This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible HaxDoor Infection?

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few weeks ago, my computer was running normally - and then it shut itself off out of nowhere. Since then it's been behaving bizarrely; I've had issues with all of my firewall history disappearing and a warning when I log into Yahoo that 'my browser doesn't support redirects'. Also had trouble installing a support update for the Synaptecs TouchPad. This morning I closed my browser and it warned me that some files related to windows related to the operation of Chrome no longer exist. The browser opperated correctly, so I simply said it was working well when prompted. When I logged back on my HP Support assistant launched and asked me if I wanted to make changed to the computer. I said yes, figuring this was part of an update. It launched my HP health check and numerous features in it…including a cscript.exe file. Since then, I've found an exclusion data.xml file in my HP Healthcheck, updated today, with the following saved in it: - - SDBOTGood.xml -1 02/16/2006 - NAVVerGood.xml -1 02/16/2006 - DelProtSys.xml -1 02/16/2006 - HaxDoor.xml -1 02/16/2006 - SpywareAdvertizing.xml -1 02/16/2006 - SpywareError.xml -1 02/16/2006 - SpywarePrivacy.xml -1 02/16/2006 - SpywareSecurity.xml -1 02/16/2006 Also, I ran a variety of Rootkit detectors, and the only one that pulled up anything was CatchMe: disk not found C:\ please note that you need administrator rights to perform deep scan detected NTDLL code modification: ZwEnumerateKey 0 != 47, ZwQueryKey 0 != 19, ZwOpenKey 0 != 15, ZwClose 0 != 12, ZwEnumerateValueKey 0 != 16, ZwQueryValueKey 0 != 20, ZwOpenFile 0 != 48, ZwQueryDirectoryFile 0 != 50, ZwQuerySystemInformation 0 != 51Initialization error My Norton comes up with some medium-level activity, though no threat warnings: all of them seem to involve HPTouchCheck.exe has been submitted for a Sample Submission. Lots of instances of WerFault.exe. WMIPRVSE.EXE was blocked repeatedly from accessing the ccSvcHst file. A 6BF2.TMP\PEV.RKEXE tried repeatedly to access ccSvcHst.exe and was blocked (probably to do with the Root Repeal runs?) and also statistical submissions for krsqxp.exe, nircmd c.rkexe. There was also an error condition detected of high severity, errror class 0xFDB6E1EA. It blocked access thread data from Services, which triggered SymErr.exe. Statistical submissions for tlbjsw.exe and tmgrnwq.exe, vgslsf.exe. There are two IPS Detection Statistical submissions that mistake my downloading various programs as a remote attack, but the URL is seen as the attacker, not my PC. Here's what was in my windows event logs: The Application Virtualization Client Core initalized correctly My Windows live has opened a lot of process keys An error was detected on device\CDRom0 during a paging operation Failed Application Name: RootkitRevealer.exe Exception Code 0x00004cd MEMSWEEP2 service failed to start due to the following error: the driver has been blocked from loading (That's from Sophos) \??\C:\\Windows\system32\95ED.tmp has been blocked from loading due to incomaptibility with this system. Same for \??\C:\\Windows\system32\D33A.tmp Norton opened 8 Registry keys too The one that really caught my eye was: Volume Shadow Copy Service warning: VSS was denied access to the root volume of \\?\Volume(3106c431-cdac-11df-9a37-c80aa996553e]\ It says that administrator rights have been denied it and that it could prevent VSS from functioning properly. There was also a warning about a patch task for the CVHSVC that failed - Probably 'cause I dissabled my connection. Root Repeal also crashed because of werinternalmetadata.xml errors Also errors for the ITSS and HHCTRL, with EVENT IDs 1 and 1904 unable to be found. I found that I couldn't access the help functions on There's also a warning for the Application Virtualization client intitalizign correctly o_0 The winlogon notification subscriber was unavailible to handle a critical notification event. I found the error that caused my initial Chrome problem: Event Name PCA2 Fault Bucket 501991210 There was also a RADAR_PRE_LEAK_WOW64 for Acrobat just before this (I'd used it for the first time). The unauthorized modifications, according to my seccurity viewer, seem to be to D33A.TMP and 95ED.TMP. The effected computer is completely disconnected from the internet, so I'm typing from my unefected one. They did share the same Netgear wireless router, however. My symptoms are generalized slowness, and an occasional jumpy/spotty cursor. I've posted all of this to the Symantec official forum, and was redirected here for assitance. Here's my DDS log; Norton, MWB and SuperAntiSpyware scans have all come up clean: DDS (Ver_10-10-21.02) - NTFS_AMD64 Run by [removed] at 9:48:02.14 on Thu 10/28/2010 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.1787.139 [GMT -4:00] SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Users\melissa\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\DllHost.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe C:\Windows\system32\conhost.exe C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\NOTEPAD.EXE C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\melissa\Downloads\dds.scr C:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\IPSBHO.DLL BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll TB: @c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll uRun: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [Google Update] "C:\Users\melissa\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun: [] mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun-x64: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s mRun-x64: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe mRun-x64: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" mRun-x64: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden mRun-x64: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" ============= SERVICES / DRIVERS =============== R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1201000.025\SymDS64.sys [2010-10-25 450096] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1201000.025\SymEFA64.sys [2010-10-25 821808] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101001.001\BHDrvx64.sys [2010-8-31 954928] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101027.001\IDSviA64.sys [2010-10-19 476720] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360] R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1201000.025\Ironx64.sys [2010-10-25 168496] R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1201000.025\symnets.sys [2010-10-25 381488] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-9-20 7767552] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-9-20 279040] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-7-17 132656] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-23 344680] R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-4-24 721768] R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-4-24 269672] R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-4-24 25960] R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-4-24 22376] R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2010-5-15 38456] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-5-15 239136] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120] =============== Created Last 30 ================ 2010-10-28 11:13:14 ——– d—–w- C:\Program Files (x86)\ESET 2010-10-27 19:45:25 ——– d—–w- C:\PROGRA~3\Recovery 2010-10-26 17:15:19 ——– d—–w- C:\Program Files (x86)\MSN Toolbar 2010-10-26 17:14:12 ——– d—–w- C:\Program Files (x86)\Bing Bar Installer 2010-10-26 17:11:33 961024 —-a-w- C:\Windows\System32\CPFilters.dll 2010-10-26 17:11:33 641536 —-a-w- C:\Windows\SysWow64\CPFilters.dll 2010-10-26 17:11:33 552960 —-a-w- C:\Windows\System32\msdri.dll 2010-10-26 17:11:32 288256 —-a-w- C:\Windows\System32\MSNP.ax 2010-10-26 17:11:32 258560 —-a-w- C:\Windows\System32\mpg2splt.ax 2010-10-26 17:11:32 204288 —-a-w- C:\Windows\SysWow64\MSNP.ax 2010-10-26 17:11:32 199680 —-a-w- C:\Windows\SysWow64\mpg2splt.ax 2010-10-26 17:11:24 27008 —-a-w- C:\Windows\System32\drivers\Diskdump.sys 2010-10-25 19:55:12 381488 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\symnets.sys 2010-10-25 19:55:11 821808 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\SymEFA64.sys 2010-10-25 19:55:11 715824 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\srtsp64.sys 2010-10-25 19:55:11 450096 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\SymDS64.sys 2010-10-25 19:55:11 40496 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\srtspx64.sys 2010-10-25 19:55:11 168496 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\Ironx64.sys 2010-10-25 19:55:00 ——– d—–w- C:\Windows\System32\drivers\NISx64\1201000.025 2010-10-20 04:52:23 ——– d—–w- C:\Windows\en 2010-10-20 04:41:40 69464 —-a-w- C:\Windows\SysWow64\XAPOFX1_3.dll 2010-10-20 04:41:40 515416 —-a-w- C:\Windows\SysWow64\XAudio2_5.dll 2010-10-20 04:41:39 523088 —-a-w- C:\Windows\System32\d3dx10_42.dll 2010-10-20 04:41:39 453456 —-a-w- C:\Windows\SysWow64\d3dx10_42.dll 2010-10-20 04:41:07 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\266adaf1cb701105\DSETUP.dll 2010-10-20 04:41:07 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\266adaf1cb701105\DXSETUP.exe 2010-10-20 04:41:07 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\266adaf1cb701105\dsetup32.dll 2010-10-20 04:41:05 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\92d1731cb701104\DSETUP.dll 2010-10-20 04:41:05 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\92d1731cb701104\DXSETUP.exe 2010-10-20 04:41:05 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\92d1731cb701104\dsetup32.dll 2010-10-20 04:39:00 ——– d—–w- C:\Users\melissa\AppData\Local\Windows Live 2010-10-20 04:37:39 257024 —-a-w- C:\Windows\System32\mfreadwrite.dll 2010-10-20 04:37:39 206848 —-a-w- C:\Windows\System32\mfps.dll 2010-10-20 04:37:38 196608 —-a-w- C:\Windows\SysWow64\mfreadwrite.dll 2010-10-20 04:37:38 1888256 —-a-w- C:\Windows\System32\WMVDECOD.DLL 2010-10-20 04:37:38 1619456 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL 2010-10-20 04:37:36 4068864 —-a-w- C:\Windows\System32\mf.dll 2010-10-20 04:37:35 3181568 —-a-w- C:\Windows\SysWow64\mf.dll 2010-10-13 23:10:31 167424 —-a-w- C:\Program Files\Windows Media Player\wmplayer.exe 2010-10-13 23:10:31 164864 —-a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe 2010-10-13 23:10:30 12625920 —-a-w- C:\Windows\System32\wmploc.DLL 2010-10-13 23:10:30 12625408 —-a-w- C:\Windows\SysWow64\wmploc.DLL 2010-10-13 23:10:29 463360 —-a-w- C:\Windows\System32\drivers\srv.sys 2010-10-13 23:10:28 9728 —-a-w- C:\Windows\SysWow64\sscore.dll 2010-10-13 23:10:28 402944 —-a-w- C:\Windows\System32\drivers\srv2.sys 2010-10-13 23:10:28 236032 —-a-w- C:\Windows\System32\srvsvc.dll 2010-10-13 23:10:28 161792 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2010-10-13 23:10:27 3123712 —-a-w- C:\Windows\System32\win32k.sys 2010-10-02 05:34:35 ——– d—–w- C:\PROGRA~3\VirtualizedApplications 2010-10-02 03:22:37 ——– d—–w- C:\Users\melissa\AppData\Local\SoftGrid Client 2010-10-02 03:22:34 ——– d—–w- C:\Users\melissa\AppData\Roaming\SoftGrid Client 2010-10-02 03:20:15 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client 2010-10-02 03:19:16 ——– d—–w- C:\Users\melissa\AppData\Roaming\TP 2010-10-01 23:04:36 214824 —-a-w- C:\Windows\System32\SynTPAPI.dll 2010-10-01 23:04:36 147752 —-a-w- C:\Windows\System32\SynTPCo4.dll 2010-10-01 23:04:32 396584 —-a-w- C:\Windows\System32\SynCOM.dll 2010-10-01 22:58:35 1964576 —-a-w- C:\Windows\System32\RtPgEx64.dll 2010-10-01 22:58:35 1146912 —-a-w- C:\Windows\System32\RTSnMg64.cpl 2010-10-01 22:58:34 332320 —-a-w- C:\Windows\System32\RtlCPAPI64.dll 2010-10-01 22:58:34 2374560 —-a-w- C:\Windows\System32\drivers\RTKVHD64.sys 2010-10-01 22:58:33 2603040 —-a-w- C:\Windows\System32\RtkAPO64.dll 2010-10-01 22:58:33 149536 —-a-w- C:\Windows\System32\RtkCfg64.dll 2010-10-01 22:58:32 476192 —-a-w- C:\Windows\System32\RtkApi64.dll 2010-10-01 22:58:32 1216032 —-a-w- C:\Windows\System32\RTCOM64.dll 2010-10-01 22:58:31 70176 —-a-w- C:\Windows\System32\RCoInst64.dll 2010-09-28 21:19:19 243712 —-a-w- C:\Windows\System32\drivers\ks.sys 2010-09-28 21:19:19 184832 —-a-w- C:\Windows\System32\drivers\usbvideo.sys 2010-09-28 21:05:33 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2010-09-28 21:05:33 2048 —-a-w- C:\Windows\System32\tzres.dll 2010-09-28 21:05:22 13312 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll 2010-09-28 21:05:22 13312 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll ==================== Find3M ==================== 2010-10-25 19:55:29 174640 —-a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS 2010-10-01 22:55:18 1251872 —-a-w- C:\Windows\RtlExUpd.dll 2010-09-23 04:47:28 49016 —-a-w- C:\Windows\SysWow64\sirenacm.dll 2010-09-23 04:32:56 301936 —-a-w- C:\Windows\WLXPGSS.SCR 2010-09-21 18:49:02 252800 —-a-w- C:\Windows\System32\LIVESSP.DLL 2010-09-21 18:03:14 208768 —-a-w- C:\Windows\SysWow64\LIVESSP.DLL 2010-09-20 06:14:16 7767552 —-a-w- C:\Windows\System32\drivers\atikmdag.sys 2010-09-20 06:12:00 20734464 —-a-w- C:\Windows\System32\atio6axx.dll 2010-09-20 05:59:42 143360 —-a-w- C:\Windows\System32\atiapfxx.exe 2010-09-20 05:56:38 450560 —-a-w- C:\Windows\System32\ATIDEMGX.dll 2010-09-20 05:56:32 461824 —-a-w- C:\Windows\System32\atieclxx.exe 2010-09-20 05:56:00 203264 —-a-w- C:\Windows\System32\atiesrxx.exe 2010-09-20 05:54:54 120320 —-a-w- C:\Windows\System32\atitmm64.dll 2010-09-20 05:54:52 15828480 —-a-w- C:\Windows\SysWow64\atioglxx.dll 2010-09-20 05:54:38 421376 —-a-w- C:\Windows\System32\atipdl64.dll 2010-09-20 05:54:32 356352 —-a-w- C:\Windows\SysWow64\atipdlxx.dll 2010-09-20 05:54:22 278528 —-a-w- C:\Windows\SysWow64\Oemdspif.dll 2010-09-20 05:54:18 12288 —-a-w- C:\Windows\System32\atimuixx.dll 2010-09-20 05:54:14 59392 —-a-w- C:\Windows\System32\atiedu64.dll 2010-09-20 05:54:08 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll 2010-09-20 05:52:54 3147264 —-a-w- C:\Windows\System32\atiumd6a.dll 2010-09-20 05:51:20 3913216 —-a-w- C:\Windows\SysWow64\atidxx32.dll 2010-09-20 05:46:00 3390976 —-a-w- C:\Windows\SysWow64\atiumdva.dll 2010-09-20 05:42:58 4602880 —-a-w- C:\Windows\System32\atidxx64.dll 2010-09-20 05:33:38 53760 —-a-w- C:\Windows\System32\atimpc64.dll 2010-09-20 05:33:38 53760 —-a-w- C:\Windows\System32\amdpcom64.dll 2010-09-20 05:33:32 52736 —-a-w- C:\Windows\SysWow64\atimpc32.dll 2010-09-20 05:33:32 52736 —-a-w- C:\Windows\SysWow64\amdpcom32.dll 2010-09-20 05:33:30 4032512 —-a-w- C:\Windows\SysWow64\atiumdag.dll 2010-09-20 05:33:04 51200 —-a-w- C:\Windows\System32\aticalrt64.dll 2010-09-20 05:33:02 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll 2010-09-20 05:32:54 44544 —-a-w- C:\Windows\System32\aticalcl64.dll 2010-09-20 05:32:52 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll 2010-09-20 05:32:42 5425664 —-a-w- C:\Windows\System32\aticaldd64.dll 2010-09-20 05:31:36 4375552 —-a-w- C:\Windows\SysWow64\aticaldd.dll 2010-09-20 05:30:28 57344 —-a-w- C:\Windows\System32\coinst.dll 2010-09-20 05:27:42 5202944 —-a-w- C:\Windows\System32\atiumd64.dll 2010-09-20 05:21:30 338432 —-a-w- C:\Windows\System32\atiadlxx.dll 2010-09-20 05:21:24 241664 —-a-w- C:\Windows\SysWow64\atiadlxy.dll 2010-09-20 05:21:16 14848 —-a-w- C:\Windows\System32\atig6pxx.dll 2010-09-20 05:21:12 12800 —-a-w- C:\Windows\SysWow64\atiglpxx.dll 2010-09-20 05:21:12 12800 —-a-w- C:\Windows\System32\atiglpxx.dll 2010-09-20 05:21:10 21504 —-a-w- C:\Windows\System32\atig6txx.dll 2010-09-20 05:21:06 19968 —-a-w- C:\Windows\SysWow64\atigktxx.dll 2010-09-20 05:21:04 279040 —-a-w- C:\Windows\System32\drivers\atikmpag.sys 2010-09-20 05:20:24 39424 —-a-w- C:\Windows\System32\atiuxp64.dll 2010-09-20 05:20:18 30208 —-a-w- C:\Windows\SysWow64\atiuxpag.dll 2010-09-20 05:20:12 37376 —-a-w- C:\Windows\System32\atiu9p64.dll 2010-09-20 05:20:06 27648 —-a-w- C:\Windows\SysWow64\atiu9pag.dll 2010-09-20 05:19:34 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll 2010-09-15 08:50:37 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2010-09-10 05:35:44 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2010-09-10 05:35:43 347648 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2010-09-08 05:36:17 1192960 —-a-w- C:\Windows\System32\wininet.dll 2010-09-08 05:34:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2010-09-08 04:30:04 978432 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-09-08 04:28:15 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-09-08 04:16:38 482816 —-a-w- C:\Windows\System32\html.iec 2010-09-08 03:35:30 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-09-08 03:22:31 386048 —-a-w- C:\Windows\SysWow64\html.iec 2010-09-08 02:48:16 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2010-08-31 04:32:30 954752 —-a-w- C:\Windows\SysWow64\mfc40.dll 2010-08-31 04:32:30 954288 —-a-w- C:\Windows\SysWow64\mfc40u.dll 2010-08-26 05:27:28 148992 —-a-w- C:\Windows\System32\t2embed.dll 2010-08-26 04:39:58 109056 —-a-w- C:\Windows\SysWow64\t2embed.dll 2010-08-21 06:38:47 1024512 —-a-w- C:\Windows\System32\wmpmde.dll 2010-08-21 06:36:49 340992 —-a-w- C:\Windows\System32\schannel.dll 2010-08-21 06:31:06 633856 —-a-w- C:\Windows\System32\comctl32.dll 2010-08-21 06:29:47 558592 —-a-w- C:\Windows\System32\spoolsv.exe 2010-08-21 05:36:33 738816 —-a-w- C:\Windows\SysWow64\wmpmde.dll 2010-08-21 05:36:24 224256 —-a-w- C:\Windows\SysWow64\schannel.dll 2010-08-21 05:33:24 530432 —-a-w- C:\Windows\SysWow64\comctl32.dll ============= FINISH: 9:52:48.86 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-10-21.02) Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 7/17/2010 9:32:23 PM System Uptime: 10/28/2010 6:31:32 AM (3 hours ago) Motherboard: Hewlett-Packard | | 1444 Processor: AMD V120 Processor | Socket S1G4 | 2200/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 219 GiB total, 174.979 GiB free. D: is FIXED (NTFS) - 14 GiB total, 1.943 GiB free. E: is FIXED (FAT32) - 0 GiB total, 0.09 GiB free. F: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP64: 10/13/2010 8:50:35 PM - Windows Update RP65: 10/16/2010 1:34:33 AM - HPSF Restore Point RP66: 10/16/2010 1:52:20 AM - HPSF Applying updates RP67: 10/17/2010 7:00:12 PM - Windows Backup RP68: 10/20/2010 12:36:45 AM - Windows Update RP69: 10/22/2010 6:30:52 PM - HPSF Applying updates RP70: 10/23/2010 7:48:11 PM - Windows Update RP71: 10/25/2010 12:23:54 AM - Windows Backup RP72: 10/25/2010 1:55:19 PM - Installed Java™ 6 Update 22 RP73: 10/25/2010 5:28:16 PM - HPSF Applying updates RP74: 10/25/2010 5:34:32 PM - Windows Update RP75: 10/26/2010 1:11:47 PM - Windows Update RP76: 10/26/2010 1:27:08 PM - Windows Update ==== Installed Programs ====================== 1st Page 2000 2.00 Free Acrobat.com ActiveCheck component for HP Active Support Library Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9.4.0 MUI Adobe Shockwave Player AIM 7 Alien Outbreak 2 AMD USB Filter Driver Atheros Driver Installation Program Bejeweled Twist Bing Bar Bing Bar Platform Bing Rewards Client Installer Boulder Dash - Pirates Quest Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CinemaNow Media Manager Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Compatibility Pack for the 2007 Office system CyberLink DVD Suite CyberLink MediaShow CyberLink PowerDVD 9 CyberLink YouCam D3DX10 Download Updater (AOL LLC) ESU for Microsoft Windows 7 Google Chrome HP Advisor HP Customer Experience Enhancements HP Games HP MediaSmart CinemaNow 2.0 HP Photo Creations HP Power Plan Utility HP Setup HP Software Framework HP Support Assistant HP Update HP User Guides 0178 HPAsset component for HP Active Support Library Internet TV for Windows Media Center Ipswitch WS_FTP Home 2007 Jasc Animation Shop 3 Jasc Paint Shop Pro 9 Java Auto Updater Java™ 6 Update 22 Junk Mail filter update LabelPrint LightScribe System Software Malwarebytes' Anti-Malware Microsoft Default Manager Microsoft Office Click-to-Run 2010 Microsoft Office Home and Student 2010 - English Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Suite Activation Assistant Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works Microsoft WSE 3.0 Runtime MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Norton Internet Security Norton Online Backup PhotoNow! Power2Go PowerDirector Realtek Ethernet Controller Driver For Windows 7 Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Recovery Manager Roxio CinemaNow 2.0 Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Center Add-in for Flash ==== End Of File ===========================
Hi MML_1980,

Welcome to WhattheTech. My name is Blottedisk and I will be helping you with your malware issues.

  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.
  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay in response time, but I will do my best to keep it as short as possible.

The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.

Please bear with me, I will post back to you shortly with instructions.

Thanks :thumbup:
Hi again,


Please follow these steps:


Step 1 | Download SystemLook from one of the links below and save it to your disinfected computer's Desktop.

This is THE link

——————————————————————–
  • Copy SystemLook_x64.exe and paste it to an USB memory. Then go to the infected machine with the memory, and copy SystemLook_x64.exe from the USB memory to the infected machine's desktop.
  • Double-click SystemLook_x64.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :folderfind 
    6BF2.TMP
    *.TMP
    
    :filefind
    tlbjsw.exe
    tmgrnwq.exe
    vgslsf.exe
    SDBOTGood.xml
    NAVVerGood.xml
    DelProtSys.xml
    HaxDoor.xml
    SpywareAdvertizing.xml
    SpywareError.xml
    SpywarePrivacy.xml
    SpywareSecurity.xml
    
    :dir
    C:\WINDOWS\system32 /n*.tmp
    
    :file
    C:\Windows\system32\95ED.tmp
    C:\Windows\system32\D33A.tmp
    C:\WINDOWS\system32\ntdll.dll

  • Click the Look button to start the scan. It may took a while to complete.
  • When finished, a notepad window will open with the results of the scan (The log can also be found on your Desktop entitled SystemLook.txt). Copy the log to the USB memory, paste it in the disinfected machine, and post the log's contents in your next reply.

Step 2 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your disinfected machine's desktop, and put it in you infected machine's desktop with an USB memory.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the [external image: Posted Image] button.
  • Two reports will open, save them in the USB memory and copy and paste their contents in your next reply:

OTListIt.txt <– Will be opened
Extras.txt <– Will be minimized
Shall do this late this afternoon! Thank you so much :) I already have a copy of OTL on the other computer - shall burn the files to a CD and get you results ASAP!
And here are the results of the duel scans - System Look first, then OT6; I'd edit my response but I can't figure out how to here :/: Also, some of my desktop gadgets (the calendar, clock, and Windows Media ones) were gone when I checked it), and I only got one OLT log file:

SystemLook 04.09.10 by jpshortstuff
Log created at 14:27 on 31/10/2010 by melissa
Administrator - Elevation successful

========== folderfind ==========

Searching for "6BF2.TMP"
C:\Users\melissa\AppData\Local\Temp\6BF2.tmp d—— [16:37 28/10/2010]

Searching for "*.TMP"
C:\Users\melissa\AppData\Local\Temp\6BF2.tmp d—— [16:37 28/10/2010]
C:\Users\melissa\AppData\Local\Temp\CR_CED1.tmp d—— [04:59 24/10/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp d—— [05:00 14/07/2009]
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPB654.tmp d—— [09:14 15/05/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF181.tmp d—— [01:50 12/08/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF93B.tmp d—— [14:26 03/10/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP116E.tmp d—— [22:09 12/08/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP386D.tmp d—— [23:42 17/07/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP536E.tmp d—— [20:07 04/10/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPAB6B.tmp d—— [21:27 12/08/2010]
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp d—— [04:54 14/07/2009]
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp d—— [05:01 14/07/2009]

========== filefind ==========

Searching for "tlbjsw.exe"
No files found.

Searching for "tmgrnwq.exe"
No files found.

Searching for "vgslsf.exe"
C:\Users\melissa\AppData\Local\Temp\vgslsf.exe –a—- 61440 bytes [14:32 28/10/2010] [14:44 26/05/2010] 5165BCCE7258BFFB47933B034D39FB82

Searching for "SDBOTGood.xml"
No files found.

Searching for "NAVVerGood.xml"
No files found.

Searching for "DelProtSys.xml"
No files found.

Searching for "HaxDoor.xml"
No files found.

Searching for "SpywareAdvertizing.xml"
No files found.

Searching for "SpywareError.xml"
No files found.

Searching for "SpywarePrivacy.xml"
No files found.

Searching for "SpywareSecurity.xml"
No files found.

========== dir ==========

C:\WINDOWS\system32 - Parameters: "/n*.tmp"

—Files—
95ED.tmp ——- 6144 bytes [14:42 28/10/2010] [14:39 26/05/2010]
D33A.tmp ——- 6144 bytes [14:32 28/10/2010] [14:39 26/05/2010]

—Folders—
0409 d—— [05:37 14/07/2009]
AdvancedInstallers d—— [03:20 14/07/2009]
ar-SA d—— [03:20 14/07/2009]
bg-BG d—— [03:20 14/07/2009]
Boot d—— [03:20 14/07/2009]
catroot d—— [03:20 14/07/2009]
catroot2 d—— [03:20 14/07/2009]
CodeIntegrity d—— [03:20 14/07/2009]
com d—— [03:20 14/07/2009]
config d—— [03:20 14/07/2009]
cs-CZ d—— [03:20 14/07/2009]
da-DK d—— [03:20 14/07/2009]
de-DE d—— [03:20 14/07/2009]
Dism d—— [03:20 14/07/2009]
drivers d—— [03:20 14/07/2009]
DriverStore d—— [03:20 14/07/2009]
DRVSTORE d—-c- [08:37 15/05/2010]
el-GR d—— [03:20 14/07/2009]
en d—— [05:37 14/07/2009]
en-US d—— [03:20 14/07/2009]
es-ES d—— [03:20 14/07/2009]
et-EE d—— [03:20 14/07/2009]
fi-FI d—— [03:20 14/07/2009]
fr-FR d—— [03:20 14/07/2009]
FxsTmp d—— [05:32 14/07/2009]
GroupPolicy d—— [03:20 14/07/2009]
GroupPolicyUsers d—— [03:20 14/07/2009]
he-IL d—— [03:20 14/07/2009]
hr-HR d—— [03:20 14/07/2009]
hu-HU d—— [03:20 14/07/2009]
ias d—— [03:20 14/07/2009]
icsxml d—— [03:20 14/07/2009]
IME d—— [03:20 14/07/2009]
inetsrv d—— [03:20 14/07/2009]
it-IT d—— [03:20 14/07/2009]
ja-JP d—— [03:20 14/07/2009]
ko-KR d—— [03:20 14/07/2009]
LogFiles d—— [03:20 14/07/2009]
lt-LT d—— [03:20 14/07/2009]
lv-LV d—— [03:20 14/07/2009]
manifeststore d—— [03:20 14/07/2009]
Microsoft d—s– [04:45 14/07/2009]
migration d—— [03:20 14/07/2009]
migwiz d—— [03:20 14/07/2009]
Msdtc d—— [03:20 14/07/2009]
MUI d—— [03:20 14/07/2009]
nb-NO d—— [03:20 14/07/2009]
NDF d—— [03:20 14/07/2009]
NetworkList d—— [03:20 14/07/2009]
nl-NL d—— [03:20 14/07/2009]
nn-NO d—— [19:07 22/07/2010]
oobe d—— [03:20 14/07/2009]
pl-PL d—— [03:20 14/07/2009]
Printing_Admin_Scripts d—— [05:37 14/07/2009]
pt-BR d—— [03:20 14/07/2009]
pt-PT d—— [03:20 14/07/2009]
ras d—— [03:20 14/07/2009]
Recovery d—— [03:20 14/07/2009]
restore d—— [05:32 14/07/2009]
ro-RO d—— [03:20 14/07/2009]
ru-RU d—— [03:20 14/07/2009]
Setup d—— [03:20 14/07/2009]
sk-SK d—— [03:20 14/07/2009]
sl-SI d—— [03:20 14/07/2009]
slmgr d—— [05:37 14/07/2009]
SMI d—— [03:20 14/07/2009]
Speech d—— [03:20 14/07/2009]
spool d—— [03:20 14/07/2009]
spp d—— [03:20 14/07/2009]
sppui d—— [03:20 14/07/2009]
sr-Latn-CS d—— [03:20 14/07/2009]
sv-SE d—— [03:20 14/07/2009]
sysprep d—— [03:20 14/07/2009]
Tasks d—— [03:20 14/07/2009]
th-TH d—— [03:20 14/07/2009]
tr-TR d—— [03:20 14/07/2009]
uk-UA d—— [03:20 14/07/2009]
Wat d—— [23:26 17/07/2010]
wbem d—— [03:20 14/07/2009]
WCN d—— [05:37 14/07/2009]
wdi d—— [03:20 14/07/2009]
wfp d—— [03:20 14/07/2009]
WinBioDatabase d—— [05:32 14/07/2009]
WinBioPlugIns d—— [05:32 14/07/2009]
WindowsPowerShell d—— [05:32 14/07/2009]
winevt d—— [03:20 14/07/2009]
winrm d—— [05:37 14/07/2009]
zh-CN d—— [03:20 14/07/2009]
zh-HK d—— [03:20 14/07/2009]
zh-TW d—— [03:20 14/07/2009]

========== file ==========

C:\Windows\system32\95ED.tmp - File found and opened.
MD5: D70476AD02D6FD75282B196D3B58831D
Created at 14:42 on 28/10/2010
Modified at 14:39 on 26/05/2010
Size: 6144 bytes
Attributes: ——-
FileDescription: Memsweep kernel driver
FileVersion: 1.0
ProductVersion: 3 (Build 1501)
OriginalFilename: MEMSWEEP.SYS
InternalName: MEMSWEEP
ProductName: Sophos Anti-Virus
CompanyName: Sophos Plc
LegalCopyright: © 1989-2005 Sophos Plc, www.sophos.com

C:\Windows\system32\D33A.tmp - File found and opened.
MD5: D70476AD02D6FD75282B196D3B58831D
Created at 14:32 on 28/10/2010
Modified at 14:39 on 26/05/2010
Size: 6144 bytes
Attributes: ——-
FileDescription: Memsweep kernel driver
FileVersion: 1.0
ProductVersion: 3 (Build 1501)
OriginalFilename: MEMSWEEP.SYS
InternalName: MEMSWEEP
ProductName: Sophos Anti-Virus
CompanyName: Sophos Plc
LegalCopyright: © 1989-2005 Sophos Plc, www.sophos.com

C:\WINDOWS\system32\ntdll.dll - File found and opened.
MD5: 26AA6DF4C9ADCE650FD87EAF8DA7601C
Created at 22:49 on 17/07/2010
Modified at 06:59 on 24/03/2010
Size: 1736608 bytes
Attributes: –a—-
FileDescription: NT Layer DLL
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
ProductVersion: 6.1.7600.16385
OriginalFilename: ntdll.dll.mui
InternalName: ntdll.dll
ProductName: Microsoft® Windows® Operating System
CompanyName: Microsoft Corporation
LegalCopyright: © Microsoft Corporation. All rights reserved.

-= EOF =-

OTL logfile created on: 10/31/2010 2:40:40 PM - Run 3
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\melissa\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 40.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.02 Gb Total Space | 174.70 Gb Free Space | 79.77% Space Free | Partition Type: NTFS
Drive D: | 13.57 Gb Total Space | 1.94 Gb Free Space | 14.32% Space Free | Partition Type: NTFS
Drive E: | 99.18 Mb Total Space | 92.01 Mb Free Space | 92.77% Space Free | Partition Type: FAT32
Drive F: | 702.83 Mb Total Space | 673.45 Mb Free Space | 95.82% Space Free | Partition Type: UDF

Computer Name: ASHANDSHEILA | User Name: melissa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - Q:\140061.enu\Office14\WINWORD.EXE File not found
PRC - C:\Windows\SysWow64\atibtmon.exe File not found
PRC - C:\Users\melissa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\melissa\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\melissa\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (RtVOsdService) – C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (Realtek Semiconductor Corp.)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard)
SRV:64bit: - (HPWMISVC) – C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CinemaNow Service) – C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1201000.025\symnets.sys (Symantec Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1201000.025\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (MEMSWEEP2) – C:\Windows\SysNative\95ED.tmp (Sophos Plc)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101027.050\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101027.050\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101027.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101001.001\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQNOT/1


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-552858515-443163218-1712401079-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQNOT/1
IE - HKU\S-1-5-21-552858515-443163218-1712401079-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-552858515-443163218-1712401079-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/10/25 16:01:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/10/25 15:54:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/26 13:15:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/10/26 13:16:07 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (@c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-552858515-443163218-1712401079-1001\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Company)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-552858515-443163218-1712401079-1001..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKU\S-1-5-21-552858515-443163218-1712401079-1001..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe ()
O4 - HKU\S-1-5-21-552858515-443163218-1712401079-1001..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/31 14:21:32 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\melissa\Desktop\OTL.exe
[2010/10/30 15:46:01 | 000,000,000 | —D | C] – C:\Users\melissa\AppData\Roaming\Webroot
[2010/10/28 10:32:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sophos
[2010/10/27 15:45:25 | 000,000,000 | —D | C] – C:\ProgramData\Recovery
[2010/10/26 13:15:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSN Toolbar
[2010/10/26 13:14:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bing Bar Installer
[2010/10/26 13:11:33 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010/10/26 13:11:33 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010/10/26 13:11:33 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010/10/26 13:11:32 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010/10/26 13:11:32 | 000,258,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2010/10/26 13:11:32 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/10/26 13:11:32 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/10/26 13:11:24 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2010/10/25 13:57:43 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/10/25 13:57:43 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/10/25 13:57:43 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/10/20 00:52:23 | 000,000,000 | —D | C] – C:\Windows\en
[2010/10/20 00:45:08 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/10/20 00:41:40 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2010/10/20 00:41:40 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2010/10/20 00:41:39 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2010/10/20 00:41:39 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2010/10/20 00:39:00 | 000,000,000 | —D | C] – C:\Users\melissa\AppData\Local\Windows Live
[2010/10/20 00:37:39 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2010/10/20 00:37:39 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2010/10/20 00:37:38 | 001,888,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2010/10/20 00:37:38 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2010/10/20 00:37:38 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2010/10/20 00:37:36 | 004,068,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2010/10/20 00:37:35 | 003,181,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2010/10/13 19:11:41 | 000,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2010/10/13 19:11:41 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2010/10/13 19:11:40 | 002,085,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ole32.dll
[2010/10/13 19:11:38 | 000,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\comctl32.dll
[2010/10/13 19:11:36 | 000,483,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\StructuredQuery.dll
[2010/10/13 19:11:35 | 001,024,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmpmde.dll
[2010/10/13 19:11:33 | 000,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmpmde.dll
[2010/10/13 19:11:32 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40.dll
[2010/10/13 19:11:32 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40u.dll
[2010/10/13 19:11:06 | 000,702,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2010/10/13 19:11:06 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/10/13 19:11:05 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2010/10/13 19:11:05 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2010/10/13 19:11:05 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2010/10/13 19:11:04 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2010/10/13 19:11:04 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2010/10/13 19:11:04 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/10/13 19:11:04 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/10/13 19:11:04 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/10/13 19:11:04 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/10/13 19:11:04 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2010/10/13 19:11:04 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/10/13 19:11:04 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/10/13 19:10:33 | 014,627,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2010/10/13 19:10:32 | 011,406,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2010/10/13 19:10:30 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2010/10/13 19:10:30 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2010/10/13 19:10:28 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sscore.dll
[2010/10/02 01:34:35 | 000,000,000 | —D | C] – C:\ProgramData\VirtualizedApplications
[2010/10/01 23:22:37 | 000,000,000 | —D | C] – C:\Users\melissa\AppData\Local\SoftGrid Client
[2010/10/01 23:22:34 | 000,000,000 | —D | C] – C:\Users\melissa\AppData\Roaming\SoftGrid Client
[2010/10/01 23:20:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2010/10/01 23:20:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Application Virtualization Client
[2010/10/01 23:19:16 | 000,000,000 | —D | C] – C:\Users\melissa\AppData\Roaming\TP
[2010/10/01 22:46:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/10/01 22:45:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2010/10/01 19:04:36 | 000,214,824 | —- | C] (Synaptics Incorporated) – C:\Windows\SysNative\SynTPAPI.dll
[2010/10/01 19:04:36 | 000,147,752 | —- | C] (Synaptics Incorporated) – C:\Windows\SysNative\SynTPCo4.dll
[2010/10/01 19:04:32 | 000,396,584 | —- | C] (Synaptics Incorporated) – C:\Windows\SysNative\SynCOM.dll
[2010/10/01 18:58:35 | 001,964,576 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2010/10/01 18:58:35 | 001,146,912 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2010/10/01 18:58:34 | 000,332,320 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2010/10/01 18:58:33 | 002,603,040 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2010/10/01 18:58:33 | 000,149,536 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2010/10/01 18:58:32 | 001,216,032 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2010/10/01 18:58:32 | 000,476,192 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2010/10/01 18:58:31 | 000,070,176 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInst64.dll
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/31 14:21:16 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/31 14:21:16 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/31 14:13:35 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/31 14:13:19 | 1405,272,064 | -HS- | M] () – C:\hiberfil.sys
[2010/10/31 14:09:16 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\melissa\Desktop\OTL.exe
[2010/10/31 14:05:38 | 000,096,256 | —- | M] () – C:\Users\melissa\Desktop\SystemLook_x64.exe
[2010/10/30 15:50:36 | 000,624,622 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/10/30 15:50:36 | 000,106,708 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/10/30 15:50:35 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/10/30 15:41:51 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-552858515-443163218-1712401079-1001UA.job
[2010/10/30 01:59:00 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-552858515-443163218-1712401079-1001Core.job
[2010/10/28 09:05:48 | 000,002,567 | —- | M] () – C:\Users\melissa\Documents\PossibleHaxdoor.rtf
[2010/10/27 21:13:13 | 000,067,675 | —- | M] () – C:\Users\melissa\Documents\list07.rtf
[2010/10/26 13:11:17 | 001,223,606 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1201000.025\Cat.DB
[2010/10/25 16:02:50 | 000,001,327 | —- | M] () – C:\Users\melissa\Desktop\Norton Installation Files.lnk
[2010/10/25 16:00:43 | 000,002,489 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/10/25 15:55:29 | 000,174,640 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/10/25 15:55:29 | 000,007,440 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/10/25 15:55:29 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/10/24 02:21:16 | 000,031,822 | —- | M] () – C:\Users\melissa\Documents\LoveAtTheFiveandDime.rtf
[2010/10/24 01:00:16 | 000,002,404 | —- | M] () – C:\Users\melissa\Desktop\Google Chrome.lnk
[2010/10/13 21:11:28 | 000,351,704 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/10/09 00:45:52 | 000,000,340 | —- | M] () – C:\Windows\tasks\HPCeeScheduleFormelissa.job
[2010/10/08 14:14:26 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/10/02 20:32:34 | 000,743,534 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/01 19:04:09 | 000,214,824 | —- | M] (Synaptics Incorporated) – C:\Windows\SysNative\SynTPAPI.dll
[2010/10/01 19:04:09 | 000,147,752 | —- | M] (Synaptics Incorporated) – C:\Windows\SysNative\SynTPCo4.dll
[2010/10/01 19:04:08 | 000,396,584 | —- | M] (Synaptics Incorporated) – C:\Windows\SysNative\SynCOM.dll
[2010/10/01 18:55:39 | 001,964,576 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2010/10/01 18:55:39 | 001,146,912 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2010/10/01 18:55:39 | 000,332,320 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2010/10/01 18:55:38 | 000,149,536 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2010/10/01 18:55:37 | 002,603,040 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2010/10/01 18:55:37 | 001,216,032 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2010/10/01 18:55:37 | 000,476,192 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2010/10/01 18:55:37 | 000,070,176 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInst64.dll
[2010/10/01 18:55:18 | 001,251,872 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2010/10/01 18:55:17 | 000,000,712 | —- | M] () – C:\Windows\SysNative\drivers\RTEQEX0.dat
[2010/10/01 18:55:17 | 000,000,176 | —- | M] () – C:\Windows\SysNative\drivers\RTHDAEQ0.dat
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/31 14:21:17 | 000,096,256 | —- | C] () – C:\Users\melissa\Desktop\SystemLook_x64.exe
[2010/10/28 09:05:47 | 000,002,567 | —- | C] () – C:\Users\melissa\Documents\PossibleHaxdoor.rtf
[2010/10/25 15:52:46 | 000,001,327 | —- | C] () – C:\Users\melissa\Desktop\Norton Installation Files.lnk
[2010/10/01 23:20:49 | 000,743,534 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/01 18:58:51 | 000,000,176 | —- | C] () – C:\Windows\SysNative\drivers\RTHDAEQ0.dat
[2010/05/15 04:52:12 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2010/05/15 04:52:06 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/05/15 04:51:53 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/05/15 04:51:36 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/05/15 04:51:00 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/05/15 04:34:07 | 000,000,282 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/05/15 04:34:07 | 000,000,223 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/03/30 07:40:15 | 000,000,188 | —- | C] () – C:\Windows\SysWow64\HPWA.ini
[2010/03/30 06:27:07 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/03/30 06:21:27 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/03/30 06:20:04 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/03/30 06:19:24 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2010/02/09 21:58:12 | 000,012,800 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

< End of report >
Hi again,


Don't worry about extras.txt. As you had run OTL once before, this log was not generated this time.


There're no signs of malware in the machine. The several files that you spotted belong to Sophos Antirootkit, so they are ok. We will now run these two last scans, although at this point I believe your issues are not malware related and would be solved via non-malware related procedures. Please do the following:


Step 1 | Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    :Commands
    [purity]
    [EmptyFlash]
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.


Step 2 | As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform Quick scan, then click on Scan
  • When done, you will be prompted. Click OK. If Items are found, then click on Show Results
  • Check all items then click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply.

The log can also be found here:

  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when the application is started.

Note: MBAM may ask to reboot your computer so it can continue with the removal process, please do so immediately.
Failure to reboot will prevent MBAM from removing all the malware.


Step 3 | Please go to Kaspersky website and perform an online antivirus scan. Note: Internet Explorer should be used.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan and then put the kettle on!
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place like your Desktop. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Copy and paste the report into your next.

[external image: Posted Image]

Oh, that's good to hear! So the ignore list in the Windows Health Check doesn't matter because my Norton Firewall would have blocked it anyway? (I didn't notice the firewall ever being turned off, though event logging had stopped as I described before). And none of the processes/programs/malware listed in the xml allow list could mutate and change themselves to be listed under different file names? ETA: When I ran the support assistant, the reccomended action was a HP Systems Diagnostics UEFI. Should I run or ignore? Also, wscript.exe and cscript.exe launch whenever I do an HP Health Check - is this supposed to happen? Is it something my new Norton 2011 upgrade is catching that others didn't? Should I use my firewall to block them? Still getting that redirect on yahoo mail. Here's the results for OTL: All processes killed ========== OTL ========== ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User: Default User User: melissa ->Flash cache emptied: 28659 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: melissa ->Temp folder emptied: 81994095 bytes ->Temporary Internet Files folder emptied: 7343136 bytes ->Java cache emptied: 7140 bytes ->Google Chrome cache emptied: 447448741 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 12288 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 744977 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 827 bytes Total Files Cleaned = 513.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 11022010_023655 Files\Folders moved on Reboot… C:\Users\melissa\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Windows\temp\FXSAPIDebugLogFile.txt moved successfully. C:\Windows\temp\FXSTIFFDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… MWAB came up with nothing: Running Kaperspy right now, but will probably have to let it go overnight; will post it in the later in the afternoon :)
Here's the Kaperspy scan results. I also noticed that there's a copy identical to the ExclusionData xml in my HP Health Check/ Active Check folder, called FilteredObjects.xml with identical allow dates, but the date of the file is 9/15/2010. The function seemed to be triggered by a file called HPSACommander, as is the cscript and wscript functioned I mentioned before. Please do let me know if all of this is safe :) Well, my attempt at uploading the Txt for Kaperspy failed, so here's the result: Tuesday, November 2, 2010
Operating system: Microsoft (build 7600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, November 02, 2010 09:24:58
Records in database: 4202672 Scan settings scan using the following database extended Scan archives: yes Scan e-mail databases yes Scan area My Computer C:\
D:\
E:\
F:\
Q:\ Scan statistics Objects scanned 211037 Threats found: 0 Infected objects found 0 Suspicious objects found 0 Scan duration 04:47:06 No threats found. Scanned area is clean. Selected area has been scanned.
ETA: Have been having issues with my connection on this tonight - repeatedly kicked off my WAP connection, with the following warning: The server could not bind to the transport \Device\NetBT_Tcpip_{54A2EC54-F507-44F8-BC0E-CD68FC6C6515} because another computer on the network has the same name. The server could not start. Two laptops use this network within the household, but this computer is the only one with this name :/ . I'm pretty sure that's not a sign of hacking, on further research, because any hacker worth their salt wouldn't make two identical accounts on the same network. I'd had the same error in September, but I thought it was because the other laptop had the same name as this one - which they definitely do not have now. Streaming video is also jerky, and my cursor will occasionally freeze if I close a window while another task is running. Programs also open and close slowly if I have more than one window streaming video. Norton is reporting heavy CPU usage by the WMI provider host, and high memory and CPU usage by my browser during same. Double ETA: Yay for edit buttons :) . I forgot to mention that during my previous Sophos scan, it said: Failed to query live registry key \HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009. You may not have access rights to the whole registry. Should I be concerned? Oh, and: \SystemRoot\SysWow64\Drivers\Normandy.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Also, the following is listed in my Temp/Local Data/Quick Launch, even though I can't find it even when I make invisible files visible: Virus Trigger 2.INK 11/4: Norton submitted a DLLMM signature set to IPS Statistical. Also, Windows/System32/Services.exe in allcaps has been blocked from accessing thread data.
Hi there,


Those xml files are not present in your machine, so don't worry about them; and if any of them mutated they'd have been caught by any of the scans we've recently run. Normandy.sys belongs to one of the antirrotkits you have run that is not compatible with Windows 7. wscript.exe and cscript.exe are both Microsoft, legit files. And regarding that registry key, it's protected, so that's why Sophos is having some issues with it; but it's legit.


Also, the following is listed in my Temp/Local Data/Quick Launch, even though I can't find it even when I make invisible files visible:

Virus Trigger 2.INK



Are you receiving this notification from Norton? Could you please take a screenshot of this?


Still getting that redirect on yahoo mail.



Would you please give me more details on this?
Oh, thank you for that bit of peace of mind :)

Nope, I'm not receiving any warnings about it in Norton - it's one of the files I'd seen in my computer during the SuperAntiSpy scan I'd run a few weeks ago - it scans it but doesn't quarantine it or report it as a virus. I just happened to see the file because I paused my scan. How would I make a screencap of it?

The redirect reads "Error- If you are seeing this page your browser settings prevent you from automatically re-directing to a new URL. Then "please click here" with a hyperlink. It does auto-redirect me through to yahoo very quickly without clicking on the link. There have been Threads about it over on google and I presumed it had something to do with that - it doesn't to it in IE, only Chrome, and not on AOL on my other computer. If it was some kind of phishing thing, it wouldn't auto-redirect at all, I guess!
Hi again MML,


Sorry for the delay in replying. I've been doing some research, and according to your description of the problem and the scans we have run, this redirection issue doesn't appear to be malware related. The machine seems clean, so I would suggest you open a new thread at the Browsers, Internet and Email subforum, where a member from the Tech Team will help you with this problem, and hopefully you will be able to solve it. But before, please follow these last steps:


Step 1 | Clean up with OTL

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Now, from the desktop, delete any logs that you have left over.


Step 2 | Let's reset system restore.

  • Right-click on My Computer and go to Properties.
  • Click on the System Protection link
  • The System Properties dialog screen will open up. Click on Create
  • Type in a description for the restore point which will help you remember the point at which is was created
  • Wait while it creates the restore point
  • When finished, press the close button

    Next:

  • Click Start, type Cleanmgr.exe and press ENTER
  • Select the C drive from the list and click OK
  • Click Clean up system files
  • This restarts Disk Cleanup to run in elevated mode.
  • Select the C drive from the list and click OK
  • Click the More Options tab
  • Click the Clean up… button under System Restore and Shadow Copies.
  • Click OK


Last Step | Here are a few articles that will help you to prevent infections and malware:


Thank you for your patience, and performing all of the procedures requested. I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can then be closed. Posted Image

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI