This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop Infected with Virus

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good evening mowman. I followed the OTL scan instructions as posted by LDTate on the forum instruction page and have posted the OTL results below.

OTL logfile created on: 11/2/2010 8:18:11 PM - Run 2
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Virus Scan
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 174.00 Mb Available Physical Memory | 17.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.04 Gb Total Space | 69.41 Gb Free Space | 48.52% Space Free | Partition Type: NTFS

Computer Name: SAMSUNG120 | User Name: JM | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\John Hurst\Application Data\Microsoft\Windows\shell.exe ()
PRC - C:\Documents and Settings\John Hurst\Local Settings\Temp\dwm.exe ()
PRC - C:\Documents and Settings\John Hurst\Application Data\Microsoft\svchost.exe ()
PRC - C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe ()
PRC - C:\Documents and Settings\JM\Local Settings\Temp\dwm.exe ()
PRC - C:\Documents and Settings\JM\Application Data\Microsoft\svchost.exe ()
PRC - C:\Virus Scan\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files\iMesh Applications\MediaBar\DataMngr\DataMngrUI.exe (iMesh, Inc)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
PRC - C:\Program Files\Crawler\Toolbar\CToolbar.exe (Crawler.com)
PRC - C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\NCH Software\Components\mp3el\mp3enc.exe ()
PRC - C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
PRC - C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
PRC - C:\Program Files\Common Files\BSD\AppUpdater\BSDChecker.exe (Bootstrap Software Development)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe (SRS Labs, Inc.)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Samsung\MagicKBD\PerformanceManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
PRC - C:\Program Files\Samsung\MagicKBD\Session.exe ()


========== Modules (SafeList) ==========

MOD - C:\Virus Scan\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Real\RealPlayer\browserrecord\chrome\hook\rpchromebrowserrecordhelper.dll (RealPlayer)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)


========== Win32 Services (SafeList) ==========

SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_062a651.dll ()
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (BarQuery Service) – C:\Documents and Settings\All Users\Application Data\BarQuery\barquery135.exe ()
SRV - (iWinTrusted) – C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (BroadWaveService) – C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
SRV - (yksvc) – C:\WINDOWS\system32\ykx32mpcoinst.dll (Marvell)
SRV - (SRS_PostInstaller) – C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe (SRS Labs, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (cpuz132) – C:\DOCUME~1\JM\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (btwmodem) – C:\WINDOWS\System32\DRIVERS\btwmodem.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (TPkd) – C:\WINDOWS\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (wowfilter) – C:\WINDOWS\system32\drivers\WOWFilter.sys ()
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ntcdrdrv) – C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys (NoteBurn Software)
DRV - (VMC326) – C:\WINDOWS\system32\drivers\VMC326.sys (Vimicro Corporation)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60001
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…N&bmod;=SMSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home?AF=14542
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
IE - HKCU\..\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch⁡=14542"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {1CE11043-9A15-4207-A565-0C94C42D590D}:11.3.7.0
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.006.004
FF - prefs.js..extensions.enabledItems: {D5493C6A-FD62-4255-AA85-AB7E7D0F0001}:1.0
FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
FF - prefs.js..extensions.enabledItems: {98e34367-8df7-42b4-837b-20b892ff0849}:1.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {28D35620-51D9-11DE-9D13-2DB156D89593}:3.1
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {99E00A4C-D35E-11DD-BA95-9B6A56D89593}:2.2
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "http://search.search-star.net/?sid=10101045100&s;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 1

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-star.net/?sid=10101045100&s;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\Program Files\iWin Games\firefox\ [2010/04/15 20:01:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\Program Files\Crawler\Toolbar\firefox\ [2010/04/16 16:55:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/10/26 17:49:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 07:24:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 07:24:58 | 000,000,000 | —D | M]

[2009/12/27 15:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Mozilla\Extensions
[2010/11/01 21:33:19 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions
[2010/06/02 00:44:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/24 10:30:01 | 000,000,000 | —D | M] (MediaBar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{28D35620-51D9-11DE-9D13-2DB156D89593}
[2010/07/25 19:29:55 | 000,000,000 | —D | M] (ooVoo Toolbar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{99E00A4C-D35E-11DD-BA95-9B6A56D89593}
[2010/08/03 13:56:37 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\searchplugins\iMeshWebSearch.xml
[2010/11/01 21:33:19 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/03 18:52:48 | 000,000,000 | —D | M] (Adobe Flash Plugin) – C:\Program Files\Mozilla Firefox\extensions\{1CE11043-9A15-4207-A565-0C94C42D590D}
[2010/05/20 16:51:53 | 000,000,000 | —D | M] (BarQuery) – C:\Program Files\Mozilla Firefox\extensions\{D5493C6A-FD62-4255-AA85-AB7E7D0F0001}
[2010/08/03 13:56:29 | 000,002,226 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/03/27 11:13:27 | 000,002,389 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\barquery129.xml
[2009/09/21 11:24:16 | 000,001,329 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
[2010/07/26 08:38:42 | 000,002,076 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\iMeshWebSearch.xml

O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Gamevance) - {0ED403E8-470A-4a8a-85A4-D7688CFE39A3} - C:\Program Files\Gamevance\gamevancelib32.dll File not found
O2 - BHO: (GameBox Toolbar) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PCCBHO.CPCCBHO) - {22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF} - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll (Capital Intellect Inc)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Updater For ooVoo Toolbar) - {442AE524-EBA5-4b17-82F3-888D68BC999A} - C:\Program Files\oovootb\auxi\oovooAu.dll (Visicom Media)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\MediaBar\DataMngr\IEBHO.dll (iMesh, Inc)
O2 - BHO: (PriceGong Class) - {4D3F3F3A-0E4B-4085-9032-7D072072319A} - C:\Program Files\PriceGong\2.0.0\PriceLoadIE.dll (PriceGong)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (no name) - {99E00A4C-D35E-11DD-BA95-9B6A56D89593} - No CLSID value found.
O2 - BHO: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O2 - BHO: (MediaBar) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll File not found
O2 - BHO: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
O2 - BHO: (Gamevance Text) - {BEAC7DC8-E106-4C6A-931E-5A42E7362883} - C:\Program Files\Gamevance\gvtl.dll ()
O2 - BHO: () - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O2 - BHO: (NetAssistantBHO Class) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\My.Freeze.com NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (GameBox Toolbar) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKLM\..\Toolbar: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O3 - HKLM\..\Toolbar: (MediaBar) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll ()
O3 - HKLM\..\Toolbar: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [BroadWave] C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
O4 - HKLM..\Run: [BSDAppUpdater] C:\Program Files\Common Files\BSD\AppUpdater\BSDChecker.exe (Bootstrap Software Development)
O4 - HKLM..\Run: [DataMngr] C:\Program Files\iMesh Applications\MediaBar\DataMngr\DataMngrUI.exe (iMesh, Inc)
O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe (SAMSUNG Electronics)
O4 - HKLM..\Run: [Gamevance] C:\Program Files\Gamevance\gamevance32.exe File not found
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\Samsung\MagicKBD\PreMKbd.exe ()
O4 - HKLM..\Run: [nlgxtayd] C:\Documents and Settings\LocalService\Local Settings\Application Data\jfemsclun\rpthiynshdw.exe File not found
O4 - HKLM..\Run: [SUPBackGround] C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
O4 - HKLM..\Run: [svchost] C:\Documents and Settings\John Hurst\Application Data\Microsoft\svchost.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VerboseRun] C:\Program Files\NCH Swift Sound\Verbose\verbose.exe File not found
O4 - HKCU..\Run: [BatteryLifeExtender] C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe (Samsung Electronics. Co. Ltd.)
O4 - HKCU..\Run: [CSmileys] C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe File not found
O4 - HKCU..\Run: [Jing] C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [ooVoo.exe] C:\program files\oovoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O4 - HKCU..\Run: [U36VRSFLG6] C:\DOCUME~1\JM\LOCALS~1\Temp\Vqe.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\JM\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
F3 - HKCU WinNT: Load - (C:\DOCUME~1\JM\LOCALS~1\Temp\dwm.exe) - C:\Documents and Settings\JM\Local Settings\Temp\dwm.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\gameboxchrome {494D4E3B-FA53-4487-8AF6-3F50FE1167A9} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll) - C:\Program Files\iMesh Applications\MediaBar\DataMngr\datamngr.dll (iMesh, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe) - C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: SwUpdate - {003541A1-3BC0-1B1C-AAF3-040114001C01}— | M] (Microsoft Corporation) - CLSID or File not found.
O24 - Desktop WallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/13 20:47:07 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell - "" = AutoRun
O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell\AutoRun\command - "" = D:\Autorun.exe – File not found
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell - "" = AutoRun
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\1\Command - "" = Recycle.exe
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\2\Command - "" = Recycle.exe
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\WINDOWS\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2010/11/01 22:33:12 | 000,000,000 | R–D | C] – C:\32788R22FWJFW
[2010/10/26 20:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Local Settings\Application Data\AVG Security Toolbar
[2010/10/19 07:01:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\35148
[2009/12/26 11:23:16 | 000,800,544 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u17-rv.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/02 20:22:01 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006UA.job
[2010/11/02 20:21:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/02 20:15:53 | 067,122,403 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/11/02 20:13:55 | 000,000,432 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F89E5EF8-7ACA-4DBF-954D-55BFE72ABEE9}.job
[2010/11/01 22:36:00 | 000,000,266 | -H– | M] () – C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/11/01 22:29:05 | 003,898,593 | —- | M] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe
[2010/11/01 22:05:00 | 000,000,240 | -H– | M] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/11/01 21:50:00 | 000,000,270 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/01 21:43:15 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/01 21:43:13 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2010/11/01 21:42:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/01 21:42:41 | 1063,702,528 | -HS- | M] () – C:\hiberfil.sys
[2010/11/01 21:40:00 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005UA.job
[2010/10/31 20:40:00 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005Core.job
[2010/10/31 13:27:24 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/29 19:21:27 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/29 14:39:10 | 000,000,484 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for John Hurst.job
[2010/10/29 07:22:00 | 000,000,914 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006Core.job
[2010/10/28 17:23:18 | 000,000,783 | —- | M] () – C:\Documents and Settings\JM\Desktop\Shortcut to chrome.lnk
[2010/10/27 16:44:17 | 000,028,672 | —- | M] () – C:\Documents and Settings\JM\My Documents\El tiempo en Miami.doc
[2010/10/27 16:21:31 | 000,002,497 | —- | M] () – C:\Documents and Settings\JM\Desktop\Microsoft Office Word 2003.lnk
[2010/10/26 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadDowngrade.job
[2010/10/26 21:22:06 | 000,313,968 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/24 18:59:09 | 000,020,992 | —- | M] () – C:\Documents and Settings\JM\My Documents\edgar allen poe.doc
[2010/10/24 18:49:49 | 000,104,448 | —- | M] () – C:\Documents and Settings\JM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/24 15:16:22 | 000,029,696 | —- | M] () – C:\Documents and Settings\JM\My Documents\Independant Novel Synopsis 10.26.10.doc
[2010/10/21 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/10/19 19:40:52 | 000,000,650 | —- | M] () – C:\Documents and Settings\JM\Desktop\Firefox.lnk
[2010/10/15 06:41:29 | 000,028,672 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 10.15..doc
[2010/10/14 05:29:46 | 000,040,448 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 218.doc
[2010/10/13 07:49:05 | 000,040,448 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 312.doc
[2010/10/07 16:37:10 | 000,000,162 | -H– | M] () – C:\Documents and Settings\JM\My Documents\~$ Birthday List.doc
[2010/10/07 16:37:09 | 001,334,272 | —- | M] () – C:\Documents and Settings\JM\My Documents\JM Birthday List.doc
[2010/10/05 19:32:59 | 000,031,232 | —- | M] () – C:\Documents and Settings\JM\My Documents\98-104.doc
[2010/10/05 07:09:07 | 000,031,744 | —- | M] () – C:\Documents and Settings\JM\My Documents\90-97.doc
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/01 22:29:01 | 003,898,593 | —- | C] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe
[2010/10/28 17:23:18 | 000,000,783 | —- | C] () – C:\Documents and Settings\JM\Desktop\Shortcut to chrome.lnk
[2010/10/27 16:44:16 | 000,028,672 | —- | C] () – C:\Documents and Settings\JM\My Documents\El tiempo en Miami.doc
[2010/10/26 20:07:26 | 000,000,266 | -H– | C] () – C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/26 20:07:21 | 000,000,270 | -H– | C] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/26 20:07:02 | 000,000,240 | -H– | C] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/24 18:59:09 | 000,020,992 | —- | C] () – C:\Documents and Settings\JM\My Documents\edgar allen poe.doc
[2010/10/24 15:16:22 | 000,029,696 | —- | C] () – C:\Documents and Settings\JM\My Documents\Independant Novel Synopsis 10.26.10.doc
[2010/10/19 19:40:52 | 000,000,650 | —- | C] () – C:\Documents and Settings\JM\Desktop\Firefox.lnk
[2010/10/15 06:41:28 | 000,028,672 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 10.15..doc
[2010/10/14 05:25:09 | 000,040,448 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 218.doc
[2010/10/13 07:49:05 | 000,040,448 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 312.doc
[2010/10/12 22:57:45 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/10/11 14:23:14 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\wavepadDowngrade.job
[2010/10/07 16:37:10 | 000,000,162 | -H– | C] () – C:\Documents and Settings\JM\My Documents\~$ Birthday List.doc
[2010/10/07 16:37:09 | 001,334,272 | —- | C] () – C:\Documents and Settings\JM\My Documents\JM Birthday List.doc
[2010/10/05 19:32:58 | 000,031,232 | —- | C] () – C:\Documents and Settings\JM\My Documents\98-104.doc
[2010/10/05 07:09:06 | 000,031,744 | —- | C] () – C:\Documents and Settings\JM\My Documents\90-97.doc
[2010/09/23 22:48:59 | 000,348,536 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/27 11:10:43 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/07/26 22:18:06 | 000,697,328 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2010/07/25 13:28:37 | 000,000,789 | —- | C] () – C:\WINDOWS\hegames.ini
[2010/04/06 22:13:07 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/03/04 19:21:05 | 000,050,630 | —- | C] () – C:\Documents and Settings\JM\Application Data\speech.wav
[2009/12/26 21:17:53 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/12/26 15:02:47 | 000,104,448 | —- | C] () – C:\Documents and Settings\JM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/26 02:00:22 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/26 01:19:06 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\John Hurst_KBD.ini
[2009/12/25 17:21:14 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\JM_KBD.ini
[2009/10/05 19:46:46 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/13 20:59:17 | 000,000,002 | —- | C] () – C:\WINDOWS\HotFixList.ini
[2009/05/13 20:59:11 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2009/05/13 20:59:11 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\Owner_KBD.ini
[2009/05/13 20:59:09 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2009/05/13 20:59:09 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2009/05/13 20:59:09 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2009/05/13 20:59:09 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2009/05/13 20:59:09 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2009/05/13 20:59:09 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2009/05/13 20:59:09 | 000,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2009/05/13 20:59:09 | 000,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2009/05/13 20:59:09 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2009/05/13 20:59:09 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2009/05/13 20:59:09 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2009/05/13 20:59:09 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2009/05/13 20:59:09 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2009/05/13 20:57:52 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2009/05/13 20:57:52 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2009/05/13 20:53:57 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/05/13 20:51:14 | 000,004,300 | —- | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2009/05/13 18:57:57 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/05/13 13:39:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/03/23 18:40:06 | 002,854,976 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2009/02/18 23:08:50 | 000,043,240 | —- | C] () – C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2009/02/18 23:08:48 | 000,025,560 | —- | C] () – C:\WINDOWS\System32\drivers\WOWFilter.sys
[2009/02/18 23:08:46 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2010/07/23 12:43:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\21271
[2010/10/19 07:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\35148
[2010/06/30 12:33:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\3B261
[2010/10/26 17:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/08/12 14:28:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/05/20 16:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BarQuery
[2010/09/05 15:51:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BearShare
[2010/02/10 19:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BSD
[2010/07/26 11:20:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/07/26 22:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010/07/05 18:32:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Inspector
[2010/01/10 13:55:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2010/02/17 21:28:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Extensions
[2010/03/23 21:30:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2010/03/20 16:11:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoBit Games
[2010/06/24 10:28:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iMesh
[2010/04/15 20:02:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/07/26 22:38:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lionhead Studios
[2010/03/07 17:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/09/05 17:00:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NoteBurner
[2010/07/09 16:27:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2010/07/12 13:57:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PhotoChances
[2010/04/19 18:08:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/06/14 15:42:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2010/07/05 18:33:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UAB
[2010/03/23 21:08:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2010/08/03 19:04:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/12/26 04:35:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinClon
[2010/03/30 20:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2009/05/13 20:54:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLAN
[2010/06/30 20:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/25 17:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/09/05 15:52:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{A7135C8B-F43E-46A1-88B2-668FD0EBD306}
[2010/06/24 10:29:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{B76CD956-76B8-4594-8C7C-A647643939D2}
[2010/05/25 13:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\3M
[2010/07/09 16:21:32 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Antares
[2010/02/10 19:34:14 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\AnvSoft
[2010/07/27 10:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Atari
[2010/10/24 17:39:18 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Audacity
[2010/07/26 09:32:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\BitComet
[2010/07/29 00:17:51 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\BitTorrent
[2010/02/10 19:37:36 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\BSD
[2010/07/26 22:29:39 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\DAEMON Tools Lite
[2010/07/26 22:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\DAEMON Tools Pro
[2010/01/10 17:54:12 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\EmailNotifier
[2010/04/08 22:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Facebook
[2010/03/24 07:55:22 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\FCSB000062035
[2010/08/13 22:29:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\GameBox
[2010/05/25 13:21:38 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\GetRightToGo
[2010/07/13 16:43:43 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\imeshmediabartb
[2010/05/03 16:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Inbox Toolbar
[2010/07/27 00:43:48 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Leadertech
[2010/07/27 17:31:26 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\ManyCam
[2010/03/04 19:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\NCH Swift Sound
[2010/01/10 13:56:49 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\ooVoo Details
[2010/06/07 18:44:28 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\oovooinstaller
[2010/07/13 16:43:45 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\oovootb
[2010/07/27 14:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\OxelonMC
[2010/07/09 16:27:42 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PACE Anti-Piracy
[2010/07/12 13:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PhotoChances
[2010/07/12 14:08:26 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PhotoScape
[2010/07/26 20:02:37 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PriceGong
[2010/08/25 20:23:15 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\uTorrent
[2010/08/02 16:36:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressburnSevenDays.job
[2010/07/29 16:36:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressburnShakeIcon.job
[2010/11/01 21:43:13 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job
[2010/11/02 20:13:55 | 000,000,432 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{F89E5EF8-7ACA-4DBF-954D-55BFE72ABEE9}.job
[2010/10/26 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\wavepadDowngrade.job
[2010/10/21 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job
[2010/11/01 21:50:00 | 000,000,270 | -H– | M] () – C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/01 22:05:00 | 000,000,240 | -H– | M] () – C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/11/01 22:36:00 | 000,000,266 | -H– | M] () – C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/05/13 20:47:07 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/12/26 01:18:25 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2009/05/13 20:47:07 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/03 10:20:08 | 000,001,808 | —- | M] () – C:\Desktop Security
[2010/11/01 21:42:41 | 1063,702,528 | -HS- | M] () – C:\hiberfil.sys
[2009/05/13 20:47:07 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/13 01:21:02 | 000,000,289 | —- | M] () – C:\Longest Video Ever On Youtube.log
[2009/05/13 20:47:07 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/01 21:42:40 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/05/13 20:57:54 | 000,000,173 | —- | M] () – C:\Setup.log
[2010/11/01 21:50:48 | 000,038,058 | —- | M] () – C:\TDSSKiller.2.4.5.1_01.11.2010_21.49.26_log.txt
[2010/08/03 10:23:33 | 000,000,711 | —- | M] () – C:\Untitled.log
[2010/05/02 09:12:56 | 000,085,933 | —- | M] () – C:\WaxCrash.dmp
[2010/05/02 09:12:53 | 000,075,464 | —- | M] () – C:\WaxCrash.txt
[2010/07/26 12:58:11 | 000,000,150 | —- | M] () – C:\zrpt.xml

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/05/13 20:46:34 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2007/02/26 19:49:10 | 001,744,896 | —- | M] (TopThinks, INC.) – C:\WINDOWS\imagine digital freedom.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/10/31 21:08:30 | 000,010,511 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\stor.cfg
[2010/11/01 21:43:18 | 000,104,960 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\svchost.exe

< %PROGRAMFILES%\*.* >
[2009/12/26 11:23:20 | 000,800,544 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u17-rv.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/05/13 13:37:30 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/05/13 13:37:30 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/05/13 13:37:30 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/13 20:47:14 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2010/01/17 18:08:34 | 000,005,120 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/25 17:21:06 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/13 20:51:30 | 000,000,079 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/11/01 22:29:05 | 003,898,593 | —- | M] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-15 07:24:21

========== Alternate Data Streams ==========

@Alternate Data Stream - 990 bytes -> C:\Program Files\WindowsUpdate:jUwsjxIR6OIzKGKUKuispnC92of
@Alternate Data Stream - 828 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:35E5AF34
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:453190EC
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:D1B5B4F1
@Alternate Data Stream - 1134 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:nBlALKTo5W826T0tCQ4f6WP9
@Alternate Data Stream - 1132 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:aIF2EwvJ6jviacDEypJ2H
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:5804A24D
@Alternate Data Stream - 1016 bytes -> C:\Program Files\WindowsUpdate:ZCgaypncyLSHfArnOH4DgoH66QzV

< End of report >
Please do the following.


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    PRC - C:\Documents and Settings\John Hurst\Application Data\Microsoft\Windows\shell.exe ()
    PRC - C:\Documents and Settings\John Hurst\Local Settings\Temp\dwm.exe ()
    PRC - C:\Documents and Settings\John Hurst\Application Data\Microsoft\svchost.exe ()
    PRC - C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe ()
    PRC - C:\Documents and Settings\JM\Local Settings\Temp\dwm.exe ()
    PRC - C:\Documents and Settings\JM\Application Data\Microsoft\svchost.exe ()
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370
    FF - prefs.js..network.proxy.http_port: 50370
    FF - prefs.js..network.proxy.type: 1
    O2 - BHO: (Gamevance) - {0ED403E8-470A-4a8a-85A4-D7688CFE39A3} - C:\Program Files\Gamevance\gamevancelib32.dll File not found
    O2 - BHO: (GameBox Toolbar) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {99E00A4C-D35E-11DD-BA95-9B6A56D89593} - No CLSID value found.
    O2 - BHO: (Gamevance Text) - {BEAC7DC8-E106-4C6A-931E-5A42E7362883} - C:\Program Files\Gamevance\gvtl.dll ()
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O3 - HKLM\..\Toolbar: (GameBox Toolbar) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
    O4 - HKLM..\Run: [Gamevance] C:\Program Files\Gamevance\gamevance32.exe File not found
    O4 - HKLM..\Run: [nlgxtayd] C:\Documents and Settings\LocalService\Local Settings\Application Data\jfemsclun\rpthiynshdw.exe File not found
    O4 - HKCU..\Run: [U36VRSFLG6] C:\DOCUME~1\JM\LOCALS~1\Temp\Vqe.exe File not found
    O4 - HKLM..\Run: [svchost] C:\Documents and Settings\JM\Application Data\Microsoft\svchost.exe ()
    F3 - HKCU WinNT: Load - (C:\DOCUME~1\JM\LOCALS~1\Temp\dwm.exe) - C:\Documents and Settings\JM\Local Settings\Temp\dwm.exe ()
    O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe) - C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe ()
    O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell - "" = AutoRun
    O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell\AutoRun\command - "" = D:\Autorun.exe – File not found
    O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell - "" = AutoRun
    O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\1\Command - "" = Recycle.exe
    O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\2\Command - "" = Recycle.exe
    O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\AutoRun - "" = Auto&Play
    [2010/10/28 07:28:10 | 000,010,115 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\stor.cfg
    [2010/10/28 20:45:07 | 000,095,232 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\svchost.exe
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )





Next


Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please





Next

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Good evening mowman. I ran the OTL per your instructions and the laptop rebooted automatically without my initiating. Consequently I did not have an option to save a log file and can not find where one was generated or saved on my hard drive. I will await your instructions before proceeding. Thank you for your assistance
hello..included below is the log file for malewarebytes. when I try to run Eset Scan, I get to the Initialization screen - "Download virus signature database" screen and the online program tells me that "Can not get update. Is proxy configured?". That is as far as I can go with this program. Any suggestions are appreciated…… Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5039 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 11/4/2010 5:33:16 PM mbam-log-2010-11-04 (17-33-16).txt Scan type: Quick scan Objects scanned: 184941 Time elapsed: 19 hour(s), 8 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 13 Registry Values Infected: 3 Registry Data Items Infected: 4 Folders Infected: 6 Files Infected: 40 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll (Trojan.Agent) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{003541a1-3bc0-1b1c-aaf3-040114001c01} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\barquery (Adware.Zwangi) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\2L4NOI3W05 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\U36VRSFLG6 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\AnVi (Rogue.AnVi) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\BarQuery (Adware.Zwangi) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus (Rogue.AntiVirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BARQUERY_SERVICE (Adware.Zwangi) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BarQuery Service (Adware.Zwangi) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\swupdate (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8 (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\7bde84a2-f58f-46ec-9eac-f1f90fead080 (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe,c:\documents,and,settings\jm\application,data\microsoft\windows\shell.exe,) Good: (Explorer.exe) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\All Users\Application Data\BarQuery (Adware.Zwangi) -> Quarantined and deleted successfully. C:\Program Files\AnVi (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\BarQuery (Adware.Zwangi) -> Quarantined and deleted successfully. C:\Program Files\Gamevance (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll (Trojan.Agent) -> Delete on reboot. C:\Documents and Settings\John Hurst\Application Data\Microsoft\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mstsc.exe.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\sycre.exe (Worm.Allaple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\BarQuery\barquery135.exe (Adware.Zwangi) -> Quarantined and deleted successfully. C:\Program Files\AnVi\about.ico (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\AnVi\activate.ico (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\AnVi\avt.db (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\AnVi\buy.ico (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\AnVi\help.ico (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\AnVi\scan.ico (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\AnVi\settings.ico (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\AnVi\update.ico (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\BarQuery\barquery.exe (Adware.Zwangi) -> Quarantined and deleted successfully. C:\Program Files\BarQuery\uninstall.exe (Adware.Zwangi) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\ars.cfg (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\icon.ico (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\About.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\Activate.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\Antivirus Support.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\Antivirus.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\Buy.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\Scan.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\Settings.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Start Menu\Programs\AnVi\Update.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\WINDOWS\$NtUninstallMTF1011$\zrpt.xml (Adware.Adrotator) -> Quarantined and deleted successfully. C:\Documents and Settings\John Hurst\Application Data\Microsoft\stor.cfg (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\zrpt.xml (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\Local.dtd (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\Ui.dtd (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\John Hurst\Application Data\Microsoft\Windows\shell.exe (Trojan.Shell) -> Quarantined and deleted successfully. C:\Documents and Settings\JM\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\kilslmd.exex (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\test.exe (Trojan.Zlob) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\John Hurst\Local Settings\Temp\dwm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
OTL logfile created on: 11/4/2010 6:29:28 PM - Run 3
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Virus Scan
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 265.00 Mb Available Physical Memory | 26.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.04 Gb Total Space | 69.73 Gb Free Space | 48.75% Space Free | Partition Type: NTFS

Computer Name: SAMSUNG120 | User Name: JM | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Virus Scan\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files\iMesh Applications\MediaBar\DataMngr\DataMngrUI.exe (iMesh, Inc)
PRC - C:\Program Files\Crawler\Toolbar\CToolbar.exe (Crawler.com)
PRC - C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\NCH Software\Components\mp3el\mp3enc.exe ()
PRC - C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
PRC - C:\Program Files\Common Files\BSD\AppUpdater\BSDChecker.exe (Bootstrap Software Development)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)


========== Modules (SafeList) ==========

MOD - C:\Virus Scan\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Real\RealPlayer\browserrecord\chrome\hook\rpchromebrowserrecordhelper.dll (RealPlayer)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)


========== Win32 Services (SafeList) ==========

SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_062a651.dll ()
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (iWinTrusted) – C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (BroadWaveService) – C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
SRV - (yksvc) – C:\WINDOWS\system32\ykx32mpcoinst.dll (Marvell)
SRV - (SRS_PostInstaller) – C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe (SRS Labs, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (cpuz132) – C:\DOCUME~1\JM\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (btwmodem) – C:\WINDOWS\System32\DRIVERS\btwmodem.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (TPkd) – C:\WINDOWS\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (wowfilter) – C:\WINDOWS\system32\drivers\WOWFilter.sys ()
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ntcdrdrv) – C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys (NoteBurn Software)
DRV - (VMC326) – C:\WINDOWS\system32\drivers\VMC326.sys (Vimicro Corporation)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60001
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…N&bmod;=SMSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home?AF=14542
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
IE - HKCU\..\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF;=14542"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {1CE11043-9A15-4207-A565-0C94C42D590D}:11.3.7.0
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.006.004
FF - prefs.js..extensions.enabledItems: {D5493C6A-FD62-4255-AA85-AB7E7D0F0001}:1.0
FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
FF - prefs.js..extensions.enabledItems: {98e34367-8df7-42b4-837b-20b892ff0849}:1.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {28D35620-51D9-11DE-9D13-2DB156D89593}:3.1
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {99E00A4C-D35E-11DD-BA95-9B6A56D89593}:2.2
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "http://search.search-star.net/?sid=10101045100&s;="
FF - prefs.js..network.proxy.http: "127.0.0.1"

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-star.net/?sid=10101045100&s;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\Program Files\iWin Games\firefox\ [2010/04/15 20:01:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\Program Files\Crawler\Toolbar\firefox\ [2010/04/16 16:55:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/10/26 17:49:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 07:24:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 07:24:58 | 000,000,000 | —D | M]

[2009/12/27 15:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Mozilla\Extensions
[2010/11/03 21:47:59 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions
[2010/06/02 00:44:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/24 10:30:01 | 000,000,000 | —D | M] (MediaBar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{28D35620-51D9-11DE-9D13-2DB156D89593}
[2010/07/25 19:29:55 | 000,000,000 | —D | M] (ooVoo Toolbar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{99E00A4C-D35E-11DD-BA95-9B6A56D89593}
[2010/08/03 13:56:37 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\searchplugins\iMeshWebSearch.xml
[2010/11/03 21:47:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/03 18:52:48 | 000,000,000 | —D | M] (Adobe Flash Plugin) – C:\Program Files\Mozilla Firefox\extensions\{1CE11043-9A15-4207-A565-0C94C42D590D}
[2010/05/20 16:51:53 | 000,000,000 | —D | M] (BarQuery) – C:\Program Files\Mozilla Firefox\extensions\{D5493C6A-FD62-4255-AA85-AB7E7D0F0001}
[2010/08/03 13:56:29 | 000,002,226 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/03/27 11:13:27 | 000,002,389 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\barquery129.xml
[2009/09/21 11:24:16 | 000,001,329 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
[2010/07/26 08:38:42 | 000,002,076 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\iMeshWebSearch.xml

O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PCCBHO.CPCCBHO) - {22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF} - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll (Capital Intellect Inc)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Updater For ooVoo Toolbar) - {442AE524-EBA5-4b17-82F3-888D68BC999A} - C:\Program Files\oovootb\auxi\oovooAu.dll (Visicom Media)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\MediaBar\DataMngr\IEBHO.dll (iMesh, Inc)
O2 - BHO: (PriceGong Class) - {4D3F3F3A-0E4B-4085-9032-7D072072319A} - C:\Program Files\PriceGong\2.0.0\PriceLoadIE.dll (PriceGong)
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O2 - BHO: (MediaBar) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll File not found
O2 - BHO: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O2 - BHO: () - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O2 - BHO: (NetAssistantBHO Class) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\My.Freeze.com NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKLM\..\Toolbar: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O3 - HKLM\..\Toolbar: (MediaBar) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll ()
O3 - HKLM\..\Toolbar: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (myBabylon English Toolbar) - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - C:\Program Files\myBabylon_English\tbmyB1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [BroadWave] C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
O4 - HKLM..\Run: [BSDAppUpdater] C:\Program Files\Common Files\BSD\AppUpdater\BSDChecker.exe (Bootstrap Software Development)
O4 - HKLM..\Run: [DataMngr] C:\Program Files\iMesh Applications\MediaBar\DataMngr\DataMngrUI.exe (iMesh, Inc)
O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe (SAMSUNG Electronics)
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\Samsung\MagicKBD\PreMKbd.exe ()
O4 - HKLM..\Run: [SUPBackGround] C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VerboseRun] C:\Program Files\NCH Swift Sound\Verbose\verbose.exe File not found
O4 - HKCU..\Run: [BatteryLifeExtender] C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe (Samsung Electronics. Co. Ltd.)
O4 - HKCU..\Run: [CSmileys] C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe File not found
O4 - HKCU..\Run: [Jing] C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [ooVoo.exe] C:\program files\oovoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\JM\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\gameboxchrome {494D4E3B-FA53-4487-8AF6-3F50FE1167A9} - C:\Program Files\GameBox\gamebox_toolbar.dll File not found
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll) - C:\Program Files\iMesh Applications\MediaBar\DataMngr\datamngr.dll (iMesh, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/13 20:47:07 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/04 17:51:06 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/11/03 22:20:40 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Application Data\Malwarebytes
[2010/11/03 22:20:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/03 22:20:27 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/03 21:30:40 | 000,000,000 | —D | C] – C:\_OTL
[2010/11/01 22:33:12 | 000,000,000 | R–D | C] – C:\32788R22FWJFW
[2010/10/26 20:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Local Settings\Application Data\AVG Security Toolbar
[2010/10/19 07:01:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\35148
[2009/12/26 11:23:16 | 000,800,544 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u17-rv.exe
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/04 18:29:00 | 000,000,432 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F89E5EF8-7ACA-4DBF-954D-55BFE72ABEE9}.job
[2010/11/04 18:22:02 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006UA.job
[2010/11/04 18:21:02 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/04 17:42:09 | 067,186,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/11/04 17:40:00 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005UA.job
[2010/11/04 17:36:58 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/04 17:36:58 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2010/11/04 17:36:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/04 17:36:16 | 1063,702,528 | -HS- | M] () – C:\hiberfil.sys
[2010/11/02 20:40:00 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005Core.job
[2010/11/01 22:29:05 | 003,898,593 | —- | M] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe
[2010/10/31 13:27:24 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/29 19:21:27 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/29 14:39:10 | 000,000,484 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for John Hurst.job
[2010/10/29 07:22:00 | 000,000,914 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006Core.job
[2010/10/28 17:23:18 | 000,000,783 | —- | M] () – C:\Documents and Settings\JM\Desktop\Shortcut to chrome.lnk
[2010/10/27 16:44:17 | 000,028,672 | —- | M] () – C:\Documents and Settings\JM\My Documents\El tiempo en Miami.doc
[2010/10/27 16:21:31 | 000,002,497 | —- | M] () – C:\Documents and Settings\JM\Desktop\Microsoft Office Word 2003.lnk
[2010/10/26 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadDowngrade.job
[2010/10/26 21:22:06 | 000,313,968 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/24 18:59:09 | 000,020,992 | —- | M] () – C:\Documents and Settings\JM\My Documents\edgar allen poe.doc
[2010/10/24 18:49:49 | 000,104,448 | —- | M] () – C:\Documents and Settings\JM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/24 15:16:22 | 000,029,696 | —- | M] () – C:\Documents and Settings\JM\My Documents\Independant Novel Synopsis 10.26.10.doc
[2010/10/21 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/10/19 19:40:52 | 000,000,650 | —- | M] () – C:\Documents and Settings\JM\Desktop\Firefox.lnk
[2010/10/15 06:41:29 | 000,028,672 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 10.15..doc
[2010/10/14 05:29:46 | 000,040,448 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 218.doc
[2010/10/13 07:49:05 | 000,040,448 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 312.doc
[2010/10/07 16:37:10 | 000,000,162 | -H– | M] () – C:\Documents and Settings\JM\My Documents\~$ Birthday List.doc
[2010/10/07 16:37:09 | 001,334,272 | —- | M] () – C:\Documents and Settings\JM\My Documents\JM Birthday List.doc
[2010/10/05 19:32:59 | 000,031,232 | —- | M] () – C:\Documents and Settings\JM\My Documents\98-104.doc
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/01 22:29:01 | 003,898,593 | —- | C] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe
[2010/10/28 17:23:18 | 000,000,783 | —- | C] () – C:\Documents and Settings\JM\Desktop\Shortcut to chrome.lnk
[2010/10/27 16:44:16 | 000,028,672 | —- | C] () – C:\Documents and Settings\JM\My Documents\El tiempo en Miami.doc
[2010/10/24 18:59:09 | 000,020,992 | —- | C] () – C:\Documents and Settings\JM\My Documents\edgar allen poe.doc
[2010/10/24 15:16:22 | 000,029,696 | —- | C] () – C:\Documents and Settings\JM\My Documents\Independant Novel Synopsis 10.26.10.doc
[2010/10/19 19:40:52 | 000,000,650 | —- | C] () – C:\Documents and Settings\JM\Desktop\Firefox.lnk
[2010/10/15 06:41:28 | 000,028,672 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 10.15..doc
[2010/10/14 05:25:09 | 000,040,448 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 218.doc
[2010/10/13 07:49:05 | 000,040,448 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 312.doc
[2010/10/12 22:57:45 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/10/11 14:23:14 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\wavepadDowngrade.job
[2010/10/07 16:37:10 | 000,000,162 | -H– | C] () – C:\Documents and Settings\JM\My Documents\~$ Birthday List.doc
[2010/10/07 16:37:09 | 001,334,272 | —- | C] () – C:\Documents and Settings\JM\My Documents\JM Birthday List.doc
[2010/10/05 19:32:58 | 000,031,232 | —- | C] () – C:\Documents and Settings\JM\My Documents\98-104.doc
[2010/09/23 22:48:59 | 000,348,536 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/27 11:10:43 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/07/26 22:18:06 | 000,697,328 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2010/07/25 13:28:37 | 000,000,789 | —- | C] () – C:\WINDOWS\hegames.ini
[2010/04/06 22:13:07 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/03/04 19:21:05 | 000,050,630 | —- | C] () – C:\Documents and Settings\JM\Application Data\speech.wav
[2009/12/26 21:17:53 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/12/26 15:02:47 | 000,104,448 | —- | C] () – C:\Documents and Settings\JM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/26 02:00:22 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/26 01:19:06 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\John Hurst_KBD.ini
[2009/12/25 17:21:14 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\JM_KBD.ini
[2009/10/05 19:46:46 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/13 20:59:17 | 000,000,002 | —- | C] () – C:\WINDOWS\HotFixList.ini
[2009/05/13 20:59:11 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2009/05/13 20:59:11 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\Owner_KBD.ini
[2009/05/13 20:59:09 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2009/05/13 20:59:09 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2009/05/13 20:59:09 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2009/05/13 20:59:09 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2009/05/13 20:59:09 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2009/05/13 20:59:09 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2009/05/13 20:59:09 | 000,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2009/05/13 20:59:09 | 000,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2009/05/13 20:59:09 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2009/05/13 20:59:09 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2009/05/13 20:59:09 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2009/05/13 20:59:09 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2009/05/13 20:59:09 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2009/05/13 20:57:52 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2009/05/13 20:57:52 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2009/05/13 20:53:57 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/05/13 20:51:14 | 000,004,300 | —- | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2009/05/13 18:57:57 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/05/13 13:39:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/03/23 18:40:06 | 002,854,976 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2009/02/18 23:08:50 | 000,043,240 | —- | C] () – C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2009/02/18 23:08:48 | 000,025,560 | —- | C] () – C:\WINDOWS\System32\drivers\WOWFilter.sys
[2009/02/18 23:08:46 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 990 bytes -> C:\Program Files\WindowsUpdate:jUwsjxIR6OIzKGKUKuispnC92of
@Alternate Data Stream - 828 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:35E5AF34
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:453190EC
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:D1B5B4F1
@Alternate Data Stream - 1134 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:nBlALKTo5W826T0tCQ4f6WP9
@Alternate Data Stream - 1132 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:aIF2EwvJ6jviacDEypJ2H
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:5804A24D
@Alternate Data Stream - 1016 bytes -> C:\Program Files\WindowsUpdate:ZCgaypncyLSHfArnOH4DgoH66QzV

< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    FF - prefs.js..network.proxy.http: "127.0.0.1"
    [2010/03/27 11:13:27 | 000,002,389 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\barquery129.xml
    [2010/07/26 08:38:42 | 000,002,076 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
    O4 - HKCU..\Run: [CSmileys] C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe File not found
    O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe File not found
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
    
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )




Next

Delete the copy of Combofix you have and download a fresh one from one of the links below,if it will still not run try in safe mode

To get into the Windows XP Safe mode, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu" . Use your arrow keys to move to "Safe Mode" and press your Enter key.


Link 1
Link 2
hello..I ran OTL with your recommended script. The computer rebooted at the conclusion of the OTL run without saving a log file. I then downloaded a fresh version of Combofix and tried to run Combo fix in regular mode and continue to get the error messages as before. I rebooted in Safe Mode and was able to run Combofix in Safe Mode however it also rebooted automatically . The only Combofix log that I can find on the hard drive is located below. I don't believe this is the information that you are looking for however. ComboFix 10-11-03.04 - Administrator 11/04/2010 21:12:01.1.2 - x86 MINIMAL Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.817 [GMT -4:00] Running from: C:\Virus Scan\Combo Fix\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! .
I checked at C:/Combofix.txt as well as did a search on the C drive for Combo The only Combofix.txt file that I can locate has the information that I posted in the previous post. Would you like me to try to run it again in Safe Mode?
Delete the copy of combofix you have and download a fresh one but make sure you save it to your desktop

Try to run in normal mode first,also allow it to install the recovery console when asked
good evening. i downloaded a fresh version of Combofix to my desktop. I tried to run it in normal mode but I received the same error messages as before. I then switched to safe mode and tried to run it. I received an error message this time advising that Combo fix will not run with AVG anti virus installed. Combofix then closed. I attempted to uninstall AVG anti virus and was not successful. I received the following error message below while trying to uninstall the AVG. Local machine: installation failed Installation: Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: creating registry key…. Access is denied. I seem to be stuck here. Any additional suggestions? Thanks for your assistance.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI