This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

infected browser hijacked?

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Think i have malware or a virus not sure. I recently tried to remove bandoo and not sure if i was successful. I also notice now when i load firefox it always opens to a webpage called searchqu.com. Also now im getting alot of error messages on my computer and everything freezes up. My internet connection also goes down constantly since this all started. Any help would be appreciated. Thanks kindly Kevin C. Linkie. I attached log files from OTL.
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
also not sure if its important or not.. but i tried so hard to try and copy paste the results of the first 2 scans and add them in the same box as i am typing now. For some reason everytime i would hit send it wouldn't go thru. Only way it would go thru was attaching them. I even tried to copy and paste the 2 files in my email so i could send from another computer.. One of the files would send in the email the other wouldn't so i decided to try and attach them instead which worked. Will try to again post them the way you asked next scans i have to do. Thanks again.
Thanks for your concern about the copy and paste. While it certainly is the preferred way to provide data, if you find that it does not work for you - please feel free to attach any necessary files as .txt files. It won't be a problem at all. OK - here we go!



P2P - I see you have P2P software ( Β΅Torrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

If you choose to leave them on the machine, please refrain from using them while we are cleaning the machine to prevent further infection.



From your OTL log I can see it was unable to set a system restore point because system restore is disabled. You may have done this intentionally, or it may be the result of malware making changes on your machine. It is very important to have a system restore point to fall back on in case your system fails to boot as expected at any time. Before going any further, it is very important you do the following:

Turn on System Restore
  • Click Start, right-click My Computer, and then click Properties.
  • In the System Properties dialog box, click the System Restore tab.
  • Click to clear the Turn off System Restore check box. Or, click the Turn off System Restore on all drives check box.
  • Click OK.
  • After a few moments, the System Properties dialog box closes.
Set a new restore point:
  • Go to Start > Programs > Accessories > System Tools
  • Click "System Restore"
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next"
  • Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.

Note: If for any reason you are unable to complete this step please post back and let me know.


We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to: VirusTotal

    [external image: Posted Image]
  • Copy and paste the following file path, one at a time if more than file is listed, into the box next to "Browse" in the middle of the page:


    C:\WINDOWS\System32\drivers\utezotkx.sys
    C:\Documents and Settings\kevin and jose\Application Data\tc7.exe

  • Then click Send File
  • Please be patient while the file is scanned.
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a notice appears saying the file has been scanned already, please select Reanalyze now.
  • Once the Scan is completed, Copy and Paste the results of each scan into your next reply.




If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<β€” ROOKIT" entries
Hi again thanks for the help. As for Uttorent thanks for the information i thought everything was fine with uttorent and safe. Not so smart i guess. I will delete but for now i have some information i want to save so onto a disk before i lose everything. Will just leave it off and not touch it till after we are are done. I tried creating a system restore point but the system wont allow me too.
Virus total worked fine the information is below. Also defogger worked fine no problem. I tried running GMer many times but it would freeze upon start and wouldn't complete i would have to manually shut down the computer and start over. I also tried it in safe mode again still wouldn't work. Sorry tried my best with GMER.

What should i do next.

Again thanks so so much i really appreciate your help.


Heres the posts from virus total :

4 VT Community user(s) with a total of 700 reputation credit(s) say(s) this sample is goodware. 2 VT Community user(s) with a total of 9 reputation credit(s) say(s) this sample is malware.
File name:
utezotkx.sys
Submission date:
2011-01-07 21:24:51 (UTC)
Current status:
queued queued (#2) analysing finished
Result:
20/ 43 (46.5%)

VT Community

goodware
Safety score: 98.7%
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.01.08.00 2011.01.07 -
AntiVir 7.11.1.57 2011.01.07 -
Antiy-AVL 2.0.3.7 2011.01.07 -
Avast 4.8.1351.0 2011.01.07 -
Avast5 5.0.677.0 2011.01.07 -
AVG 9.0.0.851 2011.01.07 -
BitDefender 7.2 2011.01.07 Rootkit.Bagle.K
CAT-QuickHeal 11.00 2011.01.07 -
ClamAV 0.96.4.0 2011.01.07 Trojan.Agent-66914
Command 5.2.11.5 2011.01.07 W32/Bagle.IJ
Comodo 7329 2011.01.07 -
DrWeb 5.0.2.03300 2011.01.07 -
Emsisoft 5.1.0.1 2011.01.07 Trojan.Win32.Bagle!IK
eSafe 7.0.17.0 2011.01.06 Win32.Bagle.RC.worm
eTrust-Vet 36.1.8087 2011.01.07 -
F-Prot 4.6.2.117 2011.01.07 W32/Bagle.IJ
F-Secure 9.0.16160.0 2011.01.07 Rootkit:W32/Bagle.SR
Fortinet 4.2.254.0 2011.01.07 W32/Bagle.ZNG!worm
GData 21 2011.01.07 Rootkit.Bagle.K
Ikarus T3.1.1.90.0 2011.01.07 Trojan.Win32.Bagle
Jiangmin 13.0.900 2011.01.07 Trojan/Agent.cmdf
K7AntiVirus 9.75.3472 2011.01.07 Trojan
Kaspersky 7.0.0.125 2011.01.07 -
McAfee 5.400.0.1158 2011.01.07 -
McAfee-GW-Edition 2010.1C 2011.01.07 -
Microsoft 1.6402 2011.01.07 -
NOD32 5768 2011.01.07 -
Norman 6.06.12 2011.01.07 W32/Suspicious_Gen2.EPZRC
nProtect 2011-01-07.01 2011.01.07 Worm/W32.Bagle.7168
Panda 10.0.2.7 2011.01.07 -
PCTools 7.0.3.5 2011.01.07 Trojan-Downloader.Bagle
Prevx 3.0 2011.01.07 Medium Risk Malware
Rising 22.81.04.04 2011.01.07 Trojan.Win32.Generic.51E920C9
Sophos 4.61.0 2011.01.07 -
SUPERAntiSpyware 4.40.0.1006 2011.01.07 Trojan.Agent/Gen
Symantec 20101.3.0.103 2011.01.07 -
TheHacker 6.7.0.1.112 2011.01.07 Trojan/Rootkit.gen
TrendMicro 9.120.0.1004 2011.01.07 -
TrendMicro-HouseCall 9.120.0.1004 2011.01.07 -
VBA32 3.12.14.2 2011.01.06 -
VIPRE 7991 2011.01.07 -
ViRobot 2011.1.7.4242 2011.01.07 Trojan.Win32.Bagle.7168
VirusBuster 13.6.134.0 2011.01.07 -
Additional information
Show all
MD5 : 524d8d450622db4a7875b111c299a76b
SHA1 : fe22db1e0b864e77baeca5520c05c42431784fd8
SHA256: 7ae9aae77884ac0baa2f8168b3ed4de0c0c9834a42d8e5a775f47a2c66cec237
ssdeep: 96:wQQovxXZHQ7SioGfU2zSVeUvaUOPLNI8n1Sw1xJj0o:w+PQ/oV2z2eaaUOW8RI
File size : 7168 bytes
First seen: 2009-01-30 14:00:58
Last seen : 2011-01-07 21:24:51
TrID:
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher….: n/a
copyright….: Zaitsev Oleg, Copyright Β© 2004-2006
product……: AVZ Driver
description..: AVZ Driver
original name: avz.sys
internal name: avz.sys
file version.: 1, 2, 0, 0
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1990
timedatestamp….: 0x4788D40F (Sat Jan 12 14:51:59 2008)
machinetype……: 0x14c (I386)

[[ 6 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x9D4, 0xA00, 5.78, b65e29f81689fbde8b3d49891e4011de
.rdata, 0x2000, 0x144, 0x200, 2.93, 4c5e3a3a7d9a4ad57704be677563d7ca
.data, 0x3000, 0x20, 0x200, 0.26, 4f4f5306b935a3d853c02c6c206aa506
INIT, 0x4000, 0x292, 0x400, 3.74, a077364ef66a2ed1ad88d7557f37474a
.rsrc, 0x5000, 0x300, 0x400, 2.56, 85021f99de084aa59772f678fd7aaf3a
.reloc, 0x6000, 0x106, 0x200, 2.65, 173202905f3e2cfaecaf72eb73fd3c1c

[[ 2 import(s) ]]
ntoskrnl.exe: MmIsAddressValid, MmProbeAndLockPages, MmMapLockedPagesSpecifyCache, MmBuildMdlForNonPagedPool, IoAllocateMdl, _except_handler3, ObfDereferenceObject, ObReferenceObjectByName, MmUnlockPages, RtlInitUnicodeString, KeServiceDescriptorTable, PsGetCurrentProcessId, IoGetCurrentProcess, IoDeleteDevice, IoCreateSymbolicLink, IoCreateDevice, IoDeleteSymbolicLink, IoFreeMdl, IoDriverObjectType, IofCompleteRequest
HAL.dll: KfLowerIrql, KeRaiseIrqlToDpcLevel
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp…14F3D00CCFB2D16
ThreatExpert:
ThreatExpert info: http://www.threatexpert.com/report.aspx?md…875b111c299a76b

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
tc7.exe
Submission date:
2011-01-07 21:31:01 (UTC)
Current status:
queued (#5) queued (#2) analysing finished
Result:
2/ 43 (4.7%)

VT Community

not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.01.08.00 2011.01.07 -
AntiVir 7.11.1.57 2011.01.07 -
Antiy-AVL 2.0.3.7 2011.01.07 -
Avast 4.8.1351.0 2011.01.07 -
Avast5 5.0.677.0 2011.01.07 -
AVG 9.0.0.851 2011.01.07 -
BitDefender 7.2 2011.01.07 -
CAT-QuickHeal 11.00 2011.01.07 -
ClamAV 0.96.4.0 2011.01.07 -
Command 5.2.11.5 2011.01.07 -
Comodo 7329 2011.01.07 -
DrWeb 5.0.2.03300 2011.01.07 Trojan.Siggen1.63828
Emsisoft 5.1.0.1 2011.01.07 -
eSafe 7.0.17.0 2011.01.06 -
eTrust-Vet 36.1.8087 2011.01.07 -
F-Prot 4.6.2.117 2011.01.07 -
F-Secure 9.0.16160.0 2011.01.07 -
Fortinet 4.2.254.0 2011.01.07 -
GData 21 2011.01.07 -
Ikarus T3.1.1.90.0 2011.01.07 -
Jiangmin 13.0.900 2011.01.07 -
K7AntiVirus 9.75.3472 2011.01.07 -
Kaspersky 7.0.0.125 2011.01.07 -
McAfee 5.400.0.1158 2011.01.07 -
McAfee-GW-Edition 2010.1C 2011.01.07 -
Microsoft 1.6402 2011.01.07 -
NOD32 5768 2011.01.07 -
Norman 6.06.12 2011.01.07 -
nProtect 2011-01-07.01 2011.01.07 -
Panda 10.0.2.7 2011.01.07 -
PCTools 7.0.3.5 2011.01.07 -
Prevx 3.0 2011.01.07 Medium Risk Malware
Rising 22.81.04.04 2011.01.07 -
Sophos 4.61.0 2011.01.07 -
SUPERAntiSpyware 4.40.0.1006 2011.01.07 -
Symantec 20101.3.0.103 2011.01.07 -
TheHacker 6.7.0.1.112 2011.01.07 -
TrendMicro 9.120.0.1004 2011.01.07 -
TrendMicro-HouseCall 9.120.0.1004 2011.01.07 -
VBA32 3.12.14.2 2011.01.06 -
VIPRE 7991 2011.01.07 -
ViRobot 2011.1.7.4242 2011.01.07 -
VirusBuster 13.6.134.0 2011.01.07 -
Additional information
Show all
MD5 : 731634912edc79c13d02536ddcf8e236
SHA1 : 67d02e636776bad4bcc99ebdaeea386ddd6161d5
SHA256: 89b224c889587964b657d631d0be32cff484f65aab2ccf20d902e22449732883
ssdeep: 48:yOlxI9oQZHH1L6x/SaTDN/JHlsbCPZ4bkr5DNC8OaAcw3wEENK2:/lxIWQZN6JvYCh4bINNX
J3sEk2
File size : 16384 bytes
First seen: 2010-10-23 14:23:09
Last seen : 2011-01-07 21:31:01
TrID:
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: Project1
description..: n/a
original name: tc7.exe
internal name: tc7
file version.: 1.00
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1130
timedatestamp….: 0x4CA76325 (Sat Oct 02 16:51:49 2010)
machinetype……: 0x14c (I386)

[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xB70, 0x1000, 3.31, 897df4edf2ca63b71f752b1d0d3a9794
.data, 0x2000, 0x9E0, 0x1000, 0.00, 620f0b67a91f7f74151bc5be745b7110
.rsrc, 0x3000, 0x88C, 0x1000, 1.84, 0f3e9fca4e8126573335dadd8f682330

[[ 1 import(s) ]]
MSVBVM60.DLL: _CIcos, _adj_fptan, __vbaEnd, _adj_fdiv_m64, _adj_fprem1, _adj_fdiv_m32, _adj_fdiv_m16i, _adj_fdivr_m16i, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, _adj_fpatan, EVENT_SINK_Release, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaFPException, _CIlog, _adj_fdiv_m32i, _adj_fdivr_m32i, _adj_fdivr_m32, _adj_fdiv_r, -, _CIatan, _allmul, _CItan, _CIexp
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp…50F630003C3E6FD
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 4096
EntryPoint: 0x1130
FileFlagsMask: 0x0000
FileOS: Win32
FileSize: 16 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 1.0
FileVersionNumber: 1.0.0.0
ImageVersion: 1.0
InitializedDataSize: 8192
InternalName: tc7
LanguageCode: English (U.S.)
LinkerVersion:
Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now


After running Combofix, I'd like you to try and run GMER again. Please disable your McAfee Security Scan when you try it again. If it still does not work, while it's not ideal we can run it in safe mode. If you need to, please do the following:


Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account & try to run GMER as per the previous instructions.
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.
OK good morning. So i ran the combofix and it ran ok. During the scan it popped up a message saying rootkit activity and needed to reboot which i hit ok. it continued on and below you will find the results. Also After i finished running this i tried running Gmer again which froze the computer. I rebooted tried again with the same result. Then i ran it in safe mode it started to run but then again the computer froze up. I tried couple more times with the same results. Still no gmer for you sorry. Computer itself after running combofix is still running about the same. Very slow boot up takes forever to load into the regular mode sometimes it gets stuck on the blue screen sometimes it will load fine.

Heres combofix.


C:\ComboFix.txt

ComboFix 11-01-07.01 - kevin and jose 08/01/2011 7:57.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.2.1033.18.223.45 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\kevin and jose\Application Data\Local
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\0.ddi
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\1.2297166.avi&b=182(2).ddr
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\1.2297166.avi&b=182.ddr
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\1.ddi
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\2.ddi
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\phagmlpbcayg.avi.ddr
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\settings.ddi
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\1.2297166(2).avi&b=182
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\1.2297166.avi&b=182
c:\documents and settings\kevin and jose\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\phagmlpbcayg.avi
c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\searchqutb
c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\searchqutb\dtx.ini
c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\searchqutb\guid.dat
c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\searchqutb\setupCfg.xml

.
((((((((((((((((((((((((( Files Created from 2010-12-08 to 2011-01-08 )))))))))))))))))))))))))))))))
.

2011-01-07 02:22 . 2011-01-07 02:22 ——– d—–w- c:\documents and settings\kevin and jose\.pgdn
2011-01-07 02:16 . 2011-01-07 02:16 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\Sweepstakes Tracker
2011-01-07 02:15 . 2011-01-07 02:15 ——– d—–w- c:\program files\Sweepstakes Tracker
2011-01-03 19:22 . 2011-01-03 19:22 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\URSoft
2011-01-03 19:22 . 2011-01-03 19:22 ——– d—–w- c:\program files\Your Uninstaller 2010
2011-01-03 18:01 . 2011-01-08 12:52 ——– d—–w- c:\windows\system32\CatRoot2
2011-01-03 17:59 . 2011-01-03 19:25 ——– d—–w- c:\program files\Fun4IM
2011-01-03 14:27 . 2011-01-03 14:28 ——– d—–w- c:\documents and settings\Administrator
2011-01-03 14:03 . 2011-01-03 14:03 ——– d—–w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Identities
2011-01-03 13:48 . 2011-01-03 13:48 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\DriverCure
2011-01-03 13:48 . 2011-01-03 13:48 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\ParetoLogic
2011-01-03 13:47 . 2011-01-05 09:50 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\ParetoLogic
2011-01-01 17:35 . 2011-01-02 18:40 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\Media Player Classic
2011-01-01 16:37 . 2011-01-01 18:33 ——– d—–w- c:\documents and settings\kevin and jose\Local Settings\Application Data\WMTools Downloaded Files
2011-01-01 01:58 . 2011-01-01 01:58 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\Publish Providers
2011-01-01 01:44 . 2011-01-01 01:44 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Sony
2011-01-01 01:44 . 2011-01-01 01:44 ——– d—–w- c:\program files\Sony
2011-01-01 01:00 . 2011-01-01 01:00 ——– d—–w- c:\documents and settings\kevin and jose\Local Settings\Application Data\Sony
2011-01-01 00:54 . 2011-01-01 01:58 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\Sony
2010-12-24 08:18 . 2010-12-20 23:09 38224 β€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-24 08:18 . 2010-12-20 23:08 20952 β€”-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 22:46 . 2008-12-14 01:01 77824 β€”-a-w- c:\windows\system32\xvid.ax
2010-12-20 22:46 . 2008-12-05 02:42 815104 β€”-a-w- c:\windows\system32\xvidcore.dll
2010-12-20 22:46 . 2008-12-05 02:46 180224 β€”-a-w- c:\windows\system32\xvidvfw.dll
2010-12-20 22:46 . 2010-12-20 22:46 ——– d—–w- c:\program files\Xvid
2010-12-20 21:47 . 2010-12-20 21:48 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-12-20 21:45 . 2010-12-20 21:50 ——– d—–w- c:\program files\DivX
2010-12-20 21:44 . 2010-12-20 21:50 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX
2010-12-20 21:29 . 2011-01-03 21:30 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\vlc
2010-12-20 21:26 . 2010-12-20 21:26 ——– d—–w- c:\program files\VideoLAN
2010-12-18 09:33 . 2010-12-18 09:34 ——– d—–w- c:\program files\Combined Community Codec Pack
2010-12-12 23:14 . 2010-12-12 23:14 ——– d—–w- c:\program files\SystemRequirementsLab
2010-12-12 23:13 . 2010-12-12 23:13 ——– d—–w- c:\documents and settings\kevin and jose\Application Data\SystemRequirementsLab
2010-12-12 17:55 . 2010-12-12 17:55 ——– d—–w- c:\program files\Maxis
2010-12-12 17:31 . 1999-05-22 02:10 129024 β€”-a-w- c:\windows\system32\ZipDll.dll
2010-12-12 17:31 . 1999-05-22 02:10 115712 β€”-a-w- c:\windows\system32\UnzDll.dll
2010-12-12 17:31 . 2010-12-18 09:24 ——– d—–w- c:\program files\EasyZip
2010-12-12 17:31 . 1997-02-17 21:23 53248 β€”-a-w- c:\windows\system32\UNRAR.DLL
2010-12-12 17:30 . 1996-07-18 18:06 297472 β€”-a-w- c:\windows\uninst.exe
2010-12-12 17:30 . 2010-12-12 17:30 ——– d—–w- c:\documents and settings\kevin and jose\WINDOWS
2010-12-12 17:20 . 2010-12-12 17:20 ——– d—–w- c:\program files\Alcohol Soft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-12 17:14 . 2010-04-06 12:11 436792 β€”-a-w- c:\windows\system32\drivers\sptd.sys
2010-11-18 18:12 . 2010-02-23 22:12 81920 β€”-a-w- c:\windows\system32\isign32.dll
2010-11-12 00:44 . 2010-11-12 00:44 94208 β€”-a-w- c:\windows\system32\dpl100.dll
2010-11-08 22:57 . 2010-11-08 22:57 353592 β€”-a-w- c:\windows\system32\DivXControlPanelApplet.cpl
2010-11-06 00:26 . 2007-12-31 10:06 43520 β€”-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2007-12-31 10:06 1469440 β€”β€”w- c:\windows\system32\inetcpl.cpl
2010-11-06 00:26 . 2007-12-31 10:05 916480 β€”-a-w- c:\windows\system32\wininet.dll
2010-11-03 12:25 . 2007-12-31 10:06 385024 β€”-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 12:00 40960 β€”-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 12:00 290048 β€”-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2007-12-31 10:05 1853312 β€”-a-w- c:\windows\system32\win32k.sys
2010-10-10 20:24 . 2010-10-10 19:06 7168 β€”-a-w- c:\windows\system32\drivers\utezotkx.sys
2004-10-01 15:00 . 2003-05-25 04:37 40960 β€”-a-w- c:\program files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0391AB3B-CD91-4968-85FA-DAB3EE66A0D0}]
2010-01-27 00:06 57344 β€”-a-w- c:\program files\Wiley_IEURLlistener\URLlistener.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-03-29 160328]
"cdloader"="c:\documents and settings\kevin and jose\Application Data\mjusbsp\cdloader2.exe" [2010-02-26 50520]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-11-20 395128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-12-09 1226608]
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

R0 50503562;50503562 Boot Guard Driver;c:\windows\system32\drivers\50503562.sys [10/10/2010 10:05 AM 37392]
R1 50503561;50503561;c:\windows\system32\drivers\50503561.sys [10/10/2010 10:05 AM 128016]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [23/02/2010 11:38 AM 814278]
S3 utezotkx;AVZ Kernel Driver;c:\windows\system32\drivers\utezotkx.sys [10/10/2010 2:06 PM 7168]
S4 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys –> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = hxxp://www.google.com
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\documents and settings\kevin and jose\Application Data\Mozilla\Firefox\Profiles\mt1hxkpv.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=402&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: AI Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\Siber Systems\AI RoboForm\Firefox
FF - Ext: DivX Plus Web Player HTML5 : {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKU-Default-RunOnce-!SearchquFF - c:\windows\TEMP\INSTAL~1.DLL
AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\kevin and jose\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-08 08:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: HDS722580VLAT20 rev.V32OA6MA -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T1L0-3

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0xFFA32555]<<
c:\docume~1\KEVINA~1\LOCALS~1\Temp\catchme.sys
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0xffa387b0]; MOV EAX, [0xffa3882c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0xFFA68030]
3 CLASSPNP[0xF9EECFD7] -> nt!IofCallDriver[0x804E37D5] -> \Device\0000005f[0x8271EF18]
5 ACPI[0xF9E63620] -> nt!IofCallDriver[0x804E37D5] -> [0xFFA69D98]
\Driver\atapi[0xFF9F5708] -> IRP_MJ_CREATE -> 0xFFA32555
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP0T1L0-3 -> \??\IDE#DiskHDS722580VLAT20_________________________V32OA6MA#5&277c123c&0&0.1.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0xFFA3239B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !

**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”

- - - - - - - > 'winlogon.exe'(388)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(448)
c:\windows\system32\WININET.dll
.
Completion time: 2011-01-08 08:23:49
ComboFix-quarantined-files.txt 2011-01-08 13:23
ComboFix2.txt 2010-10-31 20:10

Pre-Run: 39,471,382,528 bytes free
Post-Run: 39,263,686,656 bytes free

Current=8 Default=8 Failed=7 LastKnownGood=9 Sets=1,2,3,4,5,6,7,8,9
- - End Of File - - C90F6963BB7DDC761411916060FAB225

Ok so since i last sent this i tried Gmer a few more times and i finally got it to work.

Heres the gmer post.

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-08 11:35:39
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 HDS722580VLAT20 rev.V32OA6MA
Running: gmer.exe; Driver: C:\DOCUME~1\KEVINA~1\LOCALS~1\Temp\kfdoipod.sys


β€”- User code sections - GMER 1.0.15 β€”-

.text C:\WINDOWS\Explorer.EXE[804] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[804] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[804] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
.text C:\WINDOWS\System32\svchost.exe[1396] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00CD000A
.text C:\WINDOWS\System32\svchost.exe[1396] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00CE000A
.text C:\WINDOWS\System32\svchost.exe[1396] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00CC000C
.text C:\WINDOWS\System32\svchost.exe[1396] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00DF000A

β€”- Devices - GMER 1.0.15 β€”-

Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 FFA0F39B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 FFA0F39B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 FFA0F39B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 FFA0F39B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-12 FFA0F39B
Device \Device\Ide\IdeDeviceP0T1L0-3 -> \??\IDE#DiskHDS722580VLAT20_________________________V32OA6MA#5&277c123c&0&0.1.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

β€”- Registry - GMER 1.0.15 β€”-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xA4 0x43 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9B 0x90 0xFD 0xB1 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x1A 0xD0 0x74 0x3A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x9D 0xA4 0x0A 0x43 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9A 0x3E 0xF9 0x57 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEA 0x3E 0xFF 0x34 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1A 0x3F 0xBE 0x2A …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x77 0x19 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEA 0xAE 0xCE 0x77 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\

β€”- Disk sectors - GMER 1.0.15 β€”-

Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;

β€”- EOF - GMER 1.0.15 β€”-
It looks like you may have had Kaspersky on your machine at some point. But it appears you are using McAfee for your antivirus solution now. There are a couple of leftover files from Kaspersky that I'm going to remove along with the other issues I've identified. Sometimes, leftover files from one antivirus solution can interfere and cause problems whan you switch to a new one. It is possible they can cause conflicts. It many or may not be related to some of your performance problems on your machine, but we'll clean them up to be sure.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    DRV - (50503562) – C:\WINDOWS\system32\DRIVERS\50503562.sys (Kaspersky Lab)
    DRV - (50503561) – C:\WINDOWS\system32\drivers\50503561.sys (Kaspersky Lab)
    DRV - (utezotkx) – C:\WINDOWS\system32\drivers\utezotkx.sys ()
    [2010/10/10 14:06:07 | 000,007,168 | β€”- | C] () – C:\WINDOWS\System32\drivers\utezotkx.sys
    [2011/01/03 16:19:26 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\searchqutb
    [2011/01/03 12:59:28 | 000,000,000 | β€”D | C] – C:\Program Files\Windows Searchqu Toolbar
    [2011/01/03 12:59:36 | 000,000,000 | β€”D | M] (DataMngr) – C:\PROGRAM FILES\WINDOWS SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION
    FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=402&q="
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/402"
    PRC - C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
    O2 - BHO: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
    O20 - AppInit_DLLs: (c:\progra~1\wi9130~1\datamngr\datamngr.dll) - c:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resulting OTL log please.


If you are not directed to do so, please reboot your computer after doing this, and let me know if there is any improvement in how it's running.
hi hi.. ok so i have done the scan. Computer still same very sluggish and not rebooting any faster. VERY slow rebooting. No more redirects so far on the browser. Heres the results. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Error: Unable to stop service 50503562! Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\50503562 deleted successfully. C:\WINDOWS\system32\drivers\50503562.sys moved successfully. Error: Unable to stop service 50503561! Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\50503561 deleted successfully. C:\WINDOWS\system32\drivers\50503561.sys moved successfully. Service utezotkx stopped successfully! Service utezotkx deleted successfully! C:\WINDOWS\system32\drivers\utezotkx.sys moved successfully. File C:\WINDOWS\System32\drivers\utezotkx.sys not found. Folder C:\Documents and Settings\kevin and jose\Application Data\searchqutb\ not found. Folder C:\Program Files\Windows Searchqu Toolbar\ not found. Folder C:\PROGRAM FILES\WINDOWS SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION\ not found. Prefs.js: "http://www.searchqu.com/web?src=ffb&systemid=402&q=" removed from keyword.URL Prefs.js: "http://www.searchqu.com/402" removed from browser.startup.homepage No active process named datamngrUI.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FF99715-3016-4381-84CE-E4E4C9673020}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FF99715-3016-4381-84CE-E4E4C9673020}\ not found. File C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FF99715-3016-4381-84CE-E4E4C9673020} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FF99715-3016-4381-84CE-E4E4C9673020}\ not found. File C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR not found. File C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls not found. File c:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngr.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 0 bytes User: All Users.WINDOWS User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: kevin and jose ->Temp folder emptied: 585788 bytes ->Temporary Internet Files folder emptied: 357874 bytes ->Java cache emptied: 54411 bytes ->FireFox cache emptied: 66045103 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 24731 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 983174 bytes ->Java cache emptied: 18756 bytes ->Flash cache emptied: 6065 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 9154492 bytes ->Java cache emptied: 37504 bytes ->Flash cache emptied: 7652 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 50595 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 74.00 mb [EMPTYFLASH] User: Administrator ->Flash cache emptied: 0 bytes User: All Users.WINDOWS User: Default User.WINDOWS ->Flash cache emptied: 0 bytes User: kevin and jose ->Flash cache emptied: 0 bytes User: LocalService.NT AUTHORITY ->Flash cache emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb Restore point Set: OTL Restore Point (0) OTL by OldTimer - Version 3.2.20.1 log created on 01082011_170139 Files\Folders moved on Reboot… C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\PIDYJM34\doclix_ad_ifrm[1].jsp moved successfully. File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LWWTLKG3\chinaontv[1].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\chinaontv[1].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\chinaontv[2].htm not found! C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\doclix_ad_ifrm[2].jsp moved successfully. C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\find[1].htm moved successfully. File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\viewid=18894256[1].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\viewid=18894256[2].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\viewid=18894256[3].htm not found! Registry entries deleted on Reboot… Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\PIDYJM34\doclix_ad_ifrm[1].jsp not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LWWTLKG3\chinaontv[1].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\chinaontv[1].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\chinaontv[2].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\doclix_ad_ifrm[2].jsp not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\find[1].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\viewid=18894256[1].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\viewid=18894256[2].htm not found! File\Folder C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\LB200V33\viewid=18894256[3].htm not found! Registry entries deleted on Reboot…
Sometimes progress is slow. I'm glad the redirects are gone. And on another bright note, OTL was able to set a restore point this time which is a very good thing!

I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
  • [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.

Please let me know how your machine is running now.
Hi again thanks and nope no redirects when i open the webpages anymore thanks for that.. one other problem of note though that i am having is plenty of pop ups that load web pages that i haven't opened. Also getting a notice windows needs to shut down generic win32 error every now and then. Internet will only stay active for about 10 minutes and i have to reboot. Sometimes if i leave the computer for 5 minutes and come back it will be offline and i cant connect unless i reboot. Strange. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5489 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 09/01/2011 1:58:50 PM mbam-log-2011-01-09 (13-58-50).txt Scan type: Quick scan Objects scanned: 142106 Time elapsed: 13 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    [2010/10/02 11:51:48 | 000,016,384 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Application Data\tc7.exe
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resulting OTL log.



Since you are still having pop-ups, I'd also like to get a fresh OTL log to check over again. Please be aware that you won't get an extras log this time. Just post the OTL log that is produced.

OTL Custom Scan

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it in your topic
hello again ok heres the next posts.

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
C:\Documents and Settings\kevin and jose\Application Data\tc7.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users.WINDOWS

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: kevin and jose
->Temp folder emptied: 15649989 bytes
->Temporary Internet Files folder emptied: 63137 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 45592749 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 3316 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 2171676 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 2392 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 7888879 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 3942 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 83363 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 68.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users.WINDOWS

User: Default User.WINDOWS
->Flash cache emptied: 0 bytes

User: kevin and jose
->Flash cache emptied: 0 bytes

User: LocalService.NT AUTHORITY
->Flash cache emptied: 0 bytes

User: NetworkService.NT AUTHORITY
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.20.1 log created on 01092011_170838

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

OTL logfile created on: 09/01/2011 5:43:19 PM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\kevin and jose\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

223.00 Mb Total Physical Memory | 30.00 Mb Available Physical Memory | 13.00% Memory free
547.00 Mb Paging File | 270.00 Mb Available in Paging File | 49.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 57.27 Gb Total Space | 37.49 Gb Free Space | 65.47% Space Free | Partition Type: NTFS

Computer Name: KEV-DBC684C1F4A | User Name: kevin and jose | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\kevin and jose\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe (Linksys)
PRC - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe (GEMTEKS)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\kevin and jose\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WMP54Gv4SVC) – C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe WMP54Gv4.exe File not found
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\DOCUME~1\KEVINA~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (SiSkp) – C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (RT61) Linksys Wireless-G PCI Adapter Driver(RT61) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (BCM42RLY) – C:\WINDOWS\system32\bcm42rly.sys (Broadcom Corporation)
DRV - (SISNIC) – C:\WINDOWS\system32\drivers\sisnic.sys (SiS Corporation)
DRV - (GTNDIS5) – C:\WINDOWS\system32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SiS7012) Service for AC'97 Sample Driver (WDM) – C:\WINDOWS\system32\drivers\sis7012.sys (Silicon Integrated Systems Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900


FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/02/18 13:31:00 | 000,000,000 | β€”D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010/12/20 16:50:22 | 000,000,000 | β€”D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010/12/20 16:50:23 | 000,000,000 | β€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/11 16:38:10 | 000,000,000 | β€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/02 17:43:03 | 000,000,000 | β€”D | M]

[2010/02/23 17:29:05 | 000,000,000 | β€”D | M] (No name found) – C:\Documents and Settings\kevin and jose\Application Data\Mozilla\Extensions
[2011/01/08 11:50:14 | 000,000,000 | β€”D | M] (No name found) – C:\Documents and Settings\kevin and jose\Application Data\Mozilla\Firefox\Profiles\mt1hxkpv.default\extensions
[2010/11/03 14:34:28 | 000,000,000 | β€”D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\kevin and jose\Application Data\Mozilla\Firefox\Profiles\mt1hxkpv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/21 17:31:44 | 000,002,059 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Application Data\Mozilla\Firefox\Profiles\mt1hxkpv.default\searchplugins\daemon-search.xml
[2010/03/12 15:55:02 | 000,002,477 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Application Data\Mozilla\Firefox\Profiles\mt1hxkpv.default\searchplugins\diigo–google.xml
[2011/01/08 11:50:14 | 000,000,000 | β€”D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/20 14:03:01 | 000,000,000 | β€”D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/31 19:45:06 | 000,000,000 | β€”D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/20 16:50:22 | 000,000,000 | β€”D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2010/12/20 16:50:23 | 000,000,000 | β€”D | M] (DivX HiQ) – C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2010/02/26 22:08:55 | 000,000,000 | β€”D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/02/18 13:31:00 | 000,000,000 | β€”D | M] (AI Roboform Toolbar for Firefox) – C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
[2010/09/15 03:50:38 | 000,472,808 | β€”- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/09/02 18:42:06 | 000,151,552 | β€”- | M] (PopCap Games) – C:\Program Files\Mozilla Firefox\plugins\nppopcaploader.dll
[2010/12/10 06:27:29 | 000,001,538 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/10 06:27:29 | 000,000,947 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/10 06:27:29 | 000,000,769 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/10 06:27:29 | 000,001,135 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/01/08 08:32:52 | 000,000,296 | β€”- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.8minutedating.com
O1 - Hosts: 127.0.0.1 whysohardx.com
O1 - Hosts: 127.0.0.1 protectyourpc-11.com
O1 - Hosts: 127.0.0.1 checkserverstatux.com
O1 - Hosts: 127.0.0.1 xinmin.cn
O1 - Hosts: 127.0.0.1 xy95.cn
O1 - Hosts: 127.0.0.1 koralda.com
O1 - Hosts: 127.0.0.1 weirden.com
O1 - Hosts: 127.0.0.1 nanocloudcontroller.com
O1 - Hosts: 127.0.0.1 coo0lnet.net
O2 - BHO: (UrlListenerBHO Class) - {0391AB3B-CD91-4968-85FA-DAB3EE66A0D0} - C:\Program Files\Wiley_IEURLlistener\URLlistener.dll (John Wiley && Sons Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKCU..\Run: [cdloader] C:\Documents and Settings\kevin and jose\Application Data\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://www.worldwinner.com/games/v47/share…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (WordMojo Control)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 11
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

========== Files/Folders - Created Within 30 Days ==========

[2011/01/08 17:01:39 | 000,000,000 | β€”D | C] – C:\_OTL
[2011/01/08 08:41:04 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/01/08 07:30:29 | 000,212,480 | β€”- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/01/08 07:30:29 | 000,161,792 | β€”- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/01/08 07:30:29 | 000,136,704 | β€”- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/01/08 07:30:29 | 000,031,232 | β€”- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/01/08 07:29:39 | 000,000,000 | β€”D | C] – C:\Qoobox
[2011/01/06 21:22:33 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\.pgdn
[2011/01/06 21:16:23 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\Sweepstakes Tracker
[2011/01/06 21:15:33 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Sweepstakes Tracker
[2011/01/06 21:15:05 | 000,000,000 | β€”D | C] – C:\Program Files\Sweepstakes Tracker
[2011/01/05 06:38:56 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/01/03 14:22:50 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\URSoft
[2011/01/03 14:22:28 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Your Uninstaller 2010
[2011/01/03 14:22:25 | 000,000,000 | β€”D | C] – C:\Program Files\Your Uninstaller 2010
[2011/01/03 13:01:04 | 000,000,000 | β€”D | C] – C:\WINDOWS\System32\CatRoot2
[2011/01/03 12:59:21 | 000,000,000 | β€”D | C] – C:\Program Files\Fun4IM
[2011/01/03 08:48:08 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\DriverCure
[2011/01/03 08:48:04 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\ParetoLogic
[2011/01/03 08:47:33 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ParetoLogic
[2011/01/02 13:40:27 | 000,000,000 | RH-D | C] – C:\Documents and Settings\kevin and jose\Recent
[2011/01/01 15:23:02 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Desktop\New Folder (5)
[2011/01/01 12:35:52 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\Media Player Classic
[2011/01/01 11:37:01 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Local Settings\Application Data\WMTools Downloaded Files
[2011/01/01 10:27:22 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Desktop\kev and joses files
[2010/12/31 20:58:45 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\Publish Providers
[2010/12/31 20:44:40 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Sony
[2010/12/31 20:44:23 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony
[2010/12/31 20:44:02 | 000,000,000 | β€”D | C] – C:\Program Files\Sony
[2010/12/31 20:00:57 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\My Documents\Vegas Movie Studio HD Platinum 10.0 Projects
[2010/12/31 20:00:57 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Local Settings\Application Data\Sony
[2010/12/31 19:54:04 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\Sony
[2010/12/24 03:18:13 | 000,038,224 | β€”- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/24 03:18:13 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2010/12/24 03:18:07 | 000,020,952 | β€”- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/20 17:46:09 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Xvid
[2010/12/20 17:46:06 | 000,000,000 | β€”D | C] – C:\Program Files\Xvid
[2010/12/20 16:49:56 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\DivX
[2010/12/20 16:48:35 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\DivX Plus
[2010/12/20 16:47:29 | 000,000,000 | β€”D | C] – C:\Program Files\Common Files\DivX Shared
[2010/12/20 16:45:04 | 000,000,000 | β€”D | C] – C:\Program Files\DivX
[2010/12/20 16:44:15 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\DivX
[2010/12/20 16:29:54 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\vlc
[2010/12/20 16:28:14 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\VideoLAN
[2010/12/20 16:26:57 | 000,000,000 | β€”D | C] – C:\Program Files\VideoLAN
[2010/12/18 04:34:04 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Combined Community Codec Pack
[2010/12/18 04:33:57 | 000,000,000 | β€”D | C] – C:\Program Files\Combined Community Codec Pack
[2010/12/12 18:14:33 | 000,000,000 | β€”D | C] – C:\Program Files\SystemRequirementsLab
[2010/12/12 18:13:49 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\Application Data\SystemRequirementsLab
[2010/12/12 13:01:45 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\My Documents\SimCity 4
[2010/12/12 13:01:21 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Maxis
[2010/12/12 12:55:49 | 000,000,000 | β€”D | C] – C:\Program Files\Maxis
[2010/12/12 12:31:25 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\EasyZip 2000
[2010/12/12 12:31:18 | 000,000,000 | β€”D | C] – C:\Program Files\EasyZip
[2010/12/12 12:30:26 | 000,297,472 | β€”- | C] (InstallShield Corporation, Inc.) – C:\WINDOWS\uninst.exe
[2010/12/12 12:30:25 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\WINDOWS
[2010/12/12 12:27:19 | 000,000,000 | β€”D | C] – C:\Documents and Settings\kevin and jose\My Documents\Alcohol 120%
[2010/12/12 12:20:19 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Alcohol 120%
[2010/12/12 12:20:10 | 000,000,000 | β€”D | C] – C:\Program Files\Alcohol Soft

========== Files - Modified Within 30 Days ==========

[2011/01/09 17:19:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/08 12:01:24 | 000,003,160 | β€”- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/08 08:32:52 | 000,000,296 | β€”- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/01/08 07:14:50 | 004,150,017 | Rβ€” | M] () – C:\Documents and Settings\kevin and jose\Desktop\ComboFix.exe
[2011/01/07 16:34:31 | 000,000,040 | β€”- | M] () – C:\Documents and Settings\kevin and jose\defogger_reenable
[2011/01/06 21:23:13 | 000,004,246 | β€”- | M] () – C:\ads_err.adt
[2011/01/06 21:21:58 | 000,003,072 | β€”- | M] () – C:\ads_err.adi
[2011/01/06 21:16:23 | 000,002,048 | β€”- | M] () – C:\ads_err.adm
[2011/01/06 21:15:33 | 000,000,820 | β€”- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Sweepstakes Tracker.lnk
[2011/01/03 14:43:10 | 000,432,664 | β€”- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/01/03 14:43:10 | 000,067,428 | β€”- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/01/03 14:38:18 | 000,146,016 | β€”- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/03 14:22:30 | 000,000,917 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Application Data\Microsoft\Internet Explorer\Quick Launch\Your Uninstaller!.lnk
[2011/01/03 14:22:30 | 000,000,761 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Desktop\Your Uninstaller!.lnk
[2011/01/03 13:11:42 | 006,299,648 | β€”- | M] () – C:\WINDOWS\sectest.db
[2011/01/03 09:46:04 | 000,023,392 | β€”- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2011/01/03 09:46:04 | 000,016,832 | β€”- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2011/01/02 17:43:05 | 000,001,734 | β€”- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2011/01/01 19:30:38 | 000,021,504 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/01 12:21:36 | 000,002,206 | β€”- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/31 20:57:24 | 000,002,624 | β€”- | M] () – C:\Documents and Settings\kevin and jose\My Documents\Register Vegas Movie Studio HD Platinum.htm
[2010/12/24 03:18:15 | 000,000,784 | β€”- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/20 18:09:00 | 000,038,224 | β€”- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | β€”- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/20 16:50:40 | 000,001,496 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Desktop\DivX Movies.lnk
[2010/12/20 16:49:41 | 000,000,777 | β€”- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Player.lnk
[2010/12/20 16:49:03 | 000,000,817 | β€”- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Converter.lnk
[2010/12/20 16:28:22 | 000,000,719 | β€”- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\VLC media player.lnk
[2010/12/14 09:44:57 | 000,000,301 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Desktop\Shortcut to Sounds and Audio Devices.lnk
[2010/12/12 17:47:57 | 000,000,800 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/12/12 17:47:55 | 000,000,815 | β€”- | M] () – C:\Documents and Settings\kevin and jose\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/12/12 12:56:02 | 000,000,124 | β€”- | M] () – C:\Documents and Settings\kevin and jose\My Documents\ax_files.xml
[2010/12/12 12:55:55 | 000,000,533 | β€”- | M] () – C:\WINDOWS\eReg.dat
[2010/12/12 12:30:22 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/12 12:30:22 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/12/12 12:20:22 | 000,000,833 | β€”- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Alcohol 120%.lnk
[2010/12/12 12:14:21 | 000,436,792 | β€”- | M] (Duplex Secure Ltd.) – C:\WINDOWS\System32\drivers\sptd.sys

========== Files Created - No Company Name ==========

[2011/01/08 07:30:29 | 000,256,512 | β€”- | C] () – C:\WINDOWS\PEV.exe
[2011/01/08 07:30:29 | 000,098,816 | β€”- | C] () – C:\WINDOWS\sed.exe
[2011/01/08 07:30:29 | 000,089,088 | β€”- | C] () – C:\WINDOWS\MBR.exe
[2011/01/08 07:30:29 | 000,080,412 | β€”- | C] () – C:\WINDOWS\grep.exe
[2011/01/08 07:30:29 | 000,068,096 | β€”- | C] () – C:\WINDOWS\zip.exe
[2011/01/08 07:14:34 | 004,150,017 | Rβ€” | C] () – C:\Documents and Settings\kevin and jose\Desktop\ComboFix.exe
[2011/01/06 21:16:23 | 000,004,246 | β€”- | C] () – C:\ads_err.adt
[2011/01/06 21:16:23 | 000,003,072 | β€”- | C] () – C:\ads_err.adi
[2011/01/06 21:16:23 | 000,002,048 | β€”- | C] () – C:\ads_err.adm
[2011/01/06 21:15:31 | 000,000,820 | β€”- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Sweepstakes Tracker.lnk
[2011/01/03 14:22:30 | 000,000,917 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Application Data\Microsoft\Internet Explorer\Quick Launch\Your Uninstaller!.lnk
[2011/01/03 14:22:30 | 000,000,761 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Desktop\Your Uninstaller!.lnk
[2011/01/03 09:22:04 | 000,029,184 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Desktop\How To.doc
[2011/01/03 09:21:19 | 000,003,038 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Desktop\fix_svchost.bat
[2011/01/02 17:43:04 | 000,001,734 | β€”- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2010/12/31 20:17:44 | 000,002,624 | β€”- | C] () – C:\Documents and Settings\kevin and jose\My Documents\Register Vegas Movie Studio HD Platinum.htm
[2010/12/24 03:18:15 | 000,000,784 | β€”- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/20 17:46:08 | 000,815,104 | β€”- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/12/20 17:46:08 | 000,077,824 | β€”- | C] () – C:\WINDOWS\System32\xvid.ax
[2010/12/20 17:46:07 | 000,180,224 | β€”- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/12/20 16:50:40 | 000,001,496 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Desktop\DivX Movies.lnk
[2010/12/20 16:49:41 | 000,000,777 | β€”- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Player.lnk
[2010/12/20 16:49:03 | 000,000,817 | β€”- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Converter.lnk
[2010/12/20 16:28:22 | 000,000,719 | β€”- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\VLC media player.lnk
[2010/12/14 09:44:57 | 000,000,301 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Desktop\Shortcut to Sounds and Audio Devices.lnk
[2010/12/12 17:47:52 | 000,000,800 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/12/12 12:55:55 | 000,000,533 | β€”- | C] () – C:\WINDOWS\eReg.dat
[2010/12/12 12:31:19 | 000,129,024 | β€”- | C] () – C:\WINDOWS\System32\ZipDll.dll
[2010/12/12 12:31:19 | 000,115,712 | β€”- | C] () – C:\WINDOWS\System32\UnzDll.dll
[2010/12/12 12:31:18 | 000,053,248 | β€”- | C] () – C:\WINDOWS\System32\UNRAR.DLL
[2010/12/12 12:30:22 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2010/12/12 12:30:22 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2010/12/12 12:27:33 | 000,000,124 | β€”- | C] () – C:\Documents and Settings\kevin and jose\My Documents\ax_files.xml
[2010/12/12 12:20:22 | 000,000,833 | β€”- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Alcohol 120%.lnk
[2010/11/14 05:23:14 | 006,083,776 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Application Data\Rihanna Feat. Drake - Whats My Name.zip
[2010/07/31 06:26:23 | 000,354,816 | β€”- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/05/17 17:16:13 | 000,021,504 | β€”- | C] () – C:\Documents and Settings\kevin and jose\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/08 03:45:12 | 000,094,208 | β€”- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2010/03/08 03:44:57 | 000,000,920 | β€”- | C] () – C:\WINDOWS\System32\WLAN.INI
[2010/02/23 12:02:07 | 000,004,161 | β€”- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/05/24 23:37:24 | 000,040,960 | β€”- | C] () – C:\Program Files\Uninstall_CDS.exe

========== LOP Check ==========

[2010/11/21 17:31:14 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\DAEMON Tools Lite
[2010/07/31 06:00:00 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\DAEMON Tools Pro
[2010/09/02 20:35:35 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\FunGames
[2010/11/21 20:50:45 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IMSIDesign
[2010/03/20 14:11:10 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Innovative Solutions
[2011/01/05 04:50:31 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ParetoLogic
[2010/03/20 13:38:26 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
[2011/01/03 14:32:10 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\RoboForm
[2010/12/31 20:44:23 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony
[2011/01/08 10:49:19 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/10/11 04:24:35 | 000,000,000 | β€”D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\WorldWinner
[2010/03/13 21:26:20 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\Absolute Poker
[2010/11/21 17:36:08 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\DAEMON Tools Lite
[2010/07/31 06:16:59 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\DAEMON Tools Pro
[2011/01/03 08:48:08 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\DriverCure
[2010/02/25 04:43:05 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\ElevatedDiagnostics
[2010/05/22 20:50:45 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\Facebook
[2010/04/05 03:34:13 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\GlarySoft
[2010/05/25 19:45:38 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\HTML Executable
[2010/10/24 08:56:45 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\LimeWire
[2010/07/14 07:32:38 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\mjusbsp
[2011/01/03 08:48:04 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\ParetoLogic
[2010/12/31 20:58:45 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\Publish Providers
[2010/12/31 20:58:02 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\Sony
[2011/01/06 21:16:23 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\Sweepstakes Tracker
[2010/12/12 18:13:49 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\SystemRequirementsLab
[2011/01/03 14:22:50 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\URSoft
[2011/01/09 17:33:23 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\uTorrent
[2010/09/02 18:56:25 | 000,000,000 | β€”D | M] – C:\Documents and Settings\kevin and jose\Application Data\Worldwinner

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5C321E34
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:1CE11B51

< End of report >
Please read carefully and follow these steps.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI