This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

possible virus 2nd pc - continued

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, continued from: http://forums.whatthetech.com/index.php?sh…mp;#entry694706

Here if the ESET log file:


ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
esets_scanner_update returned -1 esets_gle=1
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=eacb508560441645bc6ac0149b9c4857
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-11-29 04:43:17
# local_time=2010-11-28 11:43:17 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 54791632 54791632 0 0
# compatibility_mode=768 16777215 100 0 538939 538939 0 0
# compatibility_mode=1026 16777214 0 2 32947130 32947130 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=213474
# found=8
# cleaned=0
# scan_time=6251
C:\Documents and Settings\MXC\Application Data\Sun\Java\Deployment\cache\6.0\9\7f1ee8c9-60c256a3 a variant of Java/TrojanDownloader.OpenStream.NAU trojan 00000000000000000000000000000000 I
C:\Documents and Settings\MXC\Local Settings\Temporary Internet Files\Content.IE5\Y31CJNYW\Retrogamer[1].exe a variant of Win32/AdInstaller application 00000000000000000000000000000000 I
C:\Documents and Settings\MXC\My Documents\appz\Nero8\Nero-8.1.1.0_eng_trial_wch.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 I
C:\Program Files\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\Process.exe.vir Win32/PrcView application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{24C3AF5F-B9F8-4A78-98E9-950FCA07D08A}\RP742\A0151069.exe Win32/PrcView application 00000000000000000000000000000000 I
C:\_OTListIt\MovedFiles\02282009_124454\WINDOWS\System32\ofiyevub.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
${Memory} a variant of Win32/HotSpotShield application 00000000000000000000000000000000 I
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Hi brokenhead,

Could you tell me what the "strange system tray notice" was? Is that problem related to the computer you need help with?

Please follow these directions:
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 22.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.
Next, run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
All processes killed ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 41 bytes User: HelpAssistant ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 41 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: MXC ->Temp folder emptied: 3330089 bytes ->Temporary Internet Files folder emptied: 511128372 bytes ->Java cache emptied: 103588409 bytes ->FireFox cache emptied: 28997630 bytes ->Flash cache emptied: 403501 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 81171329 bytes Total Files Cleaned = 695.00 mb [EMPTYFLASH] User: Administrator User: All Users User: Default User ->Flash cache emptied: 0 bytes User: HelpAssistant ->Flash cache emptied: 0 bytes User: LocalService User: MXC ->Flash cache emptied: 0 bytes User: NetworkService Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.17.3 log created on 12052010_092402
OTL logfile created on: 12/8/2010 8:06:25 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\MXC\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 372.83 Gb Free Space | 80.05% Space Free | Partition Type: NTFS

Computer Name: m | User Name: MXC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\MXC\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Hotspot Shield\bin\openvpntray.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\RapidSolution\Tunebite\Tunebite.exe (RapidSolution Software AG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe (Dell)
PRC - C:\WINDOWS\system32\dlbxcoms.exe (Dell)
PRC - C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\brss01a.exe (brother Industries Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\MXC\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (HssTrayService) – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe ()
SRV - (HotspotShieldService) – C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (SRS_PostInstaller) – C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (dlbx_device) – C:\WINDOWS\System32\dlbxcoms.exe (Dell)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (lgodd_filter) – C:\WINDOWS\System32\drivers\lgodd_filter.sys File not found
DRV - (catchme) – C:\DOCUME~1\MXC\LOCALS~1\Temp\catchme.sys File not found
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (taphss) – C:\WINDOWS\system32\drivers\taphss.sys (AnchorFree Inc)
DRV - (dsNcAdpt) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (tbhsd) – C:\WINDOWS\system32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (tapvpn) – C:\WINDOWS\system32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (NETw3x32) Intel® – C:\WINDOWS\system32\drivers\NETw3x32.sys (Intel® Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AGR1310_51) – C:\WINDOWS\system32\drivers\AGR1310_51.sys (Agere Systems)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (wowfilter) – C:\WINDOWS\system32\drivers\WOWFilter.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (AES2500) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (lgsnd_filter) – C:\WINDOWS\system32\drivers\lgsnd_filter.sys ()
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (LGDMEBTN) – C:\WINDOWS\system32\drivers\LGDMEBTN.sys (LG Electronics Inc.)
DRV - (Ndisipo) – C:\WINDOWS\system32\drivers\Ndisipo.sys (Windows ® 2000 DDK provider)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (BrSerIf) – C:\WINDOWS\system32\drivers\BrSerIf.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\WINDOWS\system32\drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/16 18:26:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/21 16:52:30 | 000,000,000 | —D | M]

[2008/07/17 01:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\MXC\Application Data\Mozilla\Extensions
[2010/11/14 09:13:27 | 000,000,000 | —D | M] – C:\Documents and Settings\MXC\Application Data\Mozilla\Firefox\Profiles\2j0wv06z.default\extensions
[2010/12/06 15:07:55 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/12/05 09:19:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/05 09:19:17 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/12/05 23:56:55 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [dlbxmon.exe] C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe (Dell)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Tunebite] C:\Program Files\RapidSolution\Tunebite\Tunebite.exe (RapidSolution Software AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: MasterCook: Select Image - C:\Program Files\MasterCook 9\Web\MCIEContext.hta ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://zone.msn.com/bingame/amun/default/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab55579.cab (ZPA_HRTZ Object)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/19 11:38:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/05 09:24:02 | 000,000,000 | —D | C] – C:\_OTL
[2010/12/05 09:19:29 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/05 09:19:29 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/05 09:19:29 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/05 09:19:29 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/11/23 23:17:47 | 000,000,000 | —D | C] – C:\Documents and Settings\MXC\Local Settings\Application Data\cache
[2010/11/23 23:17:08 | 000,000,000 | —D | C] – C:\Documents and Settings\MXC\Local Settings\Application Data\FullTiltPoker
[2010/11/23 23:16:48 | 000,000,000 | —D | C] – C:\Program Files\Full Tilt Poker
[2010/11/21 17:16:59 | 000,165,584 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/11/21 17:16:59 | 000,017,744 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/11/21 17:16:58 | 000,100,176 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/11/21 17:16:58 | 000,094,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/11/21 17:16:58 | 000,046,672 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/11/21 17:16:58 | 000,028,880 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/11/21 17:16:58 | 000,023,376 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/11/21 17:16:51 | 000,167,592 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/11/21 17:16:51 | 000,038,848 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2010/11/21 17:16:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/21 16:54:08 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/11/21 15:12:24 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/11/21 15:04:45 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/11/21 15:01:00 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/11/21 15:01:00 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/11/21 15:01:00 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/11/21 15:01:00 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/11/21 15:00:56 | 000,000,000 | —D | C] – C:\ComboFix
[2010/11/21 14:31:47 | 000,000,000 | —D | C] – C:\Qoobox
[2010/11/18 10:25:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/11/18 10:24:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\MXC\Recent
[2010/11/17 13:12:37 | 000,000,000 | —D | C] – C:\Documents and Settings\MXC\Application Data\HD Tune Pro
[2010/11/14 23:03:48 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/14 19:41:46 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\MXC\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2010/12/08 20:08:26 | 000,444,596 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/08 20:08:26 | 000,072,306 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/08 20:03:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/08 20:03:36 | 2682,769,408 | -HS- | M] () – C:\hiberfil.sys
[2010/12/07 23:36:28 | 000,031,744 | —- | M] () – C:\Documents and Settings\MXC\My Documents\Christmas Address List 2010.xls
[2010/12/05 23:56:55 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/05 23:56:48 | 000,001,162 | -H– | M] () – C:\Documents and Settings\MXC\My Documents\Default.rdp
[2010/12/05 09:19:17 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/12/05 09:19:17 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/05 09:19:17 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/05 09:19:17 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/05 09:19:17 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/11/28 23:54:33 | 000,002,533 | —- | M] () – C:\Documents and Settings\MXC\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/11/21 17:16:58 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/11/21 15:04:48 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2010/11/20 12:33:01 | 000,372,224 | —- | M] () – C:\Documents and Settings\MXC\Desktop\Bill Payment Tracking (MXC).xls
[2010/11/20 10:19:50 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/14 19:41:49 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\MXC\Desktop\OTL.exe
[2010/11/14 14:52:58 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat

========== Files Created - No Company Name ==========

[2010/12/07 23:36:27 | 000,031,744 | —- | C] () – C:\Documents and Settings\MXC\My Documents\Christmas Address List 2010.xls
[2010/11/21 15:04:48 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/11/21 15:04:45 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/11/21 15:01:00 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/11/21 15:01:00 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/11/21 15:01:00 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/11/21 15:01:00 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/11/21 15:01:00 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/09/21 10:16:45 | 002,463,976 | —- | C] () – C:\WINDOWS\System32\NPSWF32.dll
[2009/09/20 19:36:10 | 000,148,992 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/05/18 12:30:46 | 000,000,624 | —- | C] () – C:\WINDOWS\dellstat.ini
[2009/05/18 12:26:50 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\dlbxins.dll
[2009/05/18 12:26:50 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\dlbxinsr.dll
[2009/05/18 12:26:48 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbxvs.dll
[2009/05/18 12:26:44 | 000,397,312 | —- | C] () – C:\WINDOWS\System32\dlbxutil.dll
[2009/05/18 12:26:44 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlbxcu.dll
[2009/05/18 12:26:44 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\dlbxcur.dll
[2009/05/18 12:26:42 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlbxinsb.dll
[2009/05/18 12:26:41 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\dlbxjswr.dll
[2009/05/18 12:26:41 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dlbxcub.dll
[2008/05/28 23:24:05 | 000,006,592 | —- | C] () – C:\WINDOWS\gwpreset.ini
[2008/05/28 23:24:05 | 000,001,088 | —- | C] () – C:\WINDOWS\goldwave.ini
[2008/04/08 15:26:20 | 000,004,381 | —- | C] () – C:\Documents and Settings\MXC\Application Data\Cabos.plist
[2008/03/25 15:00:29 | 000,000,224 | —- | C] () – C:\Documents and Settings\MXC\Application Data\APUSet.xml
[2008/03/25 15:00:28 | 000,006,375 | —- | C] () – C:\Documents and Settings\MXC\Application Data\PrimoPDFSet.xml
[2008/03/25 14:03:12 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2008/02/15 14:08:26 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\f7129022-a000-4847-db07-470265a73c4f
[2008/01/13 09:44:22 | 000,010,247 | —- | C] () – C:\WINDOWS\lg_up.ini
[2007/11/11 21:15:18 | 000,001,617 | —- | C] () – C:\WINDOWS\ARCHPR.INI
[2007/10/13 18:40:55 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/09/12 19:33:33 | 000,717,296 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2007/09/03 22:06:00 | 000,000,600 | —- | C] () – C:\Documents and Settings\MXC\Local Settings\Application Data\PUTTY.RND
[2007/08/23 17:30:00 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2007/07/20 10:35:43 | 000,000,001 | —- | C] () – C:\Documents and Settings\MXC\Application Data\FrontEndCD.ini
[2007/07/20 08:30:36 | 000,126,464 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2007/05/06 18:05:01 | 000,038,473 | —- | C] () – C:\Documents and Settings\MXC\Application Data\Comma Separated Values (Windows).ADR
[2007/04/27 15:40:25 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/04/22 22:03:48 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/21 21:48:37 | 000,000,410 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2007/02/21 21:48:37 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2007/02/21 21:48:37 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2007/02/17 09:26:41 | 000,036,352 | —- | C] () – C:\Documents and Settings\MXC\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/07 15:43:38 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/02/07 13:06:12 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/07 11:34:03 | 000,000,130 | —- | C] () – C:\Documents and Settings\MXC\Local Settings\Application Data\fusioncache.dat
[2006/11/06 17:49:36 | 000,000,310 | —- | C] () – C:\WINDOWS\primopdf.ini
[2006/02/15 08:49:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/02/12 13:56:31 | 000,007,552 | —- | C] () – C:\WINDOWS\System32\drivers\lgsnd_filter.sys
[2006/02/11 00:15:22 | 000,000,992 | —- | C] () – C:\WINDOWS\lgcenter.ini
[2006/02/10 23:53:35 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/02/06 20:47:22 | 000,020,608 | —- | C] () – C:\WINDOWS\System32\drivers\WOWFilter.sys
[2006/02/06 20:47:20 | 000,036,352 | —- | C] () – C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2006/02/06 20:47:18 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/01/23 16:50:59 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/01/23 16:50:59 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/01/23 16:50:59 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/01/23 16:50:59 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/01/23 16:50:59 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/01/23 16:50:59 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/01/20 03:28:18 | 000,016,966 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/01/19 20:34:29 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CC56B59

< End of report >
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also please run OTL again and in the custom scans box, cut and paste the following: msconfig

Post the MBAM log along with the new OTL log.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI