae4d53394ab22ac3ab6d3f5d3) C:\Windows\system32\drivers\fltmgr.sys
2010/09/14 12:09:27.0721 Fs_Rec (66a078591208baa210c7634b11eb392c) C:\Windows\system32\drivers\Fs_Rec.sys
2010/09/14 12:09:27.0962 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2010/09/14 12:09:28.0333 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2010/09/14 12:09:28.0705 HDAudBus (0db613a7e427b5663563677796fd5258) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/09/14 12:09:28.0980 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2010/09/14 12:09:29.0471 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2010/09/14 12:09:29.0674 HidUsb (01e7971e9f4bd6ac6a08db52d0ea0418) C:\Windows\system32\DRIVERS\hidusb.sys
2010/09/14 12:09:29.0748 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2010/09/14 12:09:30.0098 HTTP (ea24fe637d974a8a31bc650f478e3533) C:\Windows\system32\drivers\HTTP.sys
2010/09/14 12:09:30.0370 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2010/09/14 12:09:30.0702 i8042prt (1c9ee072baa3abb460b91d7ee9152660) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/09/14 12:09:31.0199 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\DRIVERS\iaStor.sys
2010/09/14 12:09:31.0541 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2010/09/14 12:09:32.0124 igfx (038815297078d236d8cc064c295a74c6) C:\Windows\system32\DRIVERS\igdkmd32.sys
2010/09/14 12:09:32.0643 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2010/09/14 12:09:33.0548 IntcAzAudAddService (0f16d98c3af2138fabfa20adde4e01fe) C:\Windows\system32\drivers\RTKVHDA.sys
2010/09/14 12:09:33.0775 intelide (988981c840084f480ba9e3319cebde1b) C:\Windows\system32\drivers\intelide.sys
2010/09/14 12:09:34.0245 intelppm (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
2010/09/14 12:09:34.0601 IpFilterDriver (880c6f86cc3f551b8fea2c11141268c0) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/09/14 12:09:35.0517 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2010/09/14 12:09:35.0842 IPNAT (10077c35845101548037df04fd1a420b) C:\Windows\system32\DRIVERS\ipnat.sys
2010/09/14 12:09:35.0913 IRENUM (a82f328f4792304184642d6d397bb1e3) C:\Windows\system32\drivers\irenum.sys
2010/09/14 12:09:36.0338 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
2010/09/14 12:09:36.0731 iScsiPrt (4dca456d4d5723f8fa9c6760d240b0df) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/09/14 12:09:37.0309 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2010/09/14 12:09:37.0539 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2010/09/14 12:09:37.0642 kbdclass (b076b2ab806b3f696dab21375389101c) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/09/14 12:09:37.0953 kbdhid (ed61dbc6603f612b7338283edbacbc4b) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/09/14 12:09:38.0243 KSecDD (0a829977b078dea11641fc2af87ceade) C:\Windows\system32\Drivers\ksecdd.sys
2010/09/14 12:09:38.0671 lltdio (fd015b4f95daa2b712f0e372a116fbad) C:\Windows\system32\DRIVERS\lltdio.sys
2010/09/14 12:09:38.0822 LPCFilter (515fc18cabee0158a324b08b1c2667cf) C:\Windows\system32\DRIVERS\LPCFilter.sys
2010/09/14 12:09:38.0884 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2010/09/14 12:09:39.0024 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2010/09/14 12:09:39.0154 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2010/09/14 12:09:39.0245 luafv (42885bb44b6e065b8575a8dd6c430c52) C:\Windows\system32\drivers\luafv.sys
2010/09/14 12:09:39.0629 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2010/09/14 12:09:39.0770 Modem (21755967298a46fb6adfec9db6012211) C:\Windows\system32\drivers\modem.sys
2010/09/14 12:09:40.0203 monitor (7446e104a5fe5987ca9e4983fbac4f97) C:\Windows\system32\DRIVERS\monitor.sys
2010/09/14 12:09:40.0546 mouclass (5fba13c1a1841b0885d316ed3589489d) C:\Windows\system32\DRIVERS\mouclass.sys
2010/09/14 12:09:41.0108 mouhid (b569b5c5d3bde545df3a6af512cccdba) C:\Windows\system32\DRIVERS\mouhid.sys
2010/09/14 12:09:41.0526 MountMgr (01f1e5a3e4877c931cbb31613fec16a6) C:\Windows\system32\drivers\mountmgr.sys
2010/09/14 12:09:41.0705 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2010/09/14 12:09:41.0770 mpsdrv (6e7a7f0c1193ee5648443fe2d4b789ec) C:\Windows\system32\drivers\mpsdrv.sys
2010/09/14 12:09:41.0927 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2010/09/14 12:09:42.0166 MRxDAV (1d8828b98ee309d65e006f0829e280e5) C:\Windows\system32\drivers\mrxdav.sys
2010/09/14 12:09:42.0415 mrxsmb (8af705ce1bb907932157fab821170f27) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/09/14 12:09:42.0515 mrxsmb10 (47e13ab23371be3279eef22bbfa2c1be) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/09/14 12:09:42.0854 mrxsmb20 (90b3fc7bd6b3d7ee7635debba2187f66) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/09/14 12:09:43.0426 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
2010/09/14 12:09:44.0317 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2010/09/14 12:09:44.0672 Msfs (729eafefd4e7417165f353a18dbe947d) C:\Windows\system32\drivers\Msfs.sys
2010/09/14 12:09:45.0039 msisadrv (5f454a16a5146cd91a176d70f0cfa3ec) C:\Windows\system32\drivers\msisadrv.sys
2010/09/14 12:09:45.0308 MSKSSRV (892cedefa7e0ffe7be8da651b651d047) C:\Windows\system32\drivers\MSKSSRV.sys
2010/09/14 12:09:45.0483 MSPCLOCK (ae2cb1da69b2676b4cee2a501af5871c) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/09/14 12:09:45.0571 MSPQM (f910da84fa90c44a3addb7cd874463fd) C:\Windows\system32\drivers\MSPQM.sys
2010/09/14 12:09:46.0015 MsRPC (84571c0ae07647ba38d493f5f0015df7) C:\Windows\system32\drivers\MsRPC.sys
2010/09/14 12:09:46.0333 mssmbios (4385c80ede885e25492d408cad91bd6f) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/09/14 12:09:46.0610 MSTEE (c826dd1373f38afd9ca46ec3c436a14e) C:\Windows\system32\drivers\MSTEE.sys
2010/09/14 12:09:46.0663 Mup (fa7aa70050cf5e2d15de00941e5665e5) C:\Windows\system32\Drivers\mup.sys
2010/09/14 12:09:46.0865 NativeWifiP (6da4a0fc7c0e83df0cb3cfd0a514c3bc) C:\Windows\system32\DRIVERS\nwifi.sys
2010/09/14 12:09:47.0214 NDIS (fffe00134c554e113ee186eeddb0ff30) C:\Windows\system32\drivers\ndis.sys
2010/09/14 12:09:47.0607 NdisTapi (81659cdcbd0f9a9e07e6878ad8c78d3f) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/09/14 12:09:47.0806 Ndisuio (5de5ee546bf40838ebe0e01cb629df64) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/09/14 12:09:47.0985 NdisWan (397402adcbb8946223a1950101f6cd94) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/09/14 12:09:48.0093 NDProxy (1b24fa907af283199a81b3bb37e5e526) C:\Windows\system32\drivers\NDProxy.sys
2010/09/14 12:09:48.0152 NetBIOS (356dbb9f98e8dc1028dd3092fceeb877) C:\Windows\system32\DRIVERS\netbios.sys
2010/09/14 12:09:48.0395 netbt (e3a168912e7eefc3bd3b814720d68b41) C:\Windows\system32\DRIVERS\netbt.sys
2010/09/14 12:09:49.0034 NETw4v32 (c4f27ba95327b6441ca44ddcfb47562a) C:\Windows\system32\DRIVERS\NETw4v32.sys
2010/09/14 12:09:49.0356 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2010/09/14 12:09:49.0513 Npfs (4f9832beb9fafd8ceb0e541f1323b26e) C:\Windows\system32\drivers\Npfs.sys
2010/09/14 12:09:49.0745 nsiproxy (b488dfec274de1fc9d653870ef2587be) C:\Windows\system32\drivers\nsiproxy.sys
2010/09/14 12:09:50.0183 Ntfs (37430aa7a66d7a63407adc2c0d05e9f6) C:\Windows\system32\drivers\Ntfs.sys
2010/09/14 12:09:50.0508 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2010/09/14 12:09:50.0751 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys
2010/09/14 12:09:50.0842 Null (ec5efb3c60f1b624648344a328bce596) C:\Windows\system32\drivers\Null.sys
2010/09/14 12:09:51.0306 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2010/09/14 12:09:51.0670 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2010/09/14 12:09:51.0843 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
2010/09/14 12:09:52.0094 NWADI (93213c7ec08e01e37a935bf144e75df6) C:\Windows\system32\DRIVERS\NWADIenum.sys
2010/09/14 12:09:52.0369 NWUSBCDFIL (1fde5b2d61d97d803594df4b3bc28c4b) C:\Windows\system32\DRIVERS\NwUsbCdFil.sys
2010/09/14 12:09:52.0553 NWUSBModem (e25caaabe56040e001d3abeaf9432fb0) C:\Windows\system32\DRIVERS\nwusbmdm.sys
2010/09/14 12:09:52.0668 NWUSBPort (e25caaabe56040e001d3abeaf9432fb0) C:\Windows\system32\DRIVERS\nwusbser.sys
2010/09/14 12:09:52.0814 NWUSBPort2 (e25caaabe56040e001d3abeaf9432fb0) C:\Windows\system32\DRIVERS\nwusbser2.sys
2010/09/14 12:09:52.0983 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/09/14 12:09:53.0272 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2010/09/14 12:09:53.0632 partmgr (555a5b2c8022983bc7467bc925b222ee) C:\Windows\system32\drivers\partmgr.sys
2010/09/14 12:09:53.0882 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2010/09/14 12:09:54.0063 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\Windows\system32\Drivers\PCASp50.sys
2010/09/14 12:09:54.0279 pci (1085d75657807e0e8b32f9e19a1647c3) C:\Windows\system32\drivers\pci.sys
2010/09/14 12:09:54.0689 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys
2010/09/14 12:09:54.0746 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/09/14 12:09:55.0172 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2010/09/14 12:09:55.0576 PptpMiniport (6c359ac71d7b550a0d41f9db4563ce05) C:\Windows\system32\DRIVERS\raspptp.sys
2010/09/14 12:09:55.0645 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2010/09/14 12:09:55.0734 PSched (2c8bae55247c4e09352e870292e4d1ab) C:\Windows\system32\DRIVERS\pacer.sys
2010/09/14 12:09:55.0992 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys
2010/09/14 12:09:56.0153 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2010/09/14 12:09:56.0248 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2010/09/14 12:09:56.0552 QWAVEdrv (d2b3e2b7426dc23e185fbc73c8936c12) C:\Windows\system32\drivers\qwavedrv.sys
2010/09/14 12:09:56.0730 RasAcd (bd7b30f55b3649506dd8b3d38f571d2a) C:\Windows\system32\DRIVERS\rasacd.sys
2010/09/14 12:09:56.0827 Rasl2tp (88587dd843e2059848995b407b67f6cf) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/09/14 12:09:57.0019 RasPppoe (ccf4e9c6cbbac81437f88cb2ae0b6c96) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/09/14 12:09:57.0068 rdbss (54129c5d9581bbec8bd1ebd3ba813f47) C:\Windows\system32\DRIVERS\rdbss.sys
2010/09/14 12:09:57.0162 RDPCDD (794585276b5d7fca9f3fc15543f9f0b9) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/09/14 12:09:57.0269 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
2010/09/14 12:09:57.0363 RDPENCDD (980b56e2e273e19d3a9d72d5c420f008) C:\Windows\system32\drivers\rdpencdd.sys
2010/09/14 12:09:57.0529 RDPWD (8830e790a74a96605faba74f9665bb3c) C:\Windows\system32\drivers\RDPWD.sys
2010/09/14 12:09:57.0685 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys
2010/09/14 12:09:57.0855 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys
2010/09/14 12:09:57.0937 ROOTMODEM (d49d61312b273de069584d48c81c8b1d) C:\Windows\system32\Drivers\RootMdm.sys
2010/09/14 12:09:58.0129 rspndr (97e939d2128fec5d5a3e6e79b290a2f4) C:\Windows\system32\DRIVERS\rspndr.sys
2010/09/14 12:09:58.0208 RTL8169 (b8b159fa669c6386a458fcd468ebb1e6) C:\Windows\system32\DRIVERS\Rtlh86.sys
2010/09/14 12:09:58.0578 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2010/09/14 12:09:58.0696 sdbus (bcca63a3d143938273a3158757389dc7) C:\Windows\system32\DRIVERS\sdbus.sys
2010/09/14 12:09:58.0809 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/09/14 12:09:58.0877 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2010/09/14 12:09:59.0150 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2010/09/14 12:09:59.0224 sermouse (450accd77ec5cea720c1cdb9e26b953b) C:\Windows\system32\drivers\sermouse.sys
2010/09/14 12:09:59.0560 sffdisk (5381bddf337dc4d4ddf6aa4304462fd4) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/09/14 12:09:59.0745 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
2010/09/14 12:09:59.0826 sffp_sd (2883e7a2c362deb7be5f43dbdd470bd5) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/09/14 12:09:59.0888 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2010/09/14 12:10:00.0067 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
2010/09/14 12:10:00.0177 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2010/09/14 12:10:00.0279 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2010/09/14 12:10:00.0540 Smb (ac0d90738adb51a6fd12ff00874a2162) C:\Windows\system32\DRIVERS\smb.sys
2010/09/14 12:10:00.0722 spldr (426f9b029aa9162ceccf65369457d046) C:\Windows\system32\drivers\spldr.sys
2010/09/14 12:10:00.0843 srv (038579c35f7cad4a4bbf735dbf83277d) C:\Windows\system32\DRIVERS\srv.sys
2010/09/14 12:10:01.0059 srv2 (6971a757af8cb5e2cbcbb76cc530db6c) C:\Windows\system32\DRIVERS\srv2.sys
2010/09/14 12:10:01.0169 srvnet (9e1a4603b874eebce0298113951abefb) C:\Windows\system32\DRIVERS\srvnet.sys
2010/09/14 12:10:01.0306 swenum (1379bdb336f8158c176a465e30759f57) C:\Windows\system32\DRIVERS\swenum.sys
2010/09/14 12:10:01.0405 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2010/09/14 12:10:01.0454 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2010/09/14 12:10:01.0565 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2010/09/14 12:10:01.0924 SynTP (ac4459d34f22b52feb6e619746ff6bd4) C:\Windows\system32\DRIVERS\SynTP.sys
2010/09/14 12:10:02.0431 Tcpip (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\drivers\tcpip.sys
2010/09/14 12:10:02.0860 Tcpip6 (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\DRIVERS\tcpip.sys
2010/09/14 12:10:03.0241 tcpipreg (5ce0c4a7b12d0067dad527d72b68c726) C:\Windows\system32\drivers\tcpipreg.sys
2010/09/14 12:10:03.0605 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys
2010/09/14 12:10:03.0867 TDPIPE (964248aef49c31fa6a93201a73ffaf50) C:\Windows\system32\drivers\tdpipe.sys
2010/09/14 12:10:04.0153 TDTCP (7d2c1ae1648a60fce4aa0f7982e419d3) C:\Windows\system32\drivers\tdtcp.sys
2010/09/14 12:10:04.0194 tdx (ab4fde8af4a0270a46a001c08cbce1c2) C:\Windows\system32\DRIVERS\tdx.sys
2010/09/14 12:10:04.0229 TermDD (2c549bd9dd091fbfaa0a2a48e82ec2fb) C:\Windows\system32\DRIVERS\termdd.sys
2010/09/14 12:10:04.0482 tifm21 (e4c85c291ddb3dc5e4a2f227ca465ba6) C:\Windows\system32\drivers\tifm21.sys
2010/09/14 12:10:05.0022 tosrfec (5c4103544612e5011ef46301b93d1aa6) C:\Windows\system32\DRIVERS\tosrfec.sys
2010/09/14 12:10:05.0414 tos_sps32 (1ea5f27c29405bf49799feca77186da9) C:\Windows\system32\DRIVERS\tos_sps32.sys
2010/09/14 12:10:05.0714 tssecsrv (29f0eca726f0d51f7e048bdb0b372f29) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/09/14 12:10:06.0071 tunmp (65e953bc0084d44498b51f59784d2a82) C:\Windows\system32\DRIVERS\tunmp.sys
2010/09/14 12:10:06.0345 tunnel (4a39bda5e0fd30bdf4884f9d33ae6105) C:\Windows\system32\DRIVERS\tunnel.sys
2010/09/14 12:10:06.0666 TVALZ (521c5f39829875adf5466dd94c6282c7) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
2010/09/14 12:10:07.0046 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
2010/09/14 12:10:07.0396 udfs (6348da98707ceda8a0dfb05820e17732) C:\Windows\system32\DRIVERS\udfs.sys
2010/09/14 12:10:07.0762 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
2010/09/14 12:10:07.0832 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2010/09/14 12:10:08.0068 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2010/09/14 12:10:08.0234 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2010/09/14 12:10:08.0349 umbus (3fb78f1d1dd86d87bececd9dffa24dd9) C:\Windows\system32\DRIVERS\umbus.sys
2010/09/14 12:10:08.0558 usbccgp (51480458e6e9863f856ebf35aae801b4) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/09/14 12:10:08.0680 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2010/09/14 12:10:08.0793 usbehci (11fa3acbf0de0286829c69e01fe705e4) C:\Windows\system32\DRIVERS\usbehci.sys
2010/09/14 12:10:08.0903 usbhub (6a7858a38b5105731e219e7c6a238730) C:\Windows\system32\DRIVERS\usbhub.sys
2010/09/14 12:10:09.0290 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2010/09/14 12:10:09.0543 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
2010/09/14 12:10:09.0620 USBSTOR (7887ce56934e7f104e98c975f47353c5) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/09/14 12:10:09.0858 usbuhci (4013315fed70a2d293b998cbba4022ee) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/09/14 12:10:10.0023 usbvideo (0a6b81f01bc86399482e27e6fda7b33b) C:\Windows\system32\Drivers\usbvideo.sys
2010/09/14 12:10:10.0143 UVCFTR (3b929a72aaea96dc0150d3a6da268c89) C:\Windows\system32\Drivers\UVCFTR_S.SYS
2010/09/14 12:10:10.0275 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/09/14 12:10:10.0374 VgaSave (17a8f877314e4067f8c8172cc6d9101c) C:\Windows\System32\drivers\vga.sys
2010/09/14 12:10:10.0425 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
2010/09/14 12:10:10.0523 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2010/09/14 12:10:10.0643 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
2010/09/14 12:10:10.0835 volmgr (103e84c95832d0ed93507997cc7b54e8) C:\Windows\system32\drivers\volmgr.sys
2010/09/14 12:10:11.0142 volmgrx (294da8d3f965f6a8db934a83c7b461ff) C:\Windows\system32\drivers\volmgrx.sys
2010/09/14 12:10:11.0461 volsnap (80dc0c9bcb579ed9815001a4d37cbfd5) C:\Windows\system32\drivers\volsnap.sys
2010/09/14 12:10:11.0776 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2010/09/14 12:10:12.0133 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2010/09/14 12:10:12.0320 Wanarp (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys
2010/09/14 12:10:12.0353 Wanarpv6 (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys
2010/09/14 12:10:12.0541 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2010/09/14 12:10:12.0732 Wdf01000 (7b5f66e4a2219c7d9daf9e738480e534) C:\Windows\system32\drivers\Wdf01000.sys
2010/09/14 12:10:13.0051 WmiAcpi (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
2010/09/14 12:10:13.0185 WpdUsb (2d27171b16a577ef14c1273668753485) C:\Windows\system32\DRIVERS\wpdusb.sys
2010/09/14 12:10:13.0286 ws2ifsl (84620aecdcfd2a7a14e6263927d8c0ed) C:\Windows\system32\drivers\ws2ifsl.sys
2010/09/14 12:10:13.0445 WUDFRd (a2aafcc8a204736296d937c7c545b53f) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/09/14 12:10:13.0539 ================================================================================
2010/09/14 12:10:13.0539 Scan finished
2010/09/14 12:10:13.0539 ================================================================================


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-14 14:15:15
Windows 6.0.6000
Running: irwgpjj4.exe; Driver: C:\Users\LUCKY1~1\AppData\Local\Temp\ffriafoc.sys


—- Kernel code sections - GMER 1.0.15 —-

.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x826F7000, 0x510, 0x40000040]
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x826AE000, 0x4036D, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\Explorer.EXE[1116] kernel32.dll!CreateProcessInternalW 775EE445 5 Bytes JMP 000E874A

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

Double click on ComboFix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here is my new log file. I was having problems getting on to firefox or internet explorer. I had to go on as an administrator. Is that normal? I tried to open it and I get a notification that says "Illegal operation attempted on a registry key that has been marked for deletion" Is that normal? How do I get firefox back? Anyways, here is the log! Thanks I hope this is all helping out!

ComboFix 10-09-14.05 - Lucky 13 15/09/2010 12:24:20.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2038.989 [GMT -6:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Lucky 13\AppData\Local\Windows Server
c:\users\Lucky 13\AppData\Local\Windows Server\flags.ini
c:\users\Lucky 13\AppData\Local\Windows Server\uses32.dat
c:\windows\System32\ccmlua.dll
F:\Autorun.inf

Infected copy of c:\windows\system32\wininit.exe was found and disinfected
Restored copy from - c:\windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe

.
((((((((((((((((((((((((( Files Created from 2010-08-15 to 2010-09-15 )))))))))))))))))))))))))))))))
.

2010-09-15 18:33 . 2010-09-15 19:06 ——– d—–w- c:\users\Lucky 13\AppData\Local\temp
2010-09-15 18:33 . 2010-09-15 18:33 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-09-09 23:25 . 2010-09-09 23:26 ——– d—–w- c:\program files\Golden Trails - The New Western Rush2
2010-09-09 23:14 . 2010-09-09 23:14 ——– d—–w- c:\programdata\WildWestQuest2
2010-09-08 22:11 . 2010-09-08 22:11 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\Awem
2010-09-08 22:11 . 2010-09-08 22:11 ——– d—–w- c:\program files\Dream Day Couple
2010-09-08 22:08 . 2010-09-09 23:15 ——– d—–w- c:\program files\Golden Trails - The New Western Rush
2010-09-08 20:18 . 2010-09-13 22:07 ——– d—–w- c:\users\Lucky 13\AppData\Local\WinZip
2010-08-30 14:09 . 2010-08-30 14:09 680 —-a-w- c:\users\Lucky 13\AppData\Local\d3d9caps.dat
2010-08-30 14:07 . 2010-08-30 14:07 552 —-a-w- c:\users\Lucky 13\AppData\Local\d3d8caps.dat
2010-08-30 12:58 . 2010-08-30 13:48 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-08-30 12:58 . 2010-08-30 12:58 ——– d—–w- C:\Spybot - Search & Destroy
2010-08-30 12:49 . 2010-08-30 12:49 ——– d—–w- c:\program files\Trend Micro
2010-08-22 03:16 . 2010-08-22 03:16 ——– d—–w- c:\program files\Dream Day Wedding Married in Manhattan
2010-08-20 01:04 . 2010-09-09 23:13 ——– d—–w- c:\program files\Games
2010-08-19 04:14 . 2010-09-08 23:13 ——– d—–w- c:\users\Lucky 13\AppData\Local\Oberon Games
2010-08-19 00:12 . 2010-08-19 00:12 ——– d—–w- c:\program files\Hide And Secret
2010-08-19 00:10 . 2010-09-08 20:11 ——– d—–w- c:\program files\Dream Day Wedding

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-30 12:49 . 2010-08-30 12:49 388096 —-a-r- c:\users\Lucky 13\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-19 00:18 . 2010-08-10 04:10 ——– d—–w- c:\program files\Private Eye - Greatest Unsolved Mysteries
2010-08-18 23:12 . 2010-08-30 18:41 52224 —-a-w- c:\users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
2010-08-18 23:12 . 2010-08-30 18:41 101376 —-a-w- c:\users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
2010-08-16 16:54 . 2010-08-16 16:54 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\PlayFirst
2010-08-16 16:54 . 2010-08-16 16:54 ——– d—–w- c:\programdata\PlayFirst
2010-08-16 16:53 . 2010-08-16 16:53 ——– d—–w- c:\program files\Mystery of Shark Island
2010-08-13 20:41 . 2010-08-13 19:42 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\Magic Academy
2010-08-12 02:57 . 2010-08-10 04:27 ——– d—–w- c:\program files\Death On The Nile
2010-08-11 15:52 . 2010-08-11 15:52 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\FloodLightGames
2010-08-11 15:52 . 2010-08-11 15:52 ——– d—–w- c:\programdata\FloodLightGames
2010-08-10 22:47 . 2010-08-10 22:47 ——– d—–w- c:\programdata\SpinTop Games
2010-08-10 21:30 . 2010-08-10 21:29 ——– d—–w- c:\program files\Snapshot Adventures
2010-08-10 21:29 . 2010-08-10 21:29 ——– d—–w- c:\programdata\JollyBear
2010-08-10 21:26 . 2010-08-10 21:26 ——– d—–w- c:\program files\Paparazzi
2010-08-10 21:25 . 2010-08-10 21:25 ——– d—–w- c:\program files\Mystery Solitaire - Secret Island
2010-08-10 21:24 . 2010-08-10 04:07 ——– d—–w- c:\program files\Big City Adventure - San Francisco
2010-08-10 21:22 . 2010-08-10 21:22 ——– d—–w- c:\program files\Abra Academy
2010-08-10 21:18 . 2010-08-10 21:18 ——– d—–w- c:\program files\5 Spots II
2010-08-10 04:34 . 2010-08-10 04:32 ——– d—–w- c:\program files\Mystery Case Files - Ravenhearst
2010-08-10 04:25 . 2010-08-10 04:24 ——– d—–w- c:\program files\Magic Academy
2010-08-10 04:19 . 2010-08-10 04:14 ——– d—–w- c:\program files\Mirror Magic
2010-08-10 04:07 . 2010-08-10 04:07 ——– d—–w- c:\programdata\Trymedia
2010-08-10 04:07 . 2010-08-10 04:07 ——– d—–w- c:\program files\BFG
2010-08-10 04:05 . 2010-08-10 04:05 ——– d—–w- c:\program files\ReflexiveArcade
2010-08-10 04:03 . 2010-08-10 04:02 ——– d—–w- c:\programdata\WinZip
2010-08-09 18:59 . 2010-08-09 18:59 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\Anarchy
2010-08-09 18:59 . 2010-08-09 18:58 ——– d—–w- c:\program files\Redrum - Time Lies
2010-08-09 04:18 . 2010-08-07 02:09 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\MysteryStudio
2010-08-07 01:32 . 2010-08-07 01:31 ——– d—–w- c:\program files\Murder She Wrote
2010-08-07 01:15 . 2010-08-07 01:15 ——– d—–w- c:\program files\bfgclient
2010-08-07 01:00 . 2010-08-07 01:00 2560 —-a-w- c:\windows\_MSRSTRT.EXE
2010-08-05 23:54 . 2010-08-05 23:54 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers
2010-08-05 23:53 . 2010-08-05 23:52 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-08-05 23:52 . 2010-08-05 23:52 ——– d—–w- c:\program files\DVDVideoSoft
2010-07-28 19:50 . 2010-06-24 03:26 256 —-a-w- c:\windows\system32\pool.bin
2010-07-24 02:52 . 2010-07-11 03:13 ——– d—–w- c:\users\Lucky 13\AppData\Roaming\vlc
2010-07-22 04:42 . 2010-07-22 04:42 ——– d—–w- c:\programdata\McAfee
2010-07-16 04:29 . 2010-07-16 04:29 13094 —-a-r- c:\users\Lucky 13\AppData\Roaming\Microsoft\Installer\{E90C9405-DDC3-4DEB-95C8-DAAAAF69BB3E}\_87349FD83004EEB9228277.exe
2010-07-16 04:29 . 2010-07-16 04:29 13094 —-a-r- c:\users\Lucky 13\AppData\Roaming\Microsoft\Installer\{E90C9405-DDC3-4DEB-95C8-DAAAAF69BB3E}\_6FEFF9B68218417F98F549.exe
2010-07-16 04:29 . 2010-07-16 04:29 13094 —-a-r- c:\users\Lucky 13\AppData\Roaming\Microsoft\Installer\{E90C9405-DDC3-4DEB-95C8-DAAAAF69BB3E}\_3AF8409C2F87542353F525.exe
2010-07-11 03:25 . 2010-07-11 03:25 652296 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2010-07-11 03:25 . 2010-07-11 03:25 764168 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-06-27 09:25 . 2010-06-27 09:25 268800 —-a-w- c:\windows\system32\es.dll
2010-06-27 09:19 . 2010-06-27 09:19 622080 —-a-w- c:\windows\system32\icardagt.exe
2010-06-27 09:19 . 2010-06-27 09:19 11264 —-a-w- c:\windows\system32\icardres.dll
2010-06-27 09:19 . 2010-06-27 09:19 97800 —-a-w- c:\windows\system32\infocardapi.dll
2010-06-27 09:19 . 2010-06-27 09:19 105016 —-a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-06-27 09:19 . 2010-06-27 09:19 781344 —-a-w- c:\windows\system32\PresentationNative_v0300.dll
2010-06-27 09:19 . 2010-06-27 09:19 43544 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-27 09:19 . 2010-06-27 09:19 326160 —-a-w- c:\windows\system32\PresentationHost.exe
2010-06-26 09:26 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2010-06-26 09:08 . 2010-06-26 09:08 549888 —-a-w- c:\windows\system32\rpcss.dll
2010-06-26 09:08 . 2010-06-26 09:08 654336 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2010-06-26 09:08 . 2010-06-26 09:08 24576 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2010-06-26 09:08 . 2010-06-26 09:08 130560 —-a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2010-06-26 09:08 . 2010-06-26 09:08 247296 —-a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2010-06-26 09:08 . 2010-06-26 09:08 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2010-06-26 09:08 . 2010-06-26 09:08 501760 —-a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2010-06-26 09:08 . 2010-06-26 09:08 97280 —-a-w- c:\windows\system32\iasrecst.dll
2010-06-26 09:08 . 2010-06-26 09:08 53248 —-a-w- c:\windows\system32\iasads.dll
2010-06-26 09:08 . 2010-06-26 09:08 37888 —-a-w- c:\windows\system32\iasdatastore.dll
2010-06-26 09:08 . 2010-06-26 09:08 158720 —-a-w- c:\windows\system32\sdohlp.dll
2010-06-26 09:06 . 2010-06-26 09:06 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-06-26 09:06 . 2010-06-26 09:06 179712 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-06-26 09:06 . 2010-06-26 09:06 15360 —-a-w- c:\windows\system32\drivers\TUNMP.SYS
2010-06-26 09:06 . 2010-06-26 09:06 815104 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-26 09:06 . 2010-06-26 09:06 22016 —-a-w- c:\windows\system32\netiougc.exe
2010-06-26 09:06 . 2010-06-26 09:06 167424 —-a-w- c:\windows\system32\tcpipcfg.dll
2010-06-26 09:06 . 2010-06-26 09:06 9728 —-a-w- c:\windows\system32\LAPRXY.DLL
2010-06-26 09:06 . 2010-06-26 09:06 2048 —-a-w- c:\windows\system32\asferror.dll
2010-06-26 09:06 . 2010-06-26 09:06 223232 —-a-w- c:\windows\system32\WMASF.DLL
2010-06-26 09:06 . 2010-06-26 09:06 40960 —-a-w- c:\windows\AppPatch\apihex86.dll
2010-06-26 09:06 . 2010-06-26 09:06 25600 —-a-w- c:\windows\system32\amxread.dll
2010-06-26 09:06 . 2010-06-26 09:06 14848 —-a-w- c:\windows\system32\apilogen.dll
2010-06-26 09:05 . 2010-06-26 09:05 712192 —-a-w- c:\windows\system32\WindowsCodecs.dll
2010-06-26 09:05 . 2010-06-26 09:05 425472 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2010-06-26 09:05 . 2010-06-26 09:05 347136 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2010-06-26 09:04 . 2010-06-26 09:04 441856 —-a-w- c:\windows\system32\win32spl.dll
2010-06-26 09:04 . 2010-06-26 09:04 37376 —-a-w- c:\windows\system32\printcom.dll
2010-06-26 09:04 . 2010-06-26 09:04 2031104 —-a-w- c:\windows\system32\win32k.sys
2010-06-26 09:03 . 2010-06-26 09:03 14848 —-a-w- c:\windows\system32\wshrm.dll
2010-06-26 09:03 . 2010-06-26 09:03 113664 —-a-w- c:\windows\system32\drivers\rmcast.sys
2010-06-26 09:03 . 2010-06-26 09:03 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2010-06-26 09:02 . 2010-06-26 09:02 435712 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-06-26 09:02 . 2010-06-26 09:02 312320 —-a-w- c:\windows\system32\msdrm.dll
2010-06-26 09:02 . 2010-06-26 09:02 154112 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-06-26 09:02 . 2010-06-26 09:02 431104 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-06-26 09:02 . 2010-06-26 09:02 154624 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-06-26 09:02 . 2010-06-26 09:02 472576 —-a-w- c:\windows\system32\secproc.dll
2010-06-26 09:02 . 2010-06-26 09:02 523776 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-06-26 09:02 . 2010-06-26 09:02 515584 —-a-w- c:\windows\system32\RMActivate.exe
2010-06-26 09:02 . 2010-06-26 09:02 473088 —-a-w- c:\windows\system32\secproc_isv.dll
2010-06-26 09:01 . 2010-06-26 09:01 83968 —-a-w- c:\windows\system32\dnsrslvr.dll
2010-06-26 09:01 . 2010-06-26 09:01 24576 —-a-w- c:\windows\system32\dnscacheugc.exe
2010-06-25 18:26 . 2010-06-24 01:15 128424 —-a-w- c:\users\Lucky 13\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-25 17:20 . 2010-06-25 17:20 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-06-25 17:20 . 2010-06-25 17:20 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-06-25 17:20 . 2010-06-25 17:20 24064 —-a-w- c:\windows\system32\lpk.dll
2010-06-25 17:20 . 2010-06-25 17:20 156672 —-a-w- c:\windows\system32\t2embed.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-06-25 1232896]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-01-22 417792]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-09-27 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 4702208]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-09-27 77824]
"NDSTray.exe"="NDSTray.exe" [BU]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-23 438272]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
"tscui"="c:\program files\Bell Mobility\Mobile Connect Basic\tscui.exe" [2009-05-22 1970176]
"MCStart"="c:\program files\Bell Mobility\Mobile Connect Basic\tscui.exe" [2009-05-22 1970176]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-07-07 20480]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-12-04 174592]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
S2 NvtlService;NovaCore SDK Service;c:\program files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [2009-03-02 40448]
S2 SBSDWSCService;SBSD Security Center Service;c:\spybot - search & destroy\SDWinSec.exe [2009-01-26 1153368]

.
Contents of the 'Scheduled Tasks' folder

2010-09-10 c:\windows\Tasks\At1.job
- c:\windows\system32\chkkdsk.exe [2006-11-02 09:44]

2010-09-13 c:\windows\Tasks\At2.job
- c:\windows\system32\chkkdsk.exe [2006-11-02 09:44]

2010-09-14 c:\windows\Tasks\At3.job
- c:\windows\system32\chkkdsk.exe [2006-11-02 09:44]

2010-09-14 c:\windows\Tasks\At4.job
- c:\windows\system32\chkkdsk.exe [2006-11-02 09:44]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
FF - ProfilePath - c:\users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
FF - component: c:\users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-15 13:06
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i????????EW???? ??? ??????P???`?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
.
**************************************************************************
.
Completion time: 2010-09-15 13:12:23 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-15 19:12

Pre-Run: 133,548,457,984 bytes free
Post-Run: 133,360,300,032 bytes free

- - End Of File - - DAE4EF3814341E3D6A10942CB4C9F6AF
Now that I have used my computer more throughout the day, I have noticed that that error message comes up quite a bit for other things I try to do as well. Hmmmm . The redirecting of the google sites has stopped though…lol
Hi,

I have noticed that that error message comes up quite a bit for other things I try to do as well.

Do you mean it comes up in your browser or in your windows? By now I assumed that you have already rebooted your computer, are you still having those errors?


Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

AtJob::

File::
c:\windows\system32\chkkdsk.exe

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]
It comes up in my windows. (everything i open I have to right click and run as an administrator.) Even trying to open notepad it said C\Windows\System32\notepad.exe Illegal operation attempted on a registry key that has been marked for deletion. I tried to change my screen saver and it says C\Windows\System32\control.exe Illegal operation attempted on a registry key that has been marked for deletion. I will try the fix you requested and get back to you in the morning! :)
Hey…. That worked…..Do I still need to run the combo fix by dragging that file into it ?? Thank you so much for your patience with me!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI