This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect Logs (ATFGooredTDS didnt Work)

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay so I followed the instructions in the pinned thread about google redirects. It didnt work the first time. So i figured maybe I did something wrong and did it again. This worked at first, but I left and came back home and the redirecting was happening again. Here are my goored and tds logs: GooredFix by jpshortstuff (03.07.10.1) Log created at 21:56 on 15/10/2010 (Jeremy) Firefox version 3.5.13 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [05:05 05/10/2009] {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [00:45 29/01/2009] {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [02:39 28/06/2009] {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [05:21 26/08/2009] {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [10:01 28/10/2009] {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [03:15 24/11/2009] {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [22:18 29/04/2010] {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [06:51 12/08/2010] C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\ {73a6fe31-595d-460b-a920-fcc0f8843232} [20:20 09/10/2010] {c1dffba0-628e-11d9-9669-0800200c9a66} [05:10 05/10/2009] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [18:35 18/08/2010] {e4a8a97b-f2ed-450b-b12d-ee082ba24781} [07:05 03/08/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [01:19 03/02/2010] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [22:18 29/04/2010] ———- Old Logs ———- -=E.O.F=- 2010/10/15 21:56:30.0296 TDSS rootkit removing tool 2.4.4.0 Oct 4 2010 09:06:59 2010/10/15 21:56:30.0296 ================================================================================ 2010/10/15 21:56:30.0296 SystemInfo: 2010/10/15 21:56:30.0296 2010/10/15 21:56:30.0296 OS Version: 5.1.2600 ServicePack: 2.0 2010/10/15 21:56:30.0296 Product type: Workstation 2010/10/15 21:56:30.0296 ComputerName: DARKSCOMP 2010/10/15 21:56:30.0312 UserName: Jeremy 2010/10/15 21:56:30.0312 Windows directory: C:\WINDOWS 2010/10/15 21:56:30.0312 System windows directory: C:\WINDOWS 2010/10/15 21:56:30.0312 Processor architecture: Intel x86 2010/10/15 21:56:30.0312 Number of processors: 2 2010/10/15 21:56:30.0312 Page size: 0x1000 2010/10/15 21:56:30.0312 Boot type: Normal boot 2010/10/15 21:56:30.0312 ================================================================================ 2010/10/15 21:56:30.0687 Initialize success 2010/10/15 21:56:33.0218 ================================================================================ 2010/10/15 21:56:33.0218 Scan started 2010/10/15 21:56:33.0218 Mode: Manual; 2010/10/15 21:56:33.0218 ================================================================================ 2010/10/15 21:56:33.0937 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 2010/10/15 21:56:34.0031 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2010/10/15 21:56:34.0125 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2010/10/15 21:56:34.0187 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 2010/10/15 21:56:34.0265 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 2010/10/15 21:56:34.0343 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys 2010/10/15 21:56:34.0390 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys 2010/10/15 21:56:34.0468 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 2010/10/15 21:56:34.0531 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 2010/10/15 21:56:34.0734 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 2010/10/15 21:56:34.0796 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 2010/10/15 21:56:34.0875 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 2010/10/15 21:56:34.0953 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys 2010/10/15 21:56:35.0000 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys 2010/10/15 21:56:35.0078 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 2010/10/15 21:56:35.0156 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 2010/10/15 21:56:35.0218 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 2010/10/15 21:56:35.0250 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 2010/10/15 21:56:35.0312 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2010/10/15 21:56:35.0437 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2010/10/15 21:56:35.0484 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2010/10/15 21:56:35.0531 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2010/10/15 21:56:35.0562 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2010/10/15 21:56:35.0625 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 2010/10/15 21:56:35.0640 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2010/10/15 21:56:35.0671 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 2010/10/15 21:56:35.0687 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2010/10/15 21:56:35.0734 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2010/10/15 21:56:35.0796 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2010/10/15 21:56:35.0843 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 2010/10/15 21:56:35.0921 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 2010/10/15 21:56:36.0015 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 2010/10/15 21:56:36.0078 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 2010/10/15 21:56:36.0140 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 2010/10/15 21:56:36.0203 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2010/10/15 21:56:36.0265 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 2010/10/15 21:56:36.0359 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 2010/10/15 21:56:36.0390 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2010/10/15 21:56:36.0468 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2010/10/15 21:56:36.0515 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 2010/10/15 21:56:36.0562 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2010/10/15 21:56:36.0609 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2010/10/15 21:56:36.0656 e1express (34aaa3b298a852b3663e6e0d94d12945) C:\WINDOWS\system32\DRIVERS\e1e5132.sys 2010/10/15 21:56:36.0734 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2010/10/15 21:56:36.0781 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 2010/10/15 21:56:36.0796 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 2010/10/15 21:56:36.0828 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2010/10/15 21:56:36.0921 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2010/10/15 21:56:36.0968 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2010/10/15 21:56:37.0000 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2010/10/15 21:56:37.0046 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2010/10/15 21:56:37.0093 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2010/10/15 21:56:37.0140 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2010/10/15 21:56:37.0171 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 2010/10/15 21:56:37.0218 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 2010/10/15 21:56:37.0250 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 2010/10/15 21:56:37.0328 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys 2010/10/15 21:56:37.0343 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys 2010/10/15 21:56:37.0390 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys 2010/10/15 21:56:37.0406 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2010/10/15 21:56:37.0546 ialm (28423512370705aeda6a652fedb25468) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 2010/10/15 21:56:37.0750 iaStor (294110966cedd127629c5be48367c8cf) C:\WINDOWS\system32\drivers\iaStor.sys 2010/10/15 21:56:37.0812 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2010/10/15 21:56:37.0859 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 2010/10/15 21:56:37.0984 IntcAzAudAddService (17bbbabb21f86b650b2626045a9d016c) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2010/10/15 21:56:38.0140 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 2010/10/15 21:56:38.0218 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2010/10/15 21:56:38.0250 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2010/10/15 21:56:38.0281 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2010/10/15 21:56:38.0328 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2010/10/15 21:56:38.0375 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2010/10/15 21:56:38.0390 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2010/10/15 21:56:38.0421 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2010/10/15 21:56:38.0500 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2010/10/15 21:56:38.0546 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2010/10/15 21:56:38.0593 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2010/10/15 21:56:38.0656 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 2010/10/15 21:56:38.0687 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys 2010/10/15 21:56:38.0796 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 2010/10/15 21:56:38.0875 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2010/10/15 21:56:38.0906 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 2010/10/15 21:56:38.0937 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 2010/10/15 21:56:39.0000 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2010/10/15 21:56:39.0062 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2010/10/15 21:56:39.0078 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2010/10/15 21:56:39.0140 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 2010/10/15 21:56:39.0187 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2010/10/15 21:56:39.0203 MRxSmb (1fd607fc67f7f7c633c3da65bfc53d18) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2010/10/15 21:56:39.0250 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2010/10/15 21:56:39.0328 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2010/10/15 21:56:39.0484 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2010/10/15 21:56:39.0640 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2010/10/15 21:56:39.0875 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2010/10/15 21:56:40.0093 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2010/10/15 21:56:40.0515 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2010/10/15 21:56:40.0703 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2010/10/15 21:56:40.0750 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2010/10/15 21:56:40.0750 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2010/10/15 21:56:40.0765 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2010/10/15 21:56:40.0796 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2010/10/15 21:56:40.0843 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2010/10/15 21:56:40.0890 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2010/10/15 21:56:40.0921 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 2010/10/15 21:56:40.0968 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2010/10/15 21:56:41.0187 nv (4c3696c1ed1a36629ebb348bf745a328) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2010/10/15 21:56:41.0406 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2010/10/15 21:56:41.0453 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2010/10/15 21:56:41.0500 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 2010/10/15 21:56:41.0531 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2010/10/15 21:56:41.0578 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2010/10/15 21:56:41.0593 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 2010/10/15 21:56:41.0640 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2010/10/15 21:56:41.0687 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 2010/10/15 21:56:41.0812 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 2010/10/15 21:56:41.0875 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 2010/10/15 21:56:41.0937 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2010/10/15 21:56:42.0000 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2010/10/15 21:56:42.0031 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2010/10/15 21:56:42.0093 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2010/10/15 21:56:42.0140 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 2010/10/15 21:56:42.0203 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 2010/10/15 21:56:42.0265 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 2010/10/15 21:56:42.0312 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 2010/10/15 21:56:42.0359 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 2010/10/15 21:56:42.0406 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2010/10/15 21:56:42.0437 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2010/10/15 21:56:42.0484 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2010/10/15 21:56:42.0500 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2010/10/15 21:56:42.0546 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2010/10/15 21:56:42.0562 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2010/10/15 21:56:42.0625 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2010/10/15 21:56:42.0687 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 2010/10/15 21:56:42.0765 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/10/15 21:56:42.0812 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 2010/10/15 21:56:42.0843 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 2010/10/15 21:56:42.0953 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2010/10/15 21:56:42.0984 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 2010/10/15 21:56:43.0015 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys 2010/10/15 21:56:43.0078 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2010/10/15 21:56:43.0140 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys 2010/10/15 21:56:43.0203 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 2010/10/15 21:56:43.0265 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 2010/10/15 21:56:43.0312 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 2010/10/15 21:56:43.0343 Srv (20b7e396720353e4117d64d9dcb926ca) C:\WINDOWS\system32\DRIVERS\srv.sys 2010/10/15 21:56:43.0375 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2010/10/15 21:56:43.0406 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2010/10/15 21:56:43.0468 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 2010/10/15 21:56:43.0531 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 2010/10/15 21:56:43.0609 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 2010/10/15 21:56:43.0640 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 2010/10/15 21:56:43.0750 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2010/10/15 21:56:43.0812 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2010/10/15 21:56:43.0828 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2010/10/15 21:56:43.0875 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2010/10/15 21:56:43.0921 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2010/10/15 21:56:43.0984 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 2010/10/15 21:56:44.0078 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2010/10/15 21:56:44.0125 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 2010/10/15 21:56:44.0187 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 2010/10/15 21:56:44.0250 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2010/10/15 21:56:44.0281 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2010/10/15 21:56:44.0343 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2010/10/15 21:56:44.0375 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2010/10/15 21:56:44.0406 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2010/10/15 21:56:44.0453 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2010/10/15 21:56:44.0484 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys 2010/10/15 21:56:44.0546 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 2010/10/15 21:56:44.0593 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 2010/10/15 21:56:44.0640 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2010/10/15 21:56:44.0734 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 2010/10/15 21:56:44.0796 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 2010/10/15 21:56:44.0875 WpdUsb (1385e5aa9c9821790d33a9563b8d2dd0) C:\WINDOWS\system32\Drivers\wpdusb.sys 2010/10/15 21:56:44.0921 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 2010/10/15 21:56:44.0984 ================================================================================ 2010/10/15 21:56:44.0984 Scan finished 2010/10/15 21:56:44.0984 ================================================================================ 2010/10/15 21:56:48.0406 Deinitialize success any help anyone can provide would be appreciated. This is really getting old.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post




Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.







[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
I had some difficulties with GMER but it finally ran all the way through. The first time it froze, so I ran it without drivers and it didn't. However it gave me a blue screen saying there was a fatal error with fftcipow.sys I shut off the computer and restarted. It ran through the third time. Those results are included. Thanks for all of the help I appreciate it.

Extras:

OTL Extras logfile created on: 10/17/2010 11:59:18 AM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Jeremy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 550.00 Mb Available Physical Memory | 54.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.77 Gb Total Space | 137.41 Gb Free Space | 59.80% Space Free | Partition Type: NTFS

Computer Name: DARKSCOMP | User Name: Jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service discovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client – ()
"C:\Program Files\DivX\DivX Converter\Converter.exe" = C:\Program Files\DivX\DivX Converter\Converter.exe:*:Disabled:Converter – (DivX, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader – File not found
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\Launcher.exe" = C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – File not found
"C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader – File not found
"C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader – File not found
"C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe" = C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe:*:Enabled:Blizzard Downloader – File not found
"C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe" = C:\Documents and Settings\Jeremy\Desktop\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe:*:Enabled:Blizzard Downloader – File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL LLC)
"C:\Documents and Settings\Jeremy\Local Settings\Apps\2.0\PGRKX08H.6GX\YENP562C.T5G\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe" = C:\Documents and Settings\Jeremy\Local Settings\Apps\2.0\PGRKX08H.6GX\YENP562C.T5G\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe:*:Enabled:Curse Client 4.0 – File not found
"C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\Dragon Age\bin_ship\daorigins.exe" = C:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game – (BioWare)
"C:\Program Files\Dragon Age\DAOriginsLauncher.exe" = C:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher – (BioWare)
"C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe" = C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater – (BioWare)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}" = Dell DataSafe Online
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C252EB7B-7AE0-46DE-9BEE-DF681B885F13}" = Modem Diagnostic Tool
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D25F26E6-7F37-4580-9E83-2BDD9BE9E0CE}" = BlackBerry Desktop Software 6.0
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_7" = AIM 7
"Army Builder V3.2d" = Army Builder V3.2d
"Audacity_is1" = Audacity 1.2.6
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"CurseClient" = Curse Client
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"EsetOnlineScanner" = ESET Online Scanner
"FLV Player" = FLV Player 2.0 (build 25)
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla ActiveX Control v1.7.12" = Mozilla ActiveX Control v1.7.12
"Mozilla Firefox (3.5.13)" = Mozilla Firefox (3.5.13)
"MyITLab ActiveX Installer_is1" = MyITLab ActiveX Installer 2, 9, 8, 65535
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Orbit_is1" = Orbit Downloader
"PokerStars" = PokerStars
"PROSet" = Intel® PRO Network Connections Drivers
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"StarCraft II" = StarCraft II
"VASSAL (3.1.14)" = VASSAL (3.1.14)
"VLC media player" = VLC media player 1.1.2
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Facebook Plug-In" = Facebook Plug-In
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/26/2010 2:57:59 PM | Computer Name = DARKSCOMP | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.1.3523, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 8/28/2010 1:44:41 PM | Computer Name = DARKSCOMP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/28/2010 1:44:41 PM | Computer Name = DARKSCOMP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/30/2010 2:53:42 AM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application divxupdate.exe, version 1.0.1.10, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Error - 9/6/2010 7:00:17 PM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application aim.exe, version 7.1.6.4, faulting module unknown,
version 0.0.0.0, fault address 0x00002606.

Error - 9/8/2010 8:21:53 PM | Computer Name = DARKSCOMP | Source = Application Hang | ID = 1002
Description = Hanging application Wow.exe, version 3.3.5.12340, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/10/2010 12:46:08 PM | Computer Name = DARKSCOMP | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.1.3834, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/16/2010 10:50:45 AM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application backgrounddownloader.exe, version 2.2.0.1092,
faulting module backgrounddownloader.exe, version 2.2.0.1092, fault address 0x0002c0dc.

Error - 9/20/2010 12:48:24 PM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application backgrounddownloader.exe, version 2.2.0.1092,
faulting module backgrounddownloader.exe, version 2.2.0.1092, fault address 0x0002c0dc.

Error - 9/20/2010 7:16:08 PM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application backgrounddownloader.exe, version 2.2.0.1092,
faulting module backgrounddownloader.exe, version 2.2.0.1092, fault address 0x0002c0dc.

[ System Events ]
Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/17/2010 2:07:38 AM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083


< End of report >

OTL:

OTL logfile created on: 10/17/2010 11:59:18 AM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Jeremy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 550.00 Mb Available Physical Memory | 54.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.77 Gb Total Space | 137.41 Gb Free Space | 59.80% Space Free | Partition Type: NTFS

Computer Name: DARKSCOMP | User Name: Jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jeremy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jeremy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (OMCI) – C:\WINDOWS\System32\DRIVERS\OMCI.SYS File not found
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6071210
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6071210

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "yahoo.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.3.3
FF - prefs.js..extensions.enabledItems: {c1dffba0-628e-11d9-9669-0800200c9a66}:3.5.0


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/18 15:43:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/06 12:58:20 | 000,000,000 | —D | M]

[2009/10/05 00:05:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Extensions
[2010/10/16 11:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions
[2010/10/09 15:20:24 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/10/05 00:10:17 | 000,000,000 | —D | M] (PitchDark) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2010/08/18 13:35:56 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/03 02:05:29 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/10/16 11:17:26 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/29 17:18:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/12 01:51:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/10/08 12:53:29 | 000,420,902 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14540 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Jeremy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: aol.com ([kdc.uas] https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1245991674359 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab (Enlite 2.x Simulation Engine Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{b468c708-578a-11de-8a10-001d09795794}\Shell - "" = AutoRun
O33 - MountPoints2\{b468c708-578a-11de-8a10-001d09795794}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b468c708-578a-11de-8a10-001d09795794}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.444p - C:\Program Files\t@b\0.958\686\tabdec.dll File not found
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.mpng - C:\Program Files\t@b\0.958\686\tabdec.dll File not found
Drivers32: vidc.mvjp - C:\Program Files\t@b\0.958\686\tabdec.dll File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)

========== Files/Folders - Created Within 30 Days ==========

[2010/10/17 11:53:55 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2010/10/14 12:25:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\Desktop\GooredFix Backups
[2010/10/14 12:19:31 | 001,325,656 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Jeremy\Desktop\TDSSKiller.exe
[2010/10/13 16:17:03 | 000,071,398 | —- | C] (jpshortstuff) – C:\Documents and Settings\Jeremy\Desktop\GooredFix.exe
[2010/10/09 00:49:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/09 00:49:21 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/09 00:49:21 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/09 00:46:36 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Jeremy\Desktop\mbam-setup-1.46.exe
[2010/10/07 19:47:20 | 000,241,152 | —- | C] (Simon Tatham) – C:\WINDOWS\Ymyzua.exe
[2010/10/05 12:52:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport_files
[2010/10/05 09:10:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\Application Data\Research In Motion
[2010/10/05 09:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/10/05 09:09:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Research In Motion
[2010/10/05 09:09:41 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion
[2010/10/04 19:24:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/09/21 21:15:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jeremy\Recent
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/17 11:55:18 | 000,285,230 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\gmer.zip
[2010/10/17 11:53:59 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2010/10/16 23:20:34 | 000,000,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/10/16 15:22:18 | 000,254,654 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/10/16 15:22:07 | 000,000,306 | -HS- | M] () – C:\WINDOWS\tasks\Xotzfgjuc.job
[2010/10/16 15:22:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/16 15:22:02 | 1071,824,896 | -HS- | M] () – C:\hiberfil.sys
[2010/10/15 21:58:21 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/15 18:06:38 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/10/15 18:05:50 | 000,293,376 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\gmer.exe
[2010/10/13 16:17:14 | 000,071,398 | —- | M] (jpshortstuff) – C:\Documents and Settings\Jeremy\Desktop\GooredFix.exe
[2010/10/09 14:39:41 | 000,012,811 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 140 Assignment 1.docx
[2010/10/09 00:49:33 | 000,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/09 00:47:14 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Jeremy\Desktop\mbam-setup-1.46.exe
[2010/10/08 12:53:29 | 000,420,902 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/08 12:37:14 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/07 19:53:06 | 000,062,464 | RHS- | M] () – C:\WINDOWS\System32\iernonceu.dll
[2010/10/07 19:47:13 | 000,241,152 | —- | M] (Simon Tatham) – C:\WINDOWS\Ymyzua.exe
[2010/10/06 12:58:21 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/10/05 12:52:16 | 000,123,849 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport.htm
[2010/10/05 09:10:03 | 000,001,967 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/04 19:22:20 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/10/04 18:47:14 | 000,013,470 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 3.docx
[2010/10/04 09:08:00 | 001,325,656 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Jeremy\Desktop\TDSSKiller.exe
[2010/09/21 21:20:54 | 000,001,481 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\DivX Movies.lnk
[2010/09/21 21:20:46 | 000,000,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/09/21 21:16:46 | 000,447,134 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/21 21:16:46 | 000,073,620 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/21 14:23:01 | 000,000,818 | —- | M] () – C:\Documents and Settings\Jeremy\Application Data\wklnhst.dat
[2010/09/21 00:11:18 | 000,011,938 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 2.docx
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/17 11:57:22 | 000,293,376 | —- | C] () – C:\Documents and Settings\Jeremy\Desktop\gmer.exe
[2010/10/17 11:55:17 | 000,285,230 | —- | C] () – C:\Documents and Settings\Jeremy\Desktop\gmer.zip
[2010/10/09 14:39:41 | 000,012,811 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 140 Assignment 1.docx
[2010/10/09 00:49:33 | 000,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/07 19:53:08 | 000,000,306 | -HS- | C] () – C:\WINDOWS\tasks\Xotzfgjuc.job
[2010/10/07 19:53:06 | 000,062,464 | RHS- | C] () – C:\WINDOWS\System32\iernonceu.dll
[2010/10/05 12:52:15 | 000,123,849 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport.htm
[2010/10/05 09:10:51 | 000,000,077 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\Rim.Desktop.Exception.log
[2010/10/05 09:10:09 | 000,000,759 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\Rim.Desktop.HttpServerSetup.log
[2010/10/05 09:10:03 | 000,001,967 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/04 18:30:34 | 000,013,470 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 3.docx
[2010/09/20 12:34:22 | 000,011,938 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 2.docx
[2010/02/02 20:19:38 | 000,402,928 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/12/31 01:08:42 | 000,000,040 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ra3.ini
[2009/09/02 17:14:31 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/25 16:34:01 | 000,000,267 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp1v1.cab
[2009/06/25 16:34:01 | 000,000,016 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp1v2.cab
[2009/06/25 16:33:54 | 000,000,189 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp2v1.cab
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/29 14:57:08 | 000,000,818 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\wklnhst.dat
[2008/07/09 12:28:43 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/09 12:28:43 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/09 12:28:43 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/07/06 19:25:02 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/05/30 12:22:22 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/02/11 10:39:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 10:39:18 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/10 17:35:05 | 000,032,256 | —- | C] () – C:\Documents and Settings\Jeremy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/08 14:53:46 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/12/10 01:11:00 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/12/10 01:03:53 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/12/10 00:38:53 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2007/12/10 00:37:29 | 000,001,028 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/07/27 15:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 15:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2005/12/05 20:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 13:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/04 05:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys

========== LOP Check ==========

[2010/01/28 01:14:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/06/29 19:39:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BioWare
[2009/09/17 22:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\myitlab
[2010/10/05 09:09:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2009/05/18 22:03:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/10/02 01:26:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/12/10 01:07:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/06/25 16:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/13 12:29:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/01/28 01:14:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\acccore
[2009/01/26 15:25:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Aim
[2010/03/19 22:38:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Facebook
[2008/08/11 08:32:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\LimeWire
[2010/10/08 04:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Orbit
[2009/12/28 01:09:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Red Alert 3
[2010/10/05 09:11:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Research In Motion
[2008/09/29 14:57:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Template
[2009/11/05 17:57:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\uTorrent
[2010/10/16 15:22:07 | 000,000,306 | -HS- | M] () – C:\WINDOWS\Tasks\Xotzfgjuc.job

========== Purity Check ==========



========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2009/01/13 12:51:54 | 000,000,000 | —- | M] () – C:\asdasd.asdasd
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/07/07 11:38:10 | 000,000,211 | —- | M] () – C:\Boot.bak
[2009/01/24 13:29:53 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/06/28 16:21:44 | 000,018,374 | —- | M] () – C:\ComboFix.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/12/10 00:41:18 | 000,007,049 | RH– | M] () – C:\dell.sdr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/10/16 15:22:02 | 1071,824,896 | -HS- | M] () – C:\hiberfil.sys
[2008/08/27 23:44:18 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/01/28 01:14:29 | 000,001,262 | -H– | M] () – C:\IPH.PH
[2008/03/20 00:31:32 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 05:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/10/16 15:21:56 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/01/13 13:15:05 | 000,000,058 | —- | M] () – C:\proc.id
[2010/10/14 12:19:55 | 000,043,286 | —- | M] () – C:\TDSSKiller.2.4.4.0_14.10.2010_12.19.35_log.txt
[2010/10/14 12:25:33 | 000,043,286 | —- | M] () – C:\TDSSKiller.2.4.4.0_14.10.2010_12.25.13_log.txt
[2010/10/15 21:56:48 | 000,043,286 | —- | M] () – C:\TDSSKiller.2.4.4.0_15.10.2010_21.56.30_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/07/07 11:46:55 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/07/07 06:31:39 | 001,835,008 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/07/07 11:23:15 | 000,045,056 | —- | M] () – C:\WINDOWS\system32\config\security.sav
[2008/07/07 06:31:39 | 033,554,432 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/07/07 06:31:41 | 005,505,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/07 11:47:13 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/12/24 21:12:44 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 14:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/06/06 13:10:08 | 008,926,783 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\ab32d_install.exe
[2009/06/25 17:09:29 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Jeremy\Desktop\ATF_Cleaner.exe
[2010/08/15 14:44:49 | 008,573,648 | —- | M] (Mozilla) – C:\Documents and Settings\Jeremy\Desktop\Firefox Setup 3.6.8.exe
[2010/10/15 18:05:50 | 000,293,376 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\gmer.exe
[2010/10/13 16:17:14 | 000,071,398 | —- | M] (jpshortstuff) – C:\Documents and Settings\Jeremy\Desktop\GooredFix.exe
[2010/10/09 00:47:14 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Jeremy\Desktop\mbam-setup-1.46.exe
[2009/10/23 03:48:05 | 001,407,680 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\MoveMediaPlayerWin_071505000010.exe
[2010/10/17 11:53:59 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2009/06/30 00:46:09 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Jeremy\Desktop\spybotsd162.exe
[2010/10/04 09:08:00 | 001,325,656 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Jeremy\Desktop\TDSSKiller.exe
[2008/08/21 06:31:59 | 001,038,787 | —- | M] (Blizzard Entertainment) – C:\Documents and Settings\Jeremy\Desktop\WoW-BurningCrusade-Trial-enUS-Installer-downloader.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2007/12/24 21:42:27 | 006,026,816 | —- | M] (Mozilla) – C:\Documents and Settings\Jeremy\My Documents\Firefox Setup 2[1].0.0.11.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2004/08/04 06:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2007/12/24 21:12:43 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Jeremy\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/10/17 11:58:07 | 000,212,992 | -HS- | M] () – C:\Documents and Settings\Jeremy\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-07-07 00:25:11

< End of report >


GMER:

GMER 1.0.15.15319 - http://www.gmer.net
Rootkit scan 2010-10-17 14:07:10
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Jeremy\LOCALS~1\Temp\fftcipow.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF66B3360, 0x3E57A5, 0xE8000020]

—- EOF - GMER 1.0.15 —-
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Combofix never restarted my computer so I don't know if it actually removed anything, however the redirects have stopped. As of now. ComboFix 10-10-17.04 - Jeremy 10/18/2010 15:13:08.4.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.771 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Install.exe c:\windows\run.log . ((((((((((((((((((((((((( Files Created from 2010-09-18 to 2010-10-18 ))))))))))))))))))))))))))))))) . 2010-10-09 05:49 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-09 05:49 . 2010-10-09 05:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-10-09 05:49 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-10-08 00:53 . 2010-10-08 00:53 62464 –sha-r- c:\windows\system32\iernonceu.dll 2010-10-08 00:47 . 2010-10-08 00:47 241152 —-a-w- c:\windows\Ymyzua.exe 2010-10-05 14:10 . 2010-10-05 14:11 ——– d—–w- c:\documents and settings\Jeremy\Application Data\Research In Motion 2010-10-05 14:10 . 2009-01-09 22:18 27136 —-a-r- c:\windows\system32\drivers\RimSerial.sys 2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Research In Motion 2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\program files\Common Files\Research In Motion 2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\program files\Research In Motion 2010-10-05 00:24 . 2010-10-05 00:24 ——– d—–w- c:\program files\Common Files\Skype 2010-09-23 19:42 . 2010-09-23 19:42 95672 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008] "RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2004-08-04 53760] c:\documents and settings\Jeremy\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-10 24576] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Curse\\CurseClient.exe"= "c:\\Program Files\\DivX\\DivX Converter\\Converter.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\Launcher.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"= "c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= "c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"= "c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009 S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [6/29/2010 4:51 PM 25832] . Contents of the 'Scheduled Tasks' folder . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201 IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204 IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202 IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000 Trusted Zone: aol.com\kdc.uas DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - ProfilePath - c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\ FF - prefs.js: browser.startup.homepage - yahoo.com FF - plugin: c:\documents and settings\Jeremy\Application Data\Facebook\npfbplugin_1_0_1.dll FF - plugin: c:\documents and settings\Jeremy\Application Data\Facebook\npfbplugin_1_0_3.dll FF - plugin: c:\documents and settings\Jeremy\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); . - - - - ORPHANS REMOVED - - - - Toolbar-SITEguard - (no file) HKLM-Run-nwiz - c:\program files\NVIDIA Corporation\nView\nwiz.exe AddRemove-NVIDIA nView Desktop Manager - c:\program files\NVIDIA Corporation\nView\nViewSetup.exe AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-3838388586-3754024616-3633734521-1006\Software\SecuROM\License information*] "datasecu"=hex:5b,e9,7c,8f,7b,e1,d1,70,dd,44,91,9c,48,48,c0,83,27,d1,03,96,9e, b3,84,b0,bf,21,41,ea,7b,6e,ac,55,6f,ab,6f,fd,60,64,11,36,0e,41,80,5e,73,0b,\ "rkeysecu"=hex:0b,af,8a,d7,c5,2e,48,29,68,b4,a2,96,f4,d8,26,81 . Completion time: 2010-10-18 15:18:12 ComboFix-quarantined-files.txt 2010-10-18 20:18 ComboFix2.txt 2009-06-28 21:21 Pre-Run: 147,374,166,016 bytes free Post-Run: 147,331,039,232 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - 67F41CAA70F8E3A6075EBF36A383F861
Please navigate to C:\qoobox\combofix2.txt and post this log.




  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.






Next

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
ComboFix 09-06-26.02 - Jeremy 06/28/2009 16:18.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1013.717 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jeremy\Desktop\CFScript.txt

file zipped: c:\windows\system32\badufega.dll
file zipped: c:\windows\system32\basibezo.dll
file zipped: c:\windows\system32\biranoma.dll
file zipped: c:\windows\system32\bokabero.dll
file zipped: c:\windows\system32\dezupiye.dll
file zipped: c:\windows\system32\dikijowa.exe
file zipped: c:\windows\system32\dikutime.dll
file zipped: c:\windows\system32\duloteko.dll
file zipped: c:\windows\system32\fugopuno.dll
file zipped: c:\windows\system32\furoyuwe.dll
file zipped: c:\windows\system32\gapiyivi.dll
file zipped: c:\windows\system32\genohije.dll
file zipped: c:\windows\system32\gizitefo.dll
file zipped: c:\windows\system32\goluwuwe.dll
file zipped: c:\windows\system32\gosotopu.dll
file zipped: c:\windows\system32\hewalote.dll
file zipped: c:\windows\system32\hewipali.dll
file zipped: c:\windows\system32\hodeheba.exe
file zipped: c:\windows\system32\huvizuba.dll
file zipped: c:\windows\system32\javisenu.dll
file zipped: c:\windows\system32\jekegoke.dll
file zipped: c:\windows\system32\juhumuyo.dll
file zipped: c:\windows\system32\kawuruji.dll
file zipped: c:\windows\system32\kazovovi.dll
file zipped: c:\windows\system32\kisebuyu.exe
file zipped: c:\windows\system32\kovibele.exe
file zipped: c:\windows\system32\kusumiwi.dll
file zipped: c:\windows\system32\lemowate.dll
file zipped: c:\windows\system32\lubiguwi.dll
file zipped: c:\windows\system32\mapodaba.dll
file zipped: c:\windows\system32\marotiri.dll
file zipped: c:\windows\system32\moyomego.dll
file zipped: c:\windows\system32\nepodolu.exe
file zipped: c:\windows\system32\niketota.dll
file zipped: c:\windows\system32\nobetalu.exe
file zipped: c:\windows\system32\nohijubi.dll
file zipped: c:\windows\system32\patevape.dll
file zipped: c:\windows\system32\pemukevu.dll
file zipped: c:\windows\system32\penosika.exe
file zipped: c:\windows\system32\pigirayo.dll
file zipped: c:\windows\system32\redutuye.dll
file zipped: c:\windows\system32\rehenano.dll
file zipped: c:\windows\system32\rehikuru.dll
file zipped: c:\windows\system32\ritimubu.dll
file zipped: c:\windows\system32\sefinemu.dll
file zipped: c:\windows\system32\segaleni.exe
file zipped: c:\windows\system32\sohirobe.dll
file zipped: c:\windows\system32\tatoyame.dll
file zipped: c:\windows\system32\tawulani.dll
file zipped: c:\windows\system32\tobogibi.dll
file zipped: c:\windows\system32\vakefiyo.dll
file zipped: c:\windows\system32\vetagama.dll
file zipped: c:\windows\system32\vubumega.dll
file zipped: c:\windows\system32\wirahahe.dll
file zipped: c:\windows\system32\wuputile.dll
file zipped: c:\windows\system32\yalomito.dll
file zipped: c:\windows\system32\yenafute.dll
file zipped: c:\windows\system32\yurowebo.dll
file zipped: c:\windows\system32\zavegasa.dll
file zipped: c:\windows\system32\zeguyezo.dll
file zipped: c:\windows\system32\zetonadu.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\badufega.dll
c:\windows\system32\basibezo.dll
c:\windows\system32\biranoma.dll
c:\windows\system32\bokabero.dll
c:\windows\system32\dezupiye.dll
c:\windows\system32\dikijowa.exe
c:\windows\system32\dikutime.dll
c:\windows\system32\drivers\SKYNETjetkdwqi.sys
c:\windows\system32\duloteko.dll
c:\windows\system32\fugopuno.dll
c:\windows\system32\furoyuwe.dll
c:\windows\system32\gapiyivi.dll
c:\windows\system32\genohije.dll
c:\windows\system32\gizitefo.dll
c:\windows\system32\goluwuwe.dll
c:\windows\system32\gosotopu.dll
c:\windows\system32\hewalote.dll
c:\windows\system32\hewipali.dll
c:\windows\system32\hodeheba.exe
c:\windows\system32\huvizuba.dll
c:\windows\system32\javisenu.dll
c:\windows\system32\jekegoke.dll
c:\windows\system32\juhumuyo.dll
c:\windows\system32\kawuruji.dll
c:\windows\system32\kazovovi.dll
c:\windows\system32\kisebuyu.exe
c:\windows\system32\kovibele.exe
c:\windows\system32\kusumiwi.dll
c:\windows\system32\lemowate.dll
c:\windows\system32\lubiguwi.dll
c:\windows\system32\mapodaba.dll
c:\windows\system32\marotiri.dll
c:\windows\system32\moyomego.dll
c:\windows\system32\nepodolu.exe
c:\windows\system32\niketota.dll
c:\windows\system32\nobetalu.exe
c:\windows\system32\nohijubi.dll
c:\windows\system32\patevape.dll
c:\windows\system32\pemukevu.dll
c:\windows\system32\penosika.exe
c:\windows\system32\pigirayo.dll
c:\windows\system32\redutuye.dll
c:\windows\system32\rehenano.dll
c:\windows\system32\rehikuru.dll
c:\windows\system32\ritimubu.dll
c:\windows\system32\sefinemu.dll
c:\windows\system32\segaleni.exe
c:\windows\system32\SKYNETnmfwxbfp.dat
c:\windows\system32\SKYNETntymothe.dll
c:\windows\system32\SKYNETpyxenill.dll
c:\windows\system32\SKYNETxuxxvrev.dat
c:\windows\system32\sohirobe.dll
c:\windows\system32\tatoyame.dll
c:\windows\system32\tawulani.dll
c:\windows\system32\tobogibi.dll
c:\windows\system32\vakefiyo.dll
c:\windows\system32\vetagama.dll
c:\windows\system32\vubumega.dll
c:\windows\system32\wirahahe.dll
c:\windows\system32\wuputile.dll
c:\windows\system32\yalomito.dll
c:\windows\system32\yenafute.dll
c:\windows\system32\yurowebo.dll
c:\windows\system32\zavegasa.dll
c:\windows\system32\zeguyezo.dll
c:\windows\system32\zetonadu.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETpfvkosrr


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 )))))))))))))))))))))))))))))))
.

2009-06-28 02:38 . 2009-06-28 02:38 152576 —-a-w- c:\documents and settings\Jeremy\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-26 20:35 . 2009-06-26 20:35 ——– dc—-w- c:\windows\system32\dllcache\cache
2009-06-25 21:53 . 2009-06-25 21:53 ——– d—–w- c:\program files\ERUNT
2009-06-16 08:30 . 2009-06-16 09:51 ——– d—–w- c:\documents and settings\Jeremy\Local Settings\Application Data\FullTiltPoker
2009-06-16 08:29 . 2009-06-25 21:30 ——– d—–w- c:\program files\Full Tilt Poker
2009-06-07 20:13 . 2009-06-07 20:13 ——– d—–w- c:\program files\STOPzilla!
2009-05-30 03:47 . 2009-06-25 22:31 ——– d—–w- c:\documents and settings\Jeremy\Local Settings\Application Data\CurseClient
2009-05-30 03:46 . 2009-05-30 03:46 ——– d—–w- c:\program files\Curse

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 21:16 . 2008-07-09 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-06-28 21:16 . 2009-06-27 06:26 1120 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-06-28 21:16 . 2009-06-27 09:05 424 —-a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-06-28 02:38 . 2007-12-10 05:56 ——– d—–w- c:\program files\Java
2009-06-27 06:25 . 2007-12-25 02:21 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-27 06:25 . 2007-12-25 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-25 22:12 . 2009-01-13 18:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-25 22:12 . 2009-01-20 15:45 3561743 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 21:31 . 2007-12-27 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-25 21:31 . 2008-08-25 03:30 ——– d—–w- c:\program files\Viewpoint
2009-06-25 21:31 . 2007-12-10 06:04 ——– d—–w- c:\program files\CyberLink
2009-06-25 21:31 . 2007-12-10 05:58 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-25 21:28 . 2008-07-09 19:58 ——– d—–w- c:\program files\Diablo II
2009-06-17 16:27 . 2009-01-13 18:44 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 16:27 . 2009-01-13 18:44 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-05 03:39 . 2007-12-25 03:19 ——– d—–w- c:\program files\World of Warcraft
2009-05-28 19:16 . 2009-05-28 19:16 17408 —-a-r- c:\windows\system32\SZIO5.dll
2009-05-28 19:15 . 2009-05-28 19:15 294912 —-a-r- c:\windows\system32\SZBase5.dll
2009-05-28 19:14 . 2009-05-28 19:14 540672 —-a-r- c:\windows\system32\SZComp5.dll
2009-05-21 16:33 . 2009-01-29 00:45 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-19 03:03 . 2008-07-09 01:24 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2009-05-12 19:13 . 2009-05-12 19:13 61328 —-a-r- c:\windows\system32\drivers\SZKG.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

— c:\windows\system32\drivers\SZKG.sys —
Company: iS3 Inc.
File Description: szkg Device Driver
File Version: 2.40.0
Product Name: Stopzilla
Copyright: Copyright ©2005-2009 iS3 Inc . All rights reserved.
Original Filename: szkg.sys
File size: 61328
Created time: 2009-05-12 19:13
Modified time: 2009-05-12 19:13
MD5: 2BB7C951BF74183A67EFAAF614823076
SHA1: 428F29DB82ED6BB490F3D3F5E0E7D2EA9659393F


((((((((((((((((((((((((((((( SnapShot@2009-06-26_20.33.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-28 21:17 . 2009-06-28 21:17 16384 c:\windows\temp\Perflib_Perfdata_198.dat
+ 2009-06-26 20:35 . 2008-10-16 19:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2007-12-25 02:09 . 2009-06-27 09:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-25 02:09 . 2009-06-26 05:07 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-25 02:09 . 2009-06-27 09:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-25 02:09 . 2009-06-26 05:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-25 02:09 . 2009-06-27 09:05 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-12-25 02:09 . 2009-06-26 05:07 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-06-28 02:39 . 2009-05-21 16:34 148888 c:\windows\system32\javaws.exe
- 2009-01-29 00:45 . 2009-01-29 00:45 148888 c:\windows\system32\javaws.exe
+ 2009-06-28 02:39 . 2009-05-21 16:34 144792 c:\windows\system32\javaw.exe
- 2009-01-29 00:45 . 2009-01-29 00:45 144792 c:\windows\system32\javaw.exe
+ 2009-06-28 02:39 . 2009-05-21 16:34 144792 c:\windows\system32\java.exe
- 2009-01-29 00:45 . 2009-01-29 00:45 144792 c:\windows\system32\java.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-26 20:35 . 2006-03-04 03:33 658432 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 577024 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-26 20:35 . 2004-08-04 11:00 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 359040 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 983552 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-27 06:26 . 2009-06-27 06:26 180224 c:\windows\ERDNT\AutoBackup\6-27-2009\Users\00000002\UsrClass.dat
+ 2009-06-27 06:26 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\6-27-2009\ERDNT.EXE
+ 2009-06-26 20:35 . 2004-08-04 10:00 1580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-26 20:35 . 2005-03-30 01:21 2135552 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-26 20:35 . 2005-03-30 01:01 2015232 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 1032192 c:\windows\system32\dllcache\cache\explorer.exe
+ 2009-06-27 06:26 . 2009-06-27 06:26 4599808 c:\windows\ERDNT\AutoBackup\6-27-2009\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-04-26 16132608]

c:\documents and settings\Jeremy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-10 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\DivX\\DivX Converter\\Converter.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R2 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
Trusted Zone: aol.com\kdc.uas
FF - ProfilePath - c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\4h69vi0i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-28 16:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(764)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
.
Completion time: 2009-06-28 16:21
ComboFix-quarantined-files.txt 2009-06-28 21:21
ComboFix2.txt 2009-06-26 20:36

Pre-Run: 200,164,208,640 bytes free
Post-Run: 200,248,819,712 bytes free

304 — E O F — 2008-07-07 00:25




Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4878

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

10/19/2010 2:00:08 AM
mbam-log-2010-10-19 (02-00-08).txt

Scan type: Quick scan
Objects scanned: 138305
Time elapsed: 5 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Ymyzua.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.







ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=cb777706997ed94eaa32f03cef85fd90
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-10-19 07:56:29
# local_time=2010-10-19 02:56:29 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 54606541 54606541 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=78540
# found=4
# cleaned=0
# scan_time=2620
C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\10\35ace28a-40fe5d39 probably a variant of Win32/Agent.LMMBFXF trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74031c8a multiple threats 00000000000000000000000000000000 I
C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\8\4cafbd48-21e773ea probably a variant of Win32/Agent.LMMBFXF trojan 00000000000000000000000000000000 I
C:\Downloads\Setup.exe a variant of Win32/Adware.RegistryEasy application 00000000000000000000000000000000 I
Please scan the following files

c:\windows\system32\iernonceu.dll



  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: here
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".
  • Please provide the results from the scans in your next reply.



Next

Please re run OTL and post the log.
I don't have a file at the location c:\windows\system32\iernonceu.dll
I do however have a file very similar to that: c:\windows\system32\iernonce.dll

I don't think that is what you wanted but I ran a scan on that just in case there was a typo.
File name:
iernonce.dll
Submission date:
2010-10-19 20:01:53 (UTC)
Current status:
queued (#10) queued analysing finished
Result:
0/ 43 (0.0%)

I ran OTL the same way we did the first time, I hope that's what you meant. I didn't know if I was supposed to do the custom scan again or not; so I just did it all exactly the same.




OTL logfile created on: 10/19/2010 3:10:52 PM - Run 2
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Jeremy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 474.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.77 Gb Total Space | 135.27 Gb Free Space | 58.87% Space Free | Partition Type: NTFS
Drive D: | 6.99 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: DARKSCOMP | User Name: Jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jeremy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jeremy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (OMCI) – C:\WINDOWS\System32\DRIVERS\OMCI.SYS File not found
DRV - (catchme) – C:\DOCUME~1\Jeremy\LOCALS~1\Temp\catchme.sys File not found
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6071210
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6071210

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "yahoo.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.3.5
FF - prefs.js..extensions.enabledItems: {c1dffba0-628e-11d9-9669-0800200c9a66}:3.5.0


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/18 15:43:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/06 12:58:20 | 000,000,000 | —D | M]

[2009/10/05 00:05:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Extensions
[2010/10/18 15:59:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions
[2010/10/18 15:59:29 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/10/05 00:10:17 | 000,000,000 | —D | M] (PitchDark) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2010/08/18 13:35:56 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/03 02:05:29 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/10/18 15:59:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/29 17:18:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/12 01:51:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/10/18 15:16:45 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Jeremy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: aol.com ([kdc.uas] https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1245991674359 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab (Enlite 2.x Simulation Engine Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/05/24 23:56:52 | 000,000,046 | RH– | M] () - D:\autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.444p - C:\Program Files\t@b\0.958\686\tabdec.dll File not found
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.mpng - C:\Program Files\t@b\0.958\686\tabdec.dll File not found
Drivers32: vidc.mvjp - C:\Program Files\t@b\0.958\686\tabdec.dll File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)

========== Files/Folders - Created Within 30 Days ==========

[2010/10/19 02:05:43 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/10/19 01:49:12 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/10/18 15:12:02 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/10/18 15:09:08 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/10/18 15:09:08 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/10/18 15:09:08 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/10/18 15:09:08 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/10/18 15:09:00 | 000,000,000 | —D | C] – C:\ComboFix
[2010/10/18 15:08:27 | 000,000,000 | —D | C] – C:\Qoobox
[2010/10/17 11:53:55 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2010/10/09 00:49:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/09 00:49:21 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/09 00:49:21 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/09 00:46:36 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Jeremy\Desktop\mbam-setup-1.46.exe
[2010/10/05 12:52:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport_files
[2010/10/05 09:10:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\Application Data\Research In Motion
[2010/10/05 09:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/10/05 09:09:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Research In Motion
[2010/10/05 09:09:41 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion
[2010/10/04 19:24:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/09/21 21:15:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jeremy\Recent
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/19 15:08:53 | 000,010,254 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\I don.docx
[2010/10/19 12:35:34 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/10/19 02:02:04 | 000,254,654 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/10/19 02:01:50 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/19 02:01:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/19 02:01:46 | 1071,824,896 | -HS- | M] () – C:\hiberfil.sys
[2010/10/18 18:48:56 | 000,000,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/10/18 15:16:45 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/18 15:12:07 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2010/10/17 12:21:45 | 1071,853,568 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/10/17 11:53:59 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2010/10/09 14:39:41 | 000,012,811 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 140 Assignment 1.docx
[2010/10/09 00:49:33 | 000,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/09 00:47:14 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Jeremy\Desktop\mbam-setup-1.46.exe
[2010/10/08 12:37:14 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/07 19:53:06 | 000,062,464 | RHS- | M] () – C:\WINDOWS\System32\iernonceu.dll
[2010/10/06 12:58:21 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/10/05 12:52:16 | 000,123,849 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport.htm
[2010/10/05 09:10:03 | 000,001,967 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/04 19:22:20 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/10/04 18:47:14 | 000,013,470 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 3.docx
[2010/09/21 21:20:54 | 000,001,481 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\DivX Movies.lnk
[2010/09/21 21:20:46 | 000,000,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/09/21 21:16:46 | 000,447,134 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/21 21:16:46 | 000,073,620 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/21 14:23:01 | 000,000,818 | —- | M] () – C:\Documents and Settings\Jeremy\Application Data\wklnhst.dat
[2010/09/21 00:11:18 | 000,011,938 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 2.docx
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/19 15:08:53 | 000,010,254 | —- | C] () – C:\Documents and Settings\Jeremy\Desktop\I don.docx
[2010/10/18 15:09:08 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/10/18 15:09:08 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/10/18 15:09:08 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/10/18 15:09:08 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/10/18 15:09:08 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/10/09 14:39:41 | 000,012,811 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 140 Assignment 1.docx
[2010/10/09 00:49:33 | 000,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/07 19:53:06 | 000,062,464 | RHS- | C] () – C:\WINDOWS\System32\iernonceu.dll
[2010/10/05 12:52:15 | 000,123,849 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport.htm
[2010/10/05 09:10:51 | 000,000,077 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\Rim.Desktop.Exception.log
[2010/10/05 09:10:09 | 000,000,759 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\Rim.Desktop.HttpServerSetup.log
[2010/10/05 09:10:03 | 000,001,967 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/04 18:30:34 | 000,013,470 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 3.docx
[2010/09/20 12:34:22 | 000,011,938 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 2.docx
[2010/02/02 20:19:38 | 000,402,928 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/12/31 01:08:42 | 000,000,040 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ra3.ini
[2009/09/02 17:14:31 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/25 16:34:01 | 000,000,267 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp1v1.cab
[2009/06/25 16:34:01 | 000,000,016 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp1v2.cab
[2009/06/25 16:33:54 | 000,000,189 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp2v1.cab
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/29 14:57:08 | 000,000,818 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\wklnhst.dat
[2008/07/09 12:28:43 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/09 12:28:43 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/09 12:28:43 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/07/06 19:25:02 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/05/30 12:22:22 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/02/11 10:39:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 10:39:18 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/10 17:35:05 | 000,032,256 | —- | C] () – C:\Documents and Settings\Jeremy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/08 14:53:46 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/12/10 01:11:00 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/12/10 01:03:53 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/12/10 00:38:53 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2007/12/10 00:37:29 | 000,001,028 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/07/27 15:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 15:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2005/12/05 20:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 13:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/04 05:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys

========== LOP Check ==========

[2010/01/28 01:14:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/06/29 19:39:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BioWare
[2009/09/17 22:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\myitlab
[2010/10/05 09:09:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2009/05/18 22:03:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/10/02 01:26:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/12/10 01:07:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/06/25 16:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/13 12:29:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/01/28 01:14:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\acccore
[2009/01/26 15:25:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Aim
[2010/03/19 22:38:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Facebook
[2008/08/11 08:32:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\LimeWire
[2010/10/08 04:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Orbit
[2009/12/28 01:09:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Red Alert 3
[2010/10/05 09:11:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Research In Motion
[2008/09/29 14:57:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Template
[2009/11/05 17:57:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\uTorrent

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/01/13 12:51:54 | 000,000,000 | —- | M] () – C:\asdasd.asdasd
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/01/24 13:29:53 | 000,000,281 | —- | M] () – C:\Boot.bak
[2010/10/18 15:12:07 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2010/10/18 15:18:12 | 000,009,038 | —- | M] () – C:\ComboFix.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/12/10 00:41:18 | 000,007,049 | RH– | M] () – C:\dell.sdr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/10/19 02:01:46 | 1071,824,896 | -HS- | M] () – C:\hiberfil.sys
[2008/08/27 23:44:18 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/01/28 01:14:29 | 000,001,262 | -H– | M] () – C:\IPH.PH
[2008/03/20 00:31:32 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 05:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/10/19 02:01:41 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/01/13 13:15:05 | 000,000,058 | —- | M] () – C:\proc.id
[2010/10/14 12:19:55 | 000,043,286 | —- | M] () – C:\TDSSKiller.2.4.4.0_14.10.2010_12.19.35_log.txt
[2010/10/14 12:25:33 | 000,043,286 | —- | M] () – C:\TDSSKiller.2.4.4.0_14.10.2010_12.25.13_log.txt
[2010/10/15 21:56:48 | 000,043,286 | —- | M] () – C:\TDSSKiller.2.4.4.0_15.10.2010_21.56.30_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/07/07 11:46:55 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/07/07 06:31:39 | 001,835,008 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/07/07 11:23:15 | 000,045,056 | —- | M] () – C:\WINDOWS\system32\config\security.sav
[2008/07/07 06:31:39 | 033,554,432 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/07/07 06:31:41 | 005,505,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/07 11:47:13 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/12/24 21:12:44 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 14:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/06/06 13:10:08 | 008,926,783 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\ab32d_install.exe
[2010/08/15 14:44:49 | 008,573,648 | —- | M] (Mozilla) – C:\Documents and Settings\Jeremy\Desktop\Firefox Setup 3.6.8.exe
[2010/10/09 00:47:14 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Jeremy\Desktop\mbam-setup-1.46.exe
[2009/10/23 03:48:05 | 001,407,680 | —- | M] () – C:\Documents and Settings\Jeremy\Desktop\MoveMediaPlayerWin_071505000010.exe
[2010/10/17 11:53:59 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2009/06/30 00:46:09 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Jeremy\Desktop\spybotsd162.exe
[2008/08/21 06:31:59 | 001,038,787 | —- | M] (Blizzard Entertainment) – C:\Documents and Settings\Jeremy\Desktop\WoW-BurningCrusade-Trial-enUS-Installer-downloader.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2007/12/24 21:42:27 | 006,026,816 | —- | M] (Mozilla) – C:\Documents and Settings\Jeremy\My Documents\Firefox Setup 2[1].0.0.11.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2004/08/04 06:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2007/12/24 21:12:43 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Jeremy\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/10/19 15:10:14 | 000,212,992 | -HS- | M] () – C:\Documents and Settings\Jeremy\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-07-07 00:25:11

< End of report >
Sorry i forgot to say,you will need to set to show hidden files and then scan c:\windows\system32\iernonceu.dll at virustotal

To do that

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.

Please post the results.
I was already showing hidden files. It's not there. I don't have that .dll file in my system 32 folder. I double checked though just to make sure.
Hmm, From Combofix
2010-10-08 00:53 . 2010-10-08 00:53 62464 –sha-r- c:\windows\system32\iernonceu.dll

From OTL
[2010/10/07 19:53:06 | 000,062,464 | RHS- | C] () – C:\WINDOWS\System32\iernonceu.dll


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :File
    C:\WINDOWS\System32\iernonceu.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook 04.09.10 by jpshortstuff Log created at 13:36 on 23/10/2010 by Jeremy Administrator - Elevation successful ========== File ========== C:\WINDOWS\System32\iernonceu.dll - Unable to find/read file. -= EOF =-
OK lol,it obviously isn't there or just doesn't want to be found,how is the computer running now ?

Please do the following


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\10\35ace28a-40fe5d39
    C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74031c8a
    C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\8\4cafbd48-21e773ea
    C:\Downloads\Setup.exe
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
I don't get redirects anymore but the computer isn't exactly running smooth. I think I might have a power supply problem, either that or I just don't use my compressed air often enough because the computer locks up at least once a week and has to be unplugged, opened up, and cleaned out. However today was a different kind of lock up. Normally when it happens I'm not on it so it just won't come out of sleep mode, or turn off. So it has to be unplugged. Today 3-4 times it just frozen on reboot. It did it after I ran OTL. And in my task manager everything appears to be taking up at least twice as much space as it was before. Anyway here's the log. Sorry about the jacked up date like I said the computer froze up and it's giving me an error when I try to sync it with windows. All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\10\35ace28a-40fe5d39 moved successfully. C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74031c8a moved successfully. C:\Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\8\4cafbd48-21e773ea moved successfully. C:\Downloads\Setup.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Jeremy ->Temp folder emptied: 2158893 bytes ->Temporary Internet Files folder emptied: 9963277 bytes ->Java cache emptied: 52048698 bytes ->FireFox cache emptied: 43298550 bytes ->Flash cache emptied: 2337401 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2175612 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 65536 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 6553539 bytes Total Files Cleaned = 113.00 mb OTL by OldTimer - Version 3.2.15.2 log created on 03202008_025017 Files\Folders moved on Reboot… Registry entries deleted on Reboot… Files\Folders moved on Reboot… Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI