This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Safe Surfing

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My (roommate / landlord / friend) surfs the internet each evening after I have gone to bed. In an effort to keep him away from malicious sites I installed the "Web of Trust" extension for Firefox and explained to him how it worked and ask that he not visit any untrusted sites.

While previewing the modified files I noticed that a Firefox user profile had been created during the middle of the night and 30+ files had been added, groups of files were created at the same time. I deleted the entire user profile folder. I now wondering what else might have been added that I didn't see.

I've noticed now that the mouse seems slow to respond at times and at other time completely unresponsive while clicking. If someone will look at the logs I'd appreciate it.


OTL logfile created on: 9/20/2010 1:34:00 PM - Run 1
OTL by OldTimer - Version 3.2.14.0 Folder = C:\Users\Joe\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 287.11 Gb Total Space | 250.42 Gb Free Space | 87.22% Space Free | Partition Type: NTFS
Drive D: | 10.88 Gb Total Space | 1.59 Gb Free Space | 14.57% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: UNIT1
Current User Name: Joe
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Joe\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Joe\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)


========== Modules (SafeList) ==========

MOD - C:\Users\Joe\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (UimBus) – C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:64bit: - (Uim_IM) – C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (hotcore3) – C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:64bit: - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {5F590AA2-1221-4113-A6F4-A4BB62414FAC}:0.45.6.20100202.1

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/09/17 18:47:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/09/17 18:47:57 | 000,000,000 | —D | M]

[2010/09/17 18:48:12 | 000,000,000 | —D | M] – C:\Users\Joe\AppData\Roaming\Mozilla\Extensions
[2010/09/20 04:45:34 | 000,000,000 | —D | M] – C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\t5g1zykg.default\extensions
[2010/09/18 21:25:58 | 000,000,000 | —D | M] (SmoothWheel (mozdev.org)) – C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\t5g1zykg.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2010/09/18 20:43:00 | 000,000,000 | —D | M] (WOT) – C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\t5g1zykg.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/09/18 20:44:41 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\t5g1zykg.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/09/17 18:47:57 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe (PC-Doctor, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/09/20 13:25:42 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Users\Joe\Desktop\OTL.exe
[2010/09/19 23:50:31 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\CyberLink
[2010/09/19 03:00:39 | 002,441,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/09/18 08:13:49 | 000,000,000 | —D | C] – C:\ProgramData\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
[2010/09/18 08:13:17 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\hpqLog
[2010/09/18 08:11:54 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\WinBatch
[2010/09/18 08:07:38 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\HP Support Assistant
[2010/09/18 08:07:31 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\HpUpdate
[2010/09/17 22:10:44 | 000,000,000 | —D | C] – C:\Users\Joe\Documents\Any Video Converter
[2010/09/17 20:15:23 | 000,000,000 | —D | C] – C:\Users\Joe\Desktop\Divx
[2010/09/17 20:10:45 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\DivX
[2010/09/17 20:10:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PX Storage Engine
[2010/09/17 20:10:30 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/09/17 20:10:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DivX Shared
[2010/09/17 20:09:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\DivX
[2010/09/17 20:08:43 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2010/09/17 19:18:16 | 000,037,456 | —- | C] (Paragon Software Group) – C:\Windows\SysNative\drivers\hotcore3.sys
[2010/09/17 19:18:16 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/09/17 19:13:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Paragon Software
[2010/09/17 19:07:07 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\AnvSoft
[2010/09/17 19:07:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\AnvSoft
[2010/09/17 19:04:30 | 000,000,000 | —D | C] – C:\Users\Joe\Desktop\Programs
[2010/09/17 19:03:25 | 000,000,000 | —D | C] – C:\Users\Joe\Documents\StreamTransport
[2010/09/17 19:02:06 | 003,982,240 | —- | C] (Adobe Systems, Inc.) – C:\Windows\SysWow64\Flash10d.ocx
[2010/09/17 19:02:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\StreamTransport
[2010/09/17 18:48:03 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\Mozilla
[2010/09/17 18:47:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/09/17 18:36:54 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/09/17 18:36:54 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/09/17 17:44:29 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\Mozilla
[2010/09/17 17:44:20 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\Google
[2010/09/17 17:44:05 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\Apps
[2010/09/17 17:44:04 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\Deployment
[2010/09/17 17:09:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2010/09/17 17:08:27 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/09/17 17:08:27 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/09/17 17:08:26 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010/09/17 17:08:26 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/09/17 17:08:26 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010/09/17 17:08:26 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/09/17 17:08:26 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/09/17 17:08:26 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010/09/17 17:02:55 | 001,736,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2010/09/17 17:02:53 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2010/09/17 17:02:53 | 000,427,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\vbscript.dll
[2010/09/17 17:02:52 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2010/09/17 17:02:52 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010/09/17 17:02:52 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2010/09/17 17:02:52 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010/09/17 17:02:50 | 001,446,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2010/09/17 17:02:44 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/09/17 17:02:44 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/09/17 17:02:44 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/09/17 17:02:44 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/09/17 17:02:43 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/09/17 17:02:43 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/09/17 17:02:23 | 000,422,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_isv.dll
[2010/09/17 17:02:22 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc.dll
[2010/09/17 17:02:22 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2010/09/17 17:02:22 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2010/09/17 17:02:22 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_isv.exe
[2010/09/17 17:02:22 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate.exe
[2010/09/17 17:02:22 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2010/09/17 17:02:22 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2010/09/17 17:02:22 | 000,306,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp.exe
[2010/09/17 17:02:22 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010/09/17 17:02:21 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2010/09/17 17:02:21 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010/09/17 17:02:21 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp_isv.dll
[2010/09/17 17:02:21 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp.dll
[2010/09/17 17:02:21 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010/09/17 17:02:21 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2010/09/17 17:02:03 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2010/09/17 17:02:00 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010/09/17 17:02:00 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010/09/17 17:02:00 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010/09/17 17:01:59 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2010/09/17 17:01:59 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010/09/17 17:01:59 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2010/09/17 17:01:59 | 000,258,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2010/09/17 17:01:59 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/09/17 17:01:59 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/09/17 17:01:53 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2010/09/17 17:01:53 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2010/09/17 17:01:53 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2010/09/17 17:01:53 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2010/09/17 17:01:52 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/09/17 17:01:51 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2010/09/17 17:01:51 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2010/09/17 17:01:50 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010/09/17 17:01:50 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2010/09/17 17:01:50 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2010/09/17 17:01:49 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2010/09/17 17:01:49 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2010/09/17 17:01:49 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2010/09/17 17:01:49 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2010/09/17 17:01:49 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2010/09/17 17:01:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2010/09/17 17:01:48 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010/09/17 17:01:46 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010/09/17 17:01:45 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2010/09/17 17:01:45 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/09/17 17:01:45 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010/09/17 17:01:44 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2010/09/17 16:52:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Antimalware
[2010/09/17 16:52:53 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/09/17 16:42:35 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\Macromedia
[2010/09/17 16:42:35 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\Adobe
[2010/09/17 16:30:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/09/17 16:08:43 | 000,000,000 | R–D | C] – C:\Users\Joe\Searches
[2010/09/17 16:08:43 | 000,000,000 | -H-D | C] – C:\Users\Joe\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2010/09/17 16:08:35 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\Identities
[2010/09/17 16:08:33 | 000,000,000 | R–D | C] – C:\Users\Joe\Contacts
[2010/09/17 16:08:32 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\VirtualStore
[2010/09/17 16:05:30 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2010/09/17 16:05:30 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wintrust.dll
[2010/09/17 16:05:29 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2010/09/17 16:05:29 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2010/09/17 16:03:29 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\Hewlett-Packard
[2010/09/17 16:03:01 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\Hewlett-Packard
[2010/09/17 16:02:37 | 000,000,000 | –SD | C] – C:\Users\Joe\AppData\Roaming\Microsoft
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Videos
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Saved Games
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Pictures
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Music
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Links
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Favorites
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Downloads
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\My Documents
[2010/09/17 16:02:37 | 000,000,000 | R–D | C] – C:\Users\Joe\Desktop
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\AppData\Local\Temporary Internet Files
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Templates
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Start Menu
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\SendTo
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Recent
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\PrintHood
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\NetHood
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Documents\My Videos
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Documents\My Pictures
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Documents\My Music
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\My Documents
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Local Settings
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\AppData\Local\History
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Cookies
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\Application Data
[2010/09/17 16:02:37 | 000,000,000 | -HSD | C] – C:\Users\Joe\AppData\Local\Application Data
[2010/09/17 16:02:37 | 000,000,000 | -H-D | C] – C:\Users\Joe\AppData
[2010/09/17 16:02:37 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\Temp
[2010/09/17 16:02:37 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\Microsoft
[2010/09/17 16:02:37 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\Media Center Programs
[2010/09/17 16:02:37 | 000,000,000 | —D | C] – C:\Users\Joe\AppData\Local\HuluDesktop
[2010/08/25 14:45:30 | 000,446,544 | —- | C] (Paragon) – C:\Windows\SysNative\drivers\UimFIO.sys
[2010/08/25 14:45:30 | 000,249,936 | —- | C] (Paragon Software Group) – C:\Windows\SysWow64\prgiso.dll
[2010/08/25 14:45:30 | 000,050,768 | —- | C] (Windows ® 2000 DDK provider) – C:\Windows\SysNative\drivers\uimx64.sys
[2010/08/25 14:45:28 | 000,566,864 | —- | C] (Paragon) – C:\Windows\SysNative\drivers\Uim_IMx64.sys

========== Files - Modified Within 30 Days ==========

[2010/09/20 13:35:36 | 001,048,576 | -HS- | M] () – C:\Users\Joe\NTUSER.DAT
[2010/09/20 13:25:42 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\Joe\Desktop\OTL.exe
[2010/09/20 12:49:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-868716050-2658743674-3616393184-1000UA.job
[2010/09/19 17:55:53 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-868716050-2658743674-3616393184-1000Core.job
[2010/09/19 03:37:56 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/19 03:37:56 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/19 03:25:16 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/19 03:25:16 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/09/19 03:25:16 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/09/19 03:17:38 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/19 03:17:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/19 03:17:18 | 2213,404,672 | -HS- | M] () – C:\hiberfil.sys
[2010/09/19 03:16:50 | 001,552,196 | -H– | M] () – C:\Users\Joe\AppData\Local\IconCache.db
[2010/09/18 20:40:31 | 000,000,324 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJoe.job
[2010/09/18 08:14:35 | 000,001,099 | —- | M] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/09/17 18:47:58 | 000,001,965 | —- | M] () – C:\Users\Joe\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/17 17:49:51 | 000,329,176 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/09/17 16:42:22 | 000,001,439 | —- | M] () – C:\Users\Joe\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/17 16:41:43 | 000,000,544 | —- | M] () – C:\Windows\tasks\PCDRScheduledMaintenance.job
[2010/09/17 16:40:44 | 000,070,718 | —- | M] () – C:\Users\Joe\Documents\cc_20100917_164022.reg
[2010/09/17 16:14:04 | 000,524,288 | -HS- | M] () – C:\Users\Joe\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/09/17 16:14:04 | 000,524,288 | -HS- | M] () – C:\Users\Joe\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/09/17 16:14:04 | 000,065,536 | -HS- | M] () – C:\Users\Joe\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/09/17 16:07:38 | 000,079,864 | —- | M] () – C:\Users\Joe\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/09/17 16:02:47 | 000,001,662 | RHS- | M] () – C:\Windows\SysWow64\drivers\103C_HP_CPC_BQ464AA-ABA s5503w_YC_0Pavi_Q4CE020_EA1NAv6PrA8_49_INARRA5_SPEGATRON CORPORATION_V5.00_B5.55_T091208_WUH0_L409_M2815_J320_7AMD_8Sempron 140_92.7_#_N10DE03EF_Z_G10DE03D0.MRK
[2010/09/17 16:02:47 | 000,001,662 | RHS- | M] () – C:\Windows\SysNative\drivers\103C_HP_CPC_BQ464AA-ABA s5503w_YC_0Pavi_Q4CE020_EA1NAv6PrA8_49_INARRA5_SPEGATRON CORPORATION_V5.00_B5.55_T091208_WUH0_L409_M2815_J320_7AMD_8Sempron 140_92.7_#_N10DE03EF_Z_G10DE03D0.MRK
[2010/09/17 16:02:37 | 000,000,020 | -HS- | M] () – C:\Users\Joe\ntuser.ini
[2010/09/17 16:01:30 | 000,039,219 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2010/09/17 16:01:30 | 000,039,219 | —- | M] () – C:\Windows\SysNative\license.rtf
[2010/08/31 01:19:12 | 002,441,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/08/25 14:45:30 | 000,446,544 | —- | M] (Paragon) – C:\Windows\SysNative\drivers\UimFIO.sys
[2010/08/25 14:45:30 | 000,249,936 | —- | M] (Paragon Software Group) – C:\Windows\SysWow64\prgiso.dll
[2010/08/25 14:45:30 | 000,050,768 | —- | M] (Windows ® 2000 DDK provider) – C:\Windows\SysNative\drivers\uimx64.sys
[2010/08/25 14:45:28 | 000,566,864 | —- | M] (Paragon) – C:\Windows\SysNative\drivers\Uim_IMx64.sys
[2010/08/25 14:45:28 | 000,037,456 | —- | M] (Paragon Software Group) – C:\Windows\SysNative\drivers\hotcore3.sys

========== Files Created - No Company Name ==========

[2010/09/18 08:14:35 | 000,001,099 | —- | C] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/09/17 18:47:58 | 000,001,965 | —- | C] () – C:\Users\Joe\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/17 17:44:22 | 000,000,900 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-868716050-2658743674-3616393184-1000UA.job
[2010/09/17 17:44:21 | 000,000,848 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-868716050-2658743674-3616393184-1000Core.job
[2010/09/17 16:42:22 | 000,001,439 | —- | C] () – C:\Users\Joe\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/17 16:40:39 | 000,070,718 | —- | C] () – C:\Users\Joe\Documents\cc_20100917_164022.reg
[2010/09/17 16:19:05 | 000,000,544 | —- | C] () – C:\Windows\tasks\PCDRScheduledMaintenance.job
[2010/09/17 16:08:38 | 000,000,324 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForJoe.job
[2010/09/17 16:02:44 | 000,001,662 | RHS- | C] () – C:\Windows\SysWow64\drivers\103C_HP_CPC_BQ464AA-ABA s5503w_YC_0Pavi_Q4CE020_EA1NAv6PrA8_49_INARRA5_SPEGATRON CORPORATION_V5.00_B5.55_T091208_WUH0_L409_M2815_J320_7AMD_8Sempron 140_92.7_#_N10DE03EF_Z_G10DE03D0.MRK
[2010/09/17 16:02:44 | 000,001,662 | RHS- | C] () – C:\Windows\SysNative\drivers\103C_HP_CPC_BQ464AA-ABA s5503w_YC_0Pavi_Q4CE020_EA1NAv6PrA8_49_INARRA5_SPEGATRON CORPORATION_V5.00_B5.55_T091208_WUH0_L409_M2815_J320_7AMD_8Sempron 140_92.7_#_N10DE03EF_Z_G10DE03D0.MRK
[2010/09/17 16:02:37 | 001,048,576 | -HS- | C] () – C:\Users\Joe\NTUSER.DAT
[2010/09/17 16:02:37 | 000,524,288 | -HS- | C] () – C:\Users\Joe\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/09/17 16:02:37 | 000,524,288 | -HS- | C] () – C:\Users\Joe\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/09/17 16:02:37 | 000,262,144 | -HS- | C] () – C:\Users\Joe\ntuser.dat.LOG1
[2010/09/17 16:02:37 | 000,065,536 | -HS- | C] () – C:\Users\Joe\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/09/17 16:02:37 | 000,000,290 | —- | C] () – C:\Users\Joe\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/09/17 16:02:37 | 000,000,272 | —- | C] () – C:\Users\Joe\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/09/17 16:02:37 | 000,000,020 | -HS- | C] () – C:\Users\Joe\ntuser.ini
[2010/09/17 16:02:37 | 000,000,000 | -HS- | C] () – C:\Users\Joe\ntuser.dat.LOG2
[2009/09/29 18:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/09/17 19:07:07 | 000,000,000 | —D | M] – C:\Users\Joe\AppData\Roaming\AnvSoft
[2010/09/18 08:11:54 | 000,000,000 | —D | M] – C:\Users\Joe\AppData\Roaming\WinBatch
[2010/09/17 16:41:43 | 000,000,544 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2009/07/14 01:08:49 | 000,004,380 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/09/18 08:19:40 | 000,000,125 | —- | M] () – C:\FINIS_IT.TXT
[2010/09/19 03:17:18 | 2213,404,672 | -HS- | M] () – C:\hiberfil.sys
[2006/12/02 02:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2010/09/19 03:17:25 | 2951,208,960 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 15:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/17 16:42:22 | 000,000,221 | -HS- | M] () – C:\Users\Joe\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/09/20 13:25:42 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\Joe\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >



OTL Extras logfile created on: 9/20/2010 1:34:00 PM - Run 1
OTL by OldTimer - Version 3.2.14.0 Folder = C:\Users\Joe\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 287.11 Gb Total Space | 250.42 Gb Free Space | 87.22% Space Free | Partition Type: NTFS
Drive D: | 10.88 Gb Total Space | 1.59 Gb Free Space | 14.57% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: UNIT1
Current User Name: Joe
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"Microsoft Security Essentials" = Microsoft Security Essentials
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"PC-Doctor for Windows" = Hardware Diagnostic Tools

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{34A350D1-64FB-36D8-9D0C-1CD8E392DBA5}" = Google Talk Plugin
"{35021DFB-F9CA-402A-89A2-47F91E506465}" = HP MediaSmart/TouchSmart Netflix
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7FC8C210-A319-4835-A87D-B935EFB4C148}" = Microsoft Live Search Toolbar
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}" = HP MediaSmart Demo
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B60DCA15-56A3-4D2D-8747-22CF7D7B588B}" = HP Support Assistant
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{C268B5E1-A5DA-11DF-A289-005056C00008}" = Paragon Backup & Recovery™ 2010 Free Advanced
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Any Video Converter_is1" = Any Video Converter 3.0.7
"CCleaner" = CCleaner
"DivX Setup.divx.com" = DivX Setup
"HP Remote Solution" = HP Remote Solution
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 9/17/2010 4:04:55 PM | Computer Name = Unit1 | Source = Service Control Manager | ID = 7022
Description = The Windows Search service hung on starting.

Error - 9/17/2010 4:21:56 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 4:23:36 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 4:23:57 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 4:24:06 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 4:24:42 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 4:25:21 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 4:25:42 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 4:25:51 PM | Computer Name = Unit1 | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 9/17/2010 5:57:50 PM | Computer Name = Unit1 | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the NIS service.


< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI