This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infection - can't remove infected file

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my laptop has recently aquired an infection that keeps popping up mispelt security alerts and a Security Shield alert warning of 23 infections. Not having clicked on any of the scan buttons on these warnings I scanned the computer with Malwarebytes AntiMalware which displayed 1 infected file: securityshield.lnk. After clicking on Remove I restarted the computer but the problem was still there. Running Malwarebytes again, it keeps finding the same file. Norton doesn't find anything. I have just downloaded and run OTL, but only one text log was produced and when I try opening it, it flashes onto the screen and then disappears - I can't seem to get it to stay open. This is a netbook running Windows 7

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, say-no-2-trojans

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hi,

If you have an active internet connection, copy/paste the links below into your browser, don't click them or the rogue might redirect. If you don't have an active internet connection, download the tools from another machine, and transfer them to the affected machine via USB flash drive.

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.


rkill.exe
rkill.com
rkill.scr
WiNlOgOn.exe
uSeRiNiT.exe


Note:

You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

At this point, you should now be able to run analysis tools. Please re-run OTL again and post back here

If for some reason the machine reboots, repeat the process. Again, try not to restart the machine.

===================================================


Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
OTL log
MBAM log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Conspire, thanks for replying.

Running OTL this time the text log opened itself, but only OTL.txt - there is no sign of the Extras.txt log

I will rerun MBAM and post in next log



OTL logfile created on: 1/3/2011 4:03:32 PM - Run 4
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\siobhan\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,013.00 Mb Total Physical Memory | 228.00 Mb Available Physical Memory | 23.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 83.37 Gb Total Space | 60.61 Gb Free Space | 72.70% Space Free | Partition Type: NTFS
Drive D: | 55.58 Gb Total Space | 53.21 Gb Free Space | 95.74% Space Free | Partition Type: NTFS

Computer Name: SIOBHAN-MSI | User Name: siobhan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\siobhan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10i_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\System Control Manager\MGSysCtrl.exe (Micro-Star International Co., Ltd.)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\System Control Manager\MSIService.exe (Micro-Star International Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\siobhan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (Micro Star SCM) – C:\Program Files\System Control Manager\MSIService.exe (Micro-Star International Co., Ltd.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110102.003\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110102.003\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101231.001\IDSvix86.sys (Symantec Corporation)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEFA) – C:\windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\windows\system32\drivers\NIS\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\windows\system32\drivers\NIS\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SymNetS) – C:\windows\system32\drivers\NIS\1201000.025\SYMNETS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\windows\system32\drivers\NIS\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (SymDS) – C:\windows\system32\drivers\NIS\1201000.025\SYMDS.SYS (Symantec Corporation)
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (KSecPkg) – C:\windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (EUCR) – C:\windows\system32\DRIVERS\EUCR6SK.SYS (ENE Technology Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (netr28) – C:\Windows\System32\drivers\netr28.sys (Ralink Technology, Corp.)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (cmdide) – C:\windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\windows\system32\DRIVERS\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (ArcSoftKsUFilter) – C:\Windows\System32\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msi.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/12/30 20:39:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/12/30 20:37:48 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 21:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe (Micro-Star International Co., Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab (DLM Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\windows\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)


========== Files/Folders - Created Within 30 Days ==========

[2011/01/02 23:13:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\siobhan\Desktop\OTL.exe
[2010/12/30 22:38:32 | 003,194,296 | —- | C] (Javacool Software LLC ) – C:\Users\siobhan\Desktop\spywareblastersetup44.exe
[2010/12/30 22:08:25 | 000,000,000 | —D | C] – C:\Users\siobhan\AppData\Roaming\Malwarebytes
[2010/12/30 22:08:16 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2010/12/30 22:08:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2010/12/30 22:08:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/30 22:08:11 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2010/12/30 22:08:11 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/30 21:08:28 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\siobhan\Desktop\mbam-setup.exe
[2010/12/30 20:38:55 | 000,126,512 | —- | C] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2010/12/30 20:38:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/12/30 20:38:55 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/12/30 20:38:32 | 000,666,672 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.sys
[2010/12/30 20:38:32 | 000,489,008 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\srtsp.sys
[2010/12/30 20:38:32 | 000,339,504 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\SymDS.sys
[2010/12/30 20:38:32 | 000,294,448 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\symnets.sys
[2010/12/30 20:38:32 | 000,134,704 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\Ironx86.sys
[2010/12/30 20:38:32 | 000,050,096 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\srtspx.sys
[2010/12/30 20:37:57 | 000,000,000 | —D | C] – C:\windows\System32\drivers\NIS
[2010/12/30 20:37:57 | 000,000,000 | —D | C] – C:\windows\System32\drivers\NIS\1201000.025
[2010/12/30 20:37:48 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2010/12/30 20:37:48 | 000,000,000 | —D | C] – C:\Program Files\Norton Internet Security
[2010/12/30 20:34:36 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2010/12/30 20:33:02 | 095,672,064 | —- | C] (Symantec Corporation) – C:\Users\siobhan\Desktop\NIS-ESD-18-1-0-37-EN.exe
[2010/12/15 07:31:10 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\System32\tzres.dll
[2010/12/15 07:27:46 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\windows\System32\atmfd.dll
[2010/12/15 07:27:46 | 000,034,304 | —- | C] (Adobe Systems) – C:\windows\System32\atmlib.dll
[2010/12/15 07:27:38 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\windows\System32\mstime.dll
[2010/12/15 07:27:34 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2010/12/15 07:27:34 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2010/12/15 07:27:34 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2010/12/15 07:27:34 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2010/12/15 07:27:34 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2010/12/15 07:27:33 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2010/12/15 07:27:33 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\windows\System32\html.iec
[2010/12/15 07:27:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2010/12/15 07:27:33 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2010/12/15 07:27:33 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2010/12/15 07:27:26 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\windows\System32\taskschd.dll
[2010/12/15 07:27:26 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\windows\System32\wmicmiplugin.dll
[2010/12/15 07:27:26 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\windows\System32\taskcomp.dll
[2010/12/15 07:27:26 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\windows\System32\schtasks.exe
[2010/12/15 07:27:10 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\webio.dll
[2010/12/15 07:27:08 | 000,101,760 | —- | C] (Microsoft Corporation) – C:\windows\System32\consent.exe
[2010/12/15 07:26:53 | 002,327,552 | —- | C] (Microsoft Corporation) – C:\windows\System32\win32k.sys
[2010/12/09 19:57:58 | 000,000,000 | —D | C] – C:\Users\siobhan\Desktop\work
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/03 16:00:17 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\WiNlOgOn.exe
[2011/01/03 15:58:19 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.scr
[2011/01/03 15:54:41 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.com
[2011/01/03 15:25:50 | 000,012,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/03 15:25:50 | 000,012,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/03 15:25:48 | 000,021,018 | —- | M] () – C:\windows\System32\perfh009.dat
[2011/01/03 15:25:48 | 000,012,406 | —- | M] () – C:\windows\System32\perfc009.dat
[2011/01/03 15:18:49 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/03 15:18:24 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/01/03 15:18:19 | 796,622,848 | -HS- | M] () – C:\hiberfil.sys
[2011/01/03 15:12:30 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/03 15:10:39 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.exe
[2011/01/02 23:13:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\siobhan\Desktop\OTL.exe
[2010/12/30 22:38:42 | 003,194,296 | —- | M] (Javacool Software LLC ) – C:\Users\siobhan\Desktop\spywareblastersetup44.exe
[2010/12/30 22:08:18 | 000,001,077 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/30 21:08:38 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\siobhan\Desktop\mbam-setup.exe
[2010/12/30 20:39:58 | 001,014,814 | —- | M] () – C:\windows\System32\drivers\NIS\1201000.025\Cat.DB
[2010/12/30 20:38:55 | 000,126,512 | —- | M] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2010/12/30 20:38:55 | 000,007,456 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2010/12/30 20:38:55 | 000,000,805 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.INF
[2010/12/30 20:38:46 | 000,002,505 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/12/30 20:33:04 | 095,672,064 | —- | M] (Symantec Corporation) – C:\Users\siobhan\Desktop\NIS-ESD-18-1-0-37-EN.exe
[2010/12/30 20:24:40 | 000,249,856 | —- | M] () – C:\Users\siobhan\AppData\Local\uulhjqqec.exe
[2010/12/27 13:22:15 | 000,011,057 | —- | M] () – C:\Users\siobhan\Desktop\barclays own account.docx
[2010/12/27 13:20:51 | 000,013,060 | —- | M] () – C:\Users\siobhan\Desktop\barclays joint account.docx
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2010/12/16 08:45:27 | 000,333,080 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/03 16:00:13 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\WiNlOgOn.exe
[2011/01/03 15:58:12 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.scr
[2011/01/03 15:54:36 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.com
[2011/01/03 15:10:39 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.exe
[2010/12/30 22:08:17 | 000,001,077 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/30 20:39:04 | 001,014,814 | —- | C] () – C:\windows\System32\drivers\NIS\1201000.025\Cat.DB
[2010/12/30 20:38:55 | 000,007,456 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2010/12/30 20:38:55 | 000,000,805 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.INF
[2010/12/30 20:38:46 | 000,002,505 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/12/30 20:38:15 | 000,003,373 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.inf
[2010/12/30 20:38:15 | 000,002,792 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymDS.inf
[2010/12/30 20:38:15 | 000,001,445 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymNet.inf
[2010/12/30 20:38:15 | 000,001,389 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtspx.inf
[2010/12/30 20:38:15 | 000,001,383 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtsp.inf
[2010/12/30 20:38:14 | 000,000,741 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\Iron.inf
[2010/12/30 20:37:57 | 000,007,446 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymNet.cat
[2010/12/30 20:37:57 | 000,007,444 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.cat
[2010/12/30 20:37:57 | 000,007,442 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtspx.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymDS.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtsp.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\iron.cat
[2010/12/30 20:37:57 | 000,000,172 | —- | C] () – C:\windows\System32\drivers\NIS\1201000.025\isolate.ini
[2010/12/30 20:24:40 | 000,249,856 | —- | C] () – C:\Users\siobhan\AppData\Local\uulhjqqec.exe
[2010/10/08 18:08:05 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2010/07/24 10:48:36 | 000,000,768 | —- | C] () – C:\Users\siobhan\AppData\Roaming\wklnhst.dat
[2010/01/19 11:49:54 | 000,466,944 | —- | C] () – C:\windows\System32\RemoveDevice.dll
[2009/12/23 15:17:57 | 000,361,808 | —- | C] () – C:\windows\EMCRI_E.dll
[2009/11/24 07:13:39 | 000,073,728 | —- | C] () – C:\windows\System32\RtNicProp32.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\windows\System32\OGACheckControl.dll
[2009/07/13 23:51:43 | 000,073,728 | —- | C] () – C:\windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\windows\System32\BWContextHandler.dll

========== LOP Check ==========

[2010/10/08 18:09:13 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\Birdstep Technology
[2010/09/09 19:49:12 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\kidoz.52BCFEE1FEAB03D960EAF75B15C2A56D33E8320D.1
[2010/09/15 22:38:33 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\Template
[2010/11/18 15:47:40 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\Windows Live Writer
[2010/12/27 12:59:14 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 21:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 01:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/07/29 00:44:14 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 21:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/10/08 18:08:33 | 000,005,072 | —- | M] () – C:\debug.txt
[2011/01/03 15:18:19 | 796,622,848 | -HS- | M] () – C:\hiberfil.sys
[2011/01/03 15:18:21 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2011/01/03 16:02:01 | 000,000,356 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2009/07/14 04:52:25 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 04:52:25 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 04:52:25 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 04:52:25 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 21:31:19 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/27 03:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 01:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/23 00:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 04:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/24 10:51:05 | 000,000,221 | -HS- | M] () – C:\Users\siobhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/12/30 21:08:38 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\siobhan\Desktop\mbam-setup.exe
[2010/12/30 20:33:04 | 095,672,064 | —- | M] (Symantec Corporation) – C:\Users\siobhan\Desktop\NIS-ESD-18-1-0-37-EN.exe
[2011/01/02 23:13:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\siobhan\Desktop\OTL.exe
[2011/01/03 15:10:39 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.exe
[2010/12/30 22:38:42 | 003,194,296 | —- | M] (Javacool Software LLC ) – C:\Users\siobhan\Desktop\spywareblastersetup44.exe
[2011/01/03 16:00:17 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\WiNlOgOn.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-18 17:19:26

< End of report >
MBAM found 3 infected files this time Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5448 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 03/01/2011 16:27:58 mbam-log-2011-01-03 (16-27-58).txt Scan type: Quick scan Objects scanned: 136110 Time elapsed: 6 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\siobhan\local settings\application data\uulhjqqec.exe (Rogue.SecurityShield) -> Quarantined and deleted successfully. c:\Users\siobhan\AppData\Roaming\microsoft\Windows\start menu\Programs\security shield.lnk (Rogue.SecurityShield) -> Quarantined and deleted successfully. c:\Users\siobhan\Desktop\WiNlOgOn.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Good. We need to make sure everything is good before we can consider this clear.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
===================================================

Rerun OTL, this time without the custom scans command.

===================================================


On your next reply please post :
ESET log
OTL log

Good Day!
Ran them both, the ESET Online Scanner didn't find any threats and I didn't see the 'List of found threats' to push, neither did I see the 'Export to file', so there is no log to attach.

OTL log below:


OTL logfile created on: 1/4/2011 8:46:04 PM - Run 5
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\siobhan\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,013.00 Mb Total Physical Memory | 371.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 54.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 83.37 Gb Total Space | 60.47 Gb Free Space | 72.53% Space Free | Partition Type: NTFS
Drive D: | 55.58 Gb Total Space | 53.21 Gb Free Space | 95.74% Space Free | Partition Type: NTFS

Computer Name: SIOBHAN-MSI | User Name: siobhan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\siobhan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\System Control Manager\MGSysCtrl.exe (Micro-Star International Co., Ltd.)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\System Control Manager\MSIService.exe (Micro-Star International Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\siobhan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (Micro Star SCM) – C:\Program Files\System Control Manager\MSIService.exe (Micro-Star International Co., Ltd.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110104.002\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110104.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101231.001\IDSvix86.sys (Symantec Corporation)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEFA) – C:\windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\windows\system32\drivers\NIS\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\windows\system32\drivers\NIS\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SymNetS) – C:\windows\system32\drivers\NIS\1201000.025\SYMNETS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\windows\system32\drivers\NIS\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (SymDS) – C:\windows\system32\drivers\NIS\1201000.025\SYMDS.SYS (Symantec Corporation)
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (KSecPkg) – C:\windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (EUCR) – C:\windows\system32\DRIVERS\EUCR6SK.SYS (ENE Technology Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (netr28) – C:\Windows\System32\drivers\netr28.sys (Ralink Technology, Corp.)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (cmdide) – C:\windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\windows\system32\DRIVERS\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (ArcSoftKsUFilter) – C:\Windows\System32\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msi.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/12/30 20:39:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/12/30 20:37:48 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 21:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe (Micro-Star International Co., Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab (DLM Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\windows\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/04 18:31:31 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/04 18:18:53 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\siobhan\Desktop\ATF-Cleaner.exe
[2011/01/02 23:13:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\siobhan\Desktop\OTL.exe
[2010/12/30 22:38:32 | 003,194,296 | —- | C] (Javacool Software LLC ) – C:\Users\siobhan\Desktop\spywareblastersetup44.exe
[2010/12/30 22:08:25 | 000,000,000 | —D | C] – C:\Users\siobhan\AppData\Roaming\Malwarebytes
[2010/12/30 22:08:16 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2010/12/30 22:08:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2010/12/30 22:08:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/30 22:08:11 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2010/12/30 22:08:11 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/30 21:08:28 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\siobhan\Desktop\mbam-setup.exe
[2010/12/30 20:38:55 | 000,126,512 | —- | C] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2010/12/30 20:38:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/12/30 20:38:55 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/12/30 20:38:32 | 000,666,672 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.sys
[2010/12/30 20:38:32 | 000,489,008 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\srtsp.sys
[2010/12/30 20:38:32 | 000,339,504 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\SymDS.sys
[2010/12/30 20:38:32 | 000,294,448 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\symnets.sys
[2010/12/30 20:38:32 | 000,134,704 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\Ironx86.sys
[2010/12/30 20:38:32 | 000,050,096 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\srtspx.sys
[2010/12/30 20:37:57 | 000,000,000 | —D | C] – C:\windows\System32\drivers\NIS
[2010/12/30 20:37:57 | 000,000,000 | —D | C] – C:\windows\System32\drivers\NIS\1201000.025
[2010/12/30 20:37:48 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2010/12/30 20:37:48 | 000,000,000 | —D | C] – C:\Program Files\Norton Internet Security
[2010/12/30 20:34:36 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2010/12/30 20:33:02 | 095,672,064 | —- | C] (Symantec Corporation) – C:\Users\siobhan\Desktop\NIS-ESD-18-1-0-37-EN.exe
[2010/12/15 07:31:10 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\System32\tzres.dll
[2010/12/15 07:27:46 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\windows\System32\atmfd.dll
[2010/12/15 07:27:46 | 000,034,304 | —- | C] (Adobe Systems) – C:\windows\System32\atmlib.dll
[2010/12/15 07:27:38 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\windows\System32\mstime.dll
[2010/12/15 07:27:34 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2010/12/15 07:27:34 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2010/12/15 07:27:34 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2010/12/15 07:27:34 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2010/12/15 07:27:34 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2010/12/15 07:27:33 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2010/12/15 07:27:33 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\windows\System32\html.iec
[2010/12/15 07:27:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2010/12/15 07:27:33 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2010/12/15 07:27:33 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2010/12/15 07:27:26 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\windows\System32\taskschd.dll
[2010/12/15 07:27:26 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\windows\System32\wmicmiplugin.dll
[2010/12/15 07:27:26 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\windows\System32\taskcomp.dll
[2010/12/15 07:27:26 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\windows\System32\schtasks.exe
[2010/12/15 07:27:10 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\webio.dll
[2010/12/15 07:27:08 | 000,101,760 | —- | C] (Microsoft Corporation) – C:\windows\System32\consent.exe
[2010/12/15 07:26:53 | 002,327,552 | —- | C] (Microsoft Corporation) – C:\windows\System32\win32k.sys
[2010/12/09 19:57:58 | 000,000,000 | —D | C] – C:\Users\siobhan\Desktop\work
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/04 20:35:55 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/01/04 20:26:28 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/04 19:12:06 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/04 18:23:33 | 000,012,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/04 18:23:33 | 000,012,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/04 18:20:45 | 000,021,018 | —- | M] () – C:\windows\System32\perfh009.dat
[2011/01/04 18:20:45 | 000,012,406 | —- | M] () – C:\windows\System32\perfc009.dat
[2011/01/04 18:18:54 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\siobhan\Desktop\ATF-Cleaner.exe
[2011/01/04 18:16:03 | 796,622,848 | -HS- | M] () – C:\hiberfil.sys
[2011/01/03 15:58:19 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.scr
[2011/01/03 15:54:41 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.com
[2011/01/03 15:10:39 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.exe
[2011/01/02 23:13:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\siobhan\Desktop\OTL.exe
[2010/12/30 22:38:42 | 003,194,296 | —- | M] (Javacool Software LLC ) – C:\Users\siobhan\Desktop\spywareblastersetup44.exe
[2010/12/30 22:08:18 | 000,001,077 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/30 21:08:38 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\siobhan\Desktop\mbam-setup.exe
[2010/12/30 20:39:58 | 001,014,814 | —- | M] () – C:\windows\System32\drivers\NIS\1201000.025\Cat.DB
[2010/12/30 20:38:55 | 000,126,512 | —- | M] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2010/12/30 20:38:55 | 000,007,456 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2010/12/30 20:38:55 | 000,000,805 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.INF
[2010/12/30 20:38:46 | 000,002,505 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/12/30 20:33:04 | 095,672,064 | —- | M] (Symantec Corporation) – C:\Users\siobhan\Desktop\NIS-ESD-18-1-0-37-EN.exe
[2010/12/27 13:22:15 | 000,011,057 | —- | M] () – C:\Users\siobhan\Desktop\barclays own account.docx
[2010/12/27 13:20:51 | 000,013,060 | —- | M] () – C:\Users\siobhan\Desktop\barclays joint account.docx
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2010/12/16 08:45:27 | 000,333,080 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/03 15:58:12 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.scr
[2011/01/03 15:54:36 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.com
[2011/01/03 15:10:39 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.exe
[2010/12/30 22:08:17 | 000,001,077 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/30 20:39:04 | 001,014,814 | —- | C] () – C:\windows\System32\drivers\NIS\1201000.025\Cat.DB
[2010/12/30 20:38:55 | 000,007,456 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2010/12/30 20:38:55 | 000,000,805 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.INF
[2010/12/30 20:38:46 | 000,002,505 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/12/30 20:38:15 | 000,003,373 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.inf
[2010/12/30 20:38:15 | 000,002,792 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymDS.inf
[2010/12/30 20:38:15 | 000,001,445 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymNet.inf
[2010/12/30 20:38:15 | 000,001,389 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtspx.inf
[2010/12/30 20:38:15 | 000,001,383 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtsp.inf
[2010/12/30 20:38:14 | 000,000,741 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\Iron.inf
[2010/12/30 20:37:57 | 000,007,446 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymNet.cat
[2010/12/30 20:37:57 | 000,007,444 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.cat
[2010/12/30 20:37:57 | 000,007,442 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtspx.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymDS.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtsp.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\iron.cat
[2010/12/30 20:37:57 | 000,000,172 | —- | C] () – C:\windows\System32\drivers\NIS\1201000.025\isolate.ini
[2010/10/08 18:08:05 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2010/07/24 10:48:36 | 000,000,768 | —- | C] () – C:\Users\siobhan\AppData\Roaming\wklnhst.dat
[2010/01/19 11:49:54 | 000,466,944 | —- | C] () – C:\windows\System32\RemoveDevice.dll
[2009/12/23 15:17:57 | 000,361,808 | —- | C] () – C:\windows\EMCRI_E.dll
[2009/11/24 07:13:39 | 000,073,728 | —- | C] () – C:\windows\System32\RtNicProp32.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\windows\System32\OGACheckControl.dll
[2009/07/13 23:51:43 | 000,073,728 | —- | C] () – C:\windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\windows\System32\BWContextHandler.dll

========== LOP Check ==========

[2010/10/08 18:09:13 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\Birdstep Technology
[2010/09/09 19:49:12 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\kidoz.52BCFEE1FEAB03D960EAF75B15C2A56D33E8320D.1
[2010/09/15 22:38:33 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\Template
[2010/11/18 15:47:40 | 000,000,000 | —D | M] – C:\Users\siobhan\AppData\Roaming\Windows Live Writer
[2010/12/27 12:59:14 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
One last thing to do

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    
    :Commands
    [emptyflash]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

On your next reply please post :
OTL fix log
Fresh OTL log

Good Day!
OTL Fix Log: All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User: Default User User: Public User: siobhan ->Flash cache emptied: 56274 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: siobhan ->Temp folder emptied: 63106131 bytes ->Temporary Internet Files folder emptied: 102321734 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 6 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 6726 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 66048 bytes Total Files Cleaned = 158.00 mb OTL by OldTimer - Version 3.2.20.1 log created on 01052011_211635 Files\Folders moved on Reboot… C:\Users\siobhan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XSB2P5ZT\like[2].htm moved successfully. C:\Users\siobhan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IOK6EKDL\index[4].htm moved successfully. C:\Users\siobhan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92YDFM67\iframe[1].htm moved successfully. C:\Users\siobhan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\siobhan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. Registry entries deleted on Reboot…
OTL Log

OTL logfile created on: 1/5/2011 9:26:20 PM - Run 6
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\siobhan\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,013.00 Mb Total Physical Memory | 360.00 Mb Available Physical Memory | 36.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 60.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 83.37 Gb Total Space | 60.64 Gb Free Space | 72.74% Space Free | Partition Type: NTFS
Drive D: | 55.58 Gb Total Space | 53.21 Gb Free Space | 95.74% Space Free | Partition Type: NTFS

Computer Name: SIOBHAN-MSI | User Name: siobhan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\siobhan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10i_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\System Control Manager\MGSysCtrl.exe (Micro-Star International Co., Ltd.)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - \\?\C:\windows\System32\wbem\WMIADAP.EXE ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\System Control Manager\MSIService.exe (Micro-Star International Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\siobhan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (Micro Star SCM) – C:\Program Files\System Control Manager\MSIService.exe (Micro-Star International Co., Ltd.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110104.002\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110104.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101231.001\IDSvix86.sys (Symantec Corporation)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEFA) – C:\windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\windows\system32\drivers\NIS\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\windows\system32\drivers\NIS\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SymNetS) – C:\windows\system32\drivers\NIS\1201000.025\SYMNETS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\windows\system32\drivers\NIS\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (SymDS) – C:\windows\system32\drivers\NIS\1201000.025\SYMDS.SYS (Symantec Corporation)
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (KSecPkg) – C:\windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (EUCR) – C:\windows\system32\DRIVERS\EUCR6SK.SYS (ENE Technology Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (netr28) – C:\Windows\System32\drivers\netr28.sys (Ralink Technology, Corp.)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (cmdide) – C:\windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\windows\system32\DRIVERS\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (ArcSoftKsUFilter) – C:\Windows\System32\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msi.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/12/30 20:39:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/12/30 20:37:48 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 21:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe (Micro-Star International Co., Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab (DLM Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\windows\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/05 21:16:35 | 000,000,000 | —D | C] – C:\_OTL
[2011/01/04 18:31:31 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/04 18:18:53 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\siobhan\Desktop\ATF-Cleaner.exe
[2011/01/02 23:13:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\siobhan\Desktop\OTL.exe
[2010/12/30 22:38:32 | 003,194,296 | —- | C] (Javacool Software LLC ) – C:\Users\siobhan\Desktop\spywareblastersetup44.exe
[2010/12/30 22:08:25 | 000,000,000 | —D | C] – C:\Users\siobhan\AppData\Roaming\Malwarebytes
[2010/12/30 22:08:16 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2010/12/30 22:08:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2010/12/30 22:08:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/30 22:08:11 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2010/12/30 22:08:11 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/30 21:08:28 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\siobhan\Desktop\mbam-setup.exe
[2010/12/30 20:38:55 | 000,126,512 | —- | C] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2010/12/30 20:38:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/12/30 20:38:55 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/12/30 20:38:32 | 000,666,672 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.sys
[2010/12/30 20:38:32 | 000,489,008 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\srtsp.sys
[2010/12/30 20:38:32 | 000,339,504 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\SymDS.sys
[2010/12/30 20:38:32 | 000,294,448 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\symnets.sys
[2010/12/30 20:38:32 | 000,134,704 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\Ironx86.sys
[2010/12/30 20:38:32 | 000,050,096 | R— | C] (Symantec Corporation) – C:\windows\System32\drivers\NIS\1201000.025\srtspx.sys
[2010/12/30 20:37:57 | 000,000,000 | —D | C] – C:\windows\System32\drivers\NIS
[2010/12/30 20:37:57 | 000,000,000 | —D | C] – C:\windows\System32\drivers\NIS\1201000.025
[2010/12/30 20:37:48 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2010/12/30 20:37:48 | 000,000,000 | —D | C] – C:\Program Files\Norton Internet Security
[2010/12/30 20:34:36 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2010/12/30 20:33:02 | 095,672,064 | —- | C] (Symantec Corporation) – C:\Users\siobhan\Desktop\NIS-ESD-18-1-0-37-EN.exe
[2010/12/15 07:31:10 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\System32\tzres.dll
[2010/12/15 07:27:46 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\windows\System32\atmfd.dll
[2010/12/15 07:27:46 | 000,034,304 | —- | C] (Adobe Systems) – C:\windows\System32\atmlib.dll
[2010/12/15 07:27:38 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\windows\System32\mstime.dll
[2010/12/15 07:27:34 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2010/12/15 07:27:34 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2010/12/15 07:27:34 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2010/12/15 07:27:34 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2010/12/15 07:27:34 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2010/12/15 07:27:33 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2010/12/15 07:27:33 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\windows\System32\html.iec
[2010/12/15 07:27:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2010/12/15 07:27:33 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2010/12/15 07:27:33 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2010/12/15 07:27:26 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\windows\System32\taskschd.dll
[2010/12/15 07:27:26 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\windows\System32\wmicmiplugin.dll
[2010/12/15 07:27:26 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\windows\System32\taskcomp.dll
[2010/12/15 07:27:26 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\windows\System32\schtasks.exe
[2010/12/15 07:27:10 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\webio.dll
[2010/12/15 07:27:08 | 000,101,760 | —- | C] (Microsoft Corporation) – C:\windows\System32\consent.exe
[2010/12/15 07:26:53 | 002,327,552 | —- | C] (Microsoft Corporation) – C:\windows\System32\win32k.sys
[2010/12/09 19:57:58 | 000,000,000 | —D | C] – C:\Users\siobhan\Desktop\work

========== Files - Modified Within 30 Days ==========

[2011/01/05 21:29:33 | 000,012,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/05 21:29:33 | 000,012,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/05 21:28:48 | 000,021,018 | —- | M] () – C:\windows\System32\perfh009.dat
[2011/01/05 21:28:48 | 000,012,406 | —- | M] () – C:\windows\System32\perfc009.dat
[2011/01/05 21:22:20 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/05 21:21:55 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/01/05 21:21:50 | 796,622,848 | -HS- | M] () – C:\hiberfil.sys
[2011/01/05 21:12:24 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/04 18:18:54 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\siobhan\Desktop\ATF-Cleaner.exe
[2011/01/03 15:58:19 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.scr
[2011/01/03 15:54:41 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.com
[2011/01/03 15:10:39 | 000,780,283 | —- | M] () – C:\Users\siobhan\Desktop\rkill.exe
[2011/01/02 23:13:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\siobhan\Desktop\OTL.exe
[2010/12/30 22:38:42 | 003,194,296 | —- | M] (Javacool Software LLC ) – C:\Users\siobhan\Desktop\spywareblastersetup44.exe
[2010/12/30 22:08:18 | 000,001,077 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/30 21:08:38 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\siobhan\Desktop\mbam-setup.exe
[2010/12/30 20:39:58 | 001,014,814 | —- | M] () – C:\windows\System32\drivers\NIS\1201000.025\Cat.DB
[2010/12/30 20:38:55 | 000,126,512 | —- | M] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2010/12/30 20:38:55 | 000,007,456 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2010/12/30 20:38:55 | 000,000,805 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.INF
[2010/12/30 20:38:46 | 000,002,505 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/12/30 20:33:04 | 095,672,064 | —- | M] (Symantec Corporation) – C:\Users\siobhan\Desktop\NIS-ESD-18-1-0-37-EN.exe
[2010/12/27 13:22:15 | 000,011,057 | —- | M] () – C:\Users\siobhan\Desktop\barclays own account.docx
[2010/12/27 13:20:51 | 000,013,060 | —- | M] () – C:\Users\siobhan\Desktop\barclays joint account.docx
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2010/12/16 08:45:27 | 000,333,080 | —- | M] () – C:\windows\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2011/01/03 15:58:12 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.scr
[2011/01/03 15:54:36 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.com
[2011/01/03 15:10:39 | 000,780,283 | —- | C] () – C:\Users\siobhan\Desktop\rkill.exe
[2010/12/30 22:08:17 | 000,001,077 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/30 20:39:04 | 001,014,814 | —- | C] () – C:\windows\System32\drivers\NIS\1201000.025\Cat.DB
[2010/12/30 20:38:55 | 000,007,456 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2010/12/30 20:38:55 | 000,000,805 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.INF
[2010/12/30 20:38:46 | 000,002,505 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/12/30 20:38:15 | 000,003,373 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.inf
[2010/12/30 20:38:15 | 000,002,792 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymDS.inf
[2010/12/30 20:38:15 | 000,001,445 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymNet.inf
[2010/12/30 20:38:15 | 000,001,389 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtspx.inf
[2010/12/30 20:38:15 | 000,001,383 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtsp.inf
[2010/12/30 20:38:14 | 000,000,741 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\Iron.inf
[2010/12/30 20:37:57 | 000,007,446 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymNet.cat
[2010/12/30 20:37:57 | 000,007,444 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymEFA.cat
[2010/12/30 20:37:57 | 000,007,442 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtspx.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\SymDS.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\srtsp.cat
[2010/12/30 20:37:57 | 000,007,438 | R— | C] () – C:\windows\System32\drivers\NIS\1201000.025\iron.cat
[2010/12/30 20:37:57 | 000,000,172 | —- | C] () – C:\windows\System32\drivers\NIS\1201000.025\isolate.ini
[2010/10/08 18:08:05 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2010/07/24 10:48:36 | 000,000,768 | —- | C] () – C:\Users\siobhan\AppData\Roaming\wklnhst.dat
[2010/01/19 11:49:54 | 000,466,944 | —- | C] () – C:\windows\System32\RemoveDevice.dll
[2009/12/23 15:17:57 | 000,361,808 | —- | C] () – C:\windows\EMCRI_E.dll
[2009/11/24 07:13:39 | 000,073,728 | —- | C] () – C:\windows\System32\RtNicProp32.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\windows\System32\OGACheckControl.dll
[2009/07/13 23:51:43 | 000,073,728 | —- | C] () – C:\windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\windows\System32\BWContextHandler.dll

< End of report >
Great!

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

I'm pleased to let you know that your log is clean! :thumbup:

Thank you for your patience, and performing all of the procedures requested. I would also like to take this opportunity to apologize for any delay that may have occurred.

————————————————————————————————————–

Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:


MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.

Also, support is ending for some versions of Windows > http://windows.microsoft.com/en-us/w…ce-packs?os=xp


Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.


Make Internet Explorer more secure
Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.


SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an add-on available for both Firefox and IE.

  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
  • Download Host.zip and Save it to your Desktop.
  • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
  • Follow the prompts and click 'Finish'.
  • This will open the newly created hosts folder on your Desktop.
  • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
  • Once updated you should see another prompt that the task was completed.
Follow this list and keep your antivirus program and antispyware programs updated and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so.

**Please respond this one more time to ensure it is resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI