This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need help cleaning System Tool 2011 & more

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My son's computer got infected with System Tool 2011 and other misc things. Followed your System Tool self-removal instructions and have run MBAM and let it clean what it found. Computer is much better than it was, but still has a couple of significant issues. The computer will get online and surf to most sites, but cannot access microsoft update. It also still sometimes throws false 'your system/registry/whatever is infected' pop-ups/messages. It even gave a 'connection reset' every time i tried to post this help request to this site from that computer. Most other behavior seems pretty normal, but I need to be sure EVERYTHING is cleaned up on this machine before returning it.

Here's a current HJT log as a starting point, and I'm ready to run whatever other tools are recommended an take whatever steps are needed to ensure a fully clean system: Thanks in advance for any help.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:48:26 PM, on 1/8/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
D:\Program Files\Secunia\PSI\PSIA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
D:\Program Files\Motherboard Monitor 5\MBM5.EXE
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\CreataCard\Gold\FMRemind.exe
D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
D:\Program Files\Secunia\PSI\psi_tray.exe
D:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
D:\Program Files\HijackThis\HiJackThis-Install-2.0.4.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [MBM 5] "D:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ASUS Probe] D:\Program Files\ASUS\Asus Probe\AsusProb.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [smlmjydd] C:\WINDOWS\TEMP\xawjqrjfi\qldfnbeaffm.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [smlmjydd] C:\WINDOWS\TEMP\xawjqrjfi\qldfnbeaffm.exe (User 'Default user')
O4 - Global Startup: CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = D:\Program Files\CreataCard\Gold\FMRemind.exe
O4 - Global Startup: Kodak EasyShare software.lnk = D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Secunia PSI Tray.lnk = D:\Program Files\Secunia\PSI\psi_tray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk
O9 - Extra 'Tools' menuitem: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\aim.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://download.games.yahoo.com/games/web_…nx.1.0.0.55.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1109450619359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1294543693234
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://www.imgag.com/cp/install/AxCtp2.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://di.imgag.com/imgag/cp/install/Crusher.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://download.games.yahoo.com/games/web_…itched/main.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - file:///C:/Documents%20and%20Settings/Becki/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_…r/goldfever.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://games.myspace.com/gameshell/games/c…sh.1.0.0.47.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Secunia PSI Agent - Secunia - D:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - D:\Program Files\Secunia\PSI\sua.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10166 bytes
Hi fleadhfan, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

We still have some work to do.

Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKUS\S-1-5-18\..\Run: [smlmjydd] C:\WINDOWS\TEMP\xawjqrjfi\qldfnbeaffm.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [smlmjydd] C:\WINDOWS\TEMP\xawjqrjfi\qldfnbeaffm.exe (User 'Default user')


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.

Reboot the computer.

Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode

Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Standard Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL log
No need for a Hijackthis log, OTL will show use more.

Please describe the computer's behavior at the moment.

Thanks
Hi oldman960 - I'm kinda one too (956).

First, thanks for the very prompt response. I too noted the two hjt entries you identified and was 99% sure they were part of the culprits, bu thought it was time to call in the big guns.

Took the actions you prescribed in sequence. Rebooted only after hjt, and not after gmer and otl, since that was not directed.

Computer behavior now seems nominal EXCEPT that the inability to access Microsoft Update remains. Browsing seems normal and quick on all random sites attempted.

For Microsoft Update, behavior is as follows: Launching from Start-All Programs-Windows Update (which has a target of "%SystemRoot%\system32\wupdmgr.exe" and a Start in of "%HOMEDRIVE%%HOMEPATH%") opens IE and calls the url http://windowsupdate.microsoft.com, but results in the message "Internet Explorer cannot display the webpage." Navigating from there to microsoft.com to try drilling down to 'updates' on their site resulted in a redirect to http://pcspeedmaximizer.s3.amazonaws.com/index.html and the pop-up message "Errors have been found in your operating system registry! Click to download free registry cleaner software." X'd the pop-up to close it and got a web page showing typical bs 'registry errors' supposedly on my system. Closed IE.

Doing a clean IE launch I can navigate to microsoft.com and successfully select Support-Microsoft Update, which goes to update.microsoft.com/…, where I selected Start Now, which goes to the license page, then selected Continue, which tried to 'check for the latest version of update', but that quickly resulted in a page stating "the website has encountered a problem and cannot display the page yuo are trying to view, blah, blah, blah…"

Attempting the same with Firefox and going to Microsoft.com gives a connection reset as soon as It try to go to update.microsoft.com.

I'm ready for the next steps. Here are the requested logs:

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-09 09:57:21
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 ST380817AS rev.3.42
Running: pnpzdyo8.exe; Driver: C:\DOCUME~1\Becki\LOCALS~1\Temp\awliikob.sys


—- System - GMER 1.0.15 —-

SSDT F7A7D8B6 ZwCreateKey
SSDT F7A7D8AC ZwCreateThread
SSDT F7A7D8BB ZwDeleteKey
SSDT F7A7D8C5 ZwDeleteValueKey
SSDT F7A7D8CA ZwLoadKey
SSDT F7A7D898 ZwOpenProcess
SSDT F7A7D89D ZwOpenThread
SSDT F7A7D8D4 ZwReplaceKey
SSDT F7A7D8CF ZwRestoreKey
SSDT F7A7D8C0 ZwSetValueKey

—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section

[0xBA41F510]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B5000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B6000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 007B000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B7000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00E1000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00E2000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00BC000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 01BD000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 01BE000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 01BC000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B7000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F

C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[2948] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D1000A
.text C:\WINDOWS\Explorer.EXE[2948] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00D2000A
.text C:\WINDOWS\Explorer.EXE[2948] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00D0000C
.text C:\WINDOWS\System32\svchost.exe[3972] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DE000A
.text C:\WINDOWS\System32\svchost.exe[3972] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DF000A
.text C:\WINDOWS\System32\svchost.exe[3972] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00DD000C
.text C:\WINDOWS\System32\svchost.exe[3972] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 008F000A
.text C:\WINDOWS\System32\svchost.exe[3972] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00E3000A

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System

Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System

Driver/Microsoft Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T1L0-1b 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-13 8A8F8292
Device mrxsmb.sys (Windows NT SMB

Minirdr/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem

Filter Manager/Microsoft Corporation)

Device \Device\Ide\IdeDeviceP2T0L0-5 -> \??\IDE#DiskST380817AS______________________________3.42____#5&22652cbd&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like

behavior; TDL4 <– ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 156301232 (+255): rootkit-like

behavior;

—- EOF - GMER 1.0.15 —-


OTL logfile created on: 1/9/2011 10:04:26 AM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = F:\Cleanup Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 3750 3750 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.42 Gb Total Space | 4.37 Gb Free Space | 17.88% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.41 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive E: | 40.33 Gb Total Space | 32.91 Gb Free Space | 81.60% Space Free | Partition Type: NTFS
Drive F: | 495.22 Mb Total Space | 346.01 Mb Free Space | 69.87% Space Free | Partition Type: FAT

Computer Name: P4P800E-3GHZE | User Name: Becki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/09 09:44:40 | 000,602,112 | —- | M] (OldTimer Tools) – F:\Cleanup Tools\OTL.exe
PRC - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) – D:\Program Files\Secunia\PSI\psia.exe
PRC - [2010/12/21 07:04:30 | 000,399,416 | —- | M] (Secunia) – D:\Program Files\Secunia\PSI\sua.exe
PRC - [2010/12/13 08:40:07 | 000,135,336 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010/12/13 08:39:54 | 000,281,768 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/12/13 08:39:54 | 000,267,944 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/01/14 21:11:00 | 000,076,968 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/01/04 16:38:18 | 000,112,336 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
PRC - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2004/06/12 08:40:42 | 000,594,944 | —- | M] (Alex van Kaam) – D:\Program Files\Motherboard Monitor 5\MBM5.exe
PRC - [2004/02/26 09:52:00 | 000,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2004/02/13 14:12:08 | 000,016,423 | —- | M] () – C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
PRC - [2001/08/23 20:37:39 | 000,167,936 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Hardware\Mouse\point32.exe


========== Modules (SafeList) ==========

MOD - [2011/01/09 09:44:40 | 000,602,112 | —- | M] (OldTimer Tools) – F:\Cleanup Tools\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2004/02/11 16:58:16 | 000,024,613 | —- | M] (BackWeb) – C:\Documents and Settings\Becki\Local Settings\Temp\IadHide5.dll
MOD - [2001/05/09 21:00:28 | 000,045,056 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Hardware\Mouse\Msh_zwf.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\WINDOWS\System32\spoolsv.exe – (Spooler)
SRV - File not found [On_Demand | Stopped] – C:\WINDOWS\System32\appmgmts.dll – (AppMgmt)
SRV - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) [Auto | Running] – D:\Program Files\Secunia\PSI\PSIA.exe – (Secunia PSI Agent)
SRV - [2010/12/21 07:04:30 | 000,399,416 | —- | M] (Secunia) [Auto | Running] – D:\Program Files\Secunia\PSI\sua.exe – (Secunia Update Agent)
SRV - [2010/12/13 08:40:07 | 000,135,336 | —- | M] (Avira GmbH) [Auto | Running] – D:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2010/12/13 08:39:54 | 000,267,944 | —- | M] (Avira GmbH) [Auto | Running] – D:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2010/03/29 07:53:22 | 000,068,000 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper.dll – (getPlusHelper) getPlus®
SRV - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2004/02/26 09:52:00 | 000,049,152 | —- | M] (Ulead Systems, Inc.) [Auto | Running] – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper)


========== Driver Services (SafeList) ==========

DRV - [2010/12/13 08:40:21 | 000,135,096 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2010/12/13 08:40:21 | 000,061,960 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2010/09/01 03:30:58 | 000,015,544 | —- | M] (Secunia) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\psi_mf.sys – (PSI)
DRV - [2010/06/17 14:27:22 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2010/06/17 14:27:12 | 000,011,608 | —- | M] (Avira GmbH) [Kernel | System | Running] – D:\Program Files\Avira\AntiVir Desktop\avgio.sys – (avgio)
DRV - [2008/04/13 13:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2005/12/19 15:02:36 | 000,060,572 | —- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ftser2k.sys – (FTSER2K)
DRV - [2005/12/19 15:02:36 | 000,028,449 | —- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ftdibus.sys – (FTDIBUS)
DRV - [2005/12/11 22:40:43 | 001,414,656 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2004/08/03 22:29:56 | 001,897,408 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2004/04/10 08:42:36 | 000,002,944 | —- | M] ([removed]) [Kernel | System | Running] – C:\WINDOWS\system32\mbmiodrvr.sys – (mbmiodrvr)
DRV - [2004/02/18 03:16:14 | 000,091,177 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\P1131Vid.sys – (P1131VID) Creative WebCam NX Pro (WDM)
DRV - [2004/01/09 10:17:02 | 000,601,100 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2003/12/11 10:54:14 | 000,391,424 | —- | M] (Sensaura Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS)
DRV - [2003/10/23 06:28:00 | 000,174,336 | —- | M] (Marvell Semiconductor Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\yukonwxp.sys – (yukonwxp)
DRV - [2002/09/16 17:14:32 | 000,004,228 | —- | M] (PowerQuest Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\PQNTDRV.sys – (PQNTDrv)
DRV - [2001/08/23 02:33:10 | 000,010,192 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ipfilter.sys – (IPFilter)
DRV - [2001/08/17 09:00:04 | 000,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)
DRV - [1997/04/22 09:16:00 | 000,006,272 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ASLM75.SYS – (aslm75)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {3D28ECD4-DCFF-4863-B1EF-93C84A532140}:1.9.1
FF - prefs.js..extensions.enabledItems: {082AF3DD-1069-4377-B0C1-AEA1EFD7B367}:1.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox
FF - HKLM\software\mozilla\Firefox\Extensions\\{3D28ECD4-DCFF-4863-B1EF-93C84A532140}: C:\Documents and Settings\Becki\Local Settings\Application Data\{3D28ECD4-DCFF-4863-B1EF-93C84A532140} [2010/06/01

11:10:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367}: C:\Documents and Settings\Stephen\Local Settings\Application Data\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367} [2010/06/06

13:46:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/01/08 19:10:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/01/08 19:11:09 | 000,000,000 | —D | M]

[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions
[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions\[removed]
[2011/01/08 22:52:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions
[2009/12/30 09:47:54 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Becki\Application

Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/01 11:28:46 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Becki\Application

Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/05/08 15:13:40 | 000,000,000 | —D | M] (Move Media Player) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
[2009/04/15 10:59:49 | 000,000,000 | —D | M] (Oberon Game Host) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
[2010/06/01 11:10:57 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\BECKI\LOCAL SETTINGS\APPLICATION DATA\{3D28ECD4-DCFF-4863-B1EF-93C84A532140}
[2010/06/06 13:46:09 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\STEPHEN\LOCAL SETTINGS\APPLICATION DATA\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367}
[2009/01/31 11:17:34 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/09 07:34:56 | 000,000,000 | —D | M] (Skype extension for Firefox) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/01/31 11:17:52 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2010/01/12 04:21:51 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/11/30 11:21:02 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

O1 HOSTS File: ([2011/01/08 15:42:46 | 000,001,003 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.8minutedating.com
O1 - Hosts: 127.0.0.1 whysohardx.com
O1 - Hosts: 127.0.0.1 protectyourpc-11.com
O1 - Hosts: 127.0.0.1 checkserverstatux.com
O1 - Hosts: 127.0.0.1 xinmin.cn
O1 - Hosts: 127.0.0.1 xy95.cn
O1 - Hosts: 127.0.0.1 koralda.com
O1 - Hosts: 127.0.0.1 weirden.com
O1 - Hosts: 127.0.0.1 nanocloudcontroller.com
O1 - Hosts: 127.0.0.1 coo0lnet.net
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [ASUS Probe] D:\Program Files\ASUS\Asus Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avgnt] D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [MBM 5] D:\Program Files\Motherboard Monitor 5\MBM5.EXE (Alex van Kaam)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = D:\Program Files\CreataCard\Gold\FMRemind.exe (Micrografx, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = D:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_22.dll (Sun Microsystems, Inc.)
O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - Reg Error: Value error. File not found
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\aim.exe File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://download.games.yahoo.com/games/web_…nx.1.0.0.55.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1109450619359 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1294543693234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab (cpbrkpie Control)
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} http://www.imgag.com/cp/install/AxCtp2.cab (Create & Print ActiveX Plug-in)
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} http://di.imgag.com/imgag/cp/install/Crusher.cab (Creative Toolbox Plug-in)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} file:///C:/Documents%20and%20Settings/Becki/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://download.games.yahoo.com/games/web_…r/goldfever.cab (TikGames Online Control)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} http://games.myspace.com/gameshell/games/c…sh.[removed].cab

(CPlayFirstWeddingDashControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: J:\ireland\ireland 115.jpg
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Becki\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/26 11:03:18 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell - "" = AutoRun
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun\command - "" = K:\MediaManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: fastndll - (C:\WINDOWS\system32\ipxrvr32.dll) - C:\WINDOWS\System32\ipxrvr32.dll File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (68412030092050432)

========== Files/Folders - Created Within 30 Days ==========

[2011/01/08 20:29:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/01/08 20:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Application Data\Avira
[2011/01/08 19:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/01/08 19:22:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/01/08 19:10:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/08 19:09:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/01/08 17:01:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/01/08 17:01:08 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/01/08 17:01:07 | 000,135,096 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/01/08 17:01:07 | 000,061,960 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/01/08 17:01:07 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/01/08 17:01:07 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/01/08 17:01:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2011/01/08 16:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader
[2011/01/08 16:46:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2011/01/08 16:42:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/01/08 15:51:00 | 000,000,000 | —D | C] – C:\WINDOWS\Internet Logs
[2011/01/03 04:16:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\eFdDi06300
[2010/12/26 09:12:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/12/21 04:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Start Menu\Programs\FrostWire
[2010/12/19 13:32:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2010/12/19 13:32:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/12/14 16:42:42 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/12/10 11:35:05 | 000,000,000 | R–D | C] – C:\Documents and Settings\Becki\Start Menu\Programs\Administrative Tools
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At58.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/01/09 10:03:36 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/09 09:43:28 | 033,689,600 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2011/01/09 09:43:26 | 015,939,584 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2011/01/09 09:42:08 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/09 08:35:37 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At57.job
[2011/01/09 08:20:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At47.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At46.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At45.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At72.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At71.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At70.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/01/08 20:26:13 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At69.job
[2011/01/08 19:22:51 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/01/08 19:03:47 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At43.job
[2011/01/08 19:03:47 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2011/01/08 18:50:51 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At65.job
[2011/01/08 17:29:10 | 000,000,637 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:11 | 000,000,166 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:55 | 000,001,094 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:39 | 000,001,138 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:18 | 000,087,228 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2011/01/08 17:05:14 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2011/01/08 17:05:14 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2011/01/08 16:13:04 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2011/01/08 16:13:03 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2011/01/08 15:42:46 | 000,001,003 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/01/08 14:40:21 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At62.job
[2011/01/08 14:11:42 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/01/08 13:57:04 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At61.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/01/08 11:20:26 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At59.job
[2011/01/08 09:12:50 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At64.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At63.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At66.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At60.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/01/07 08:26:15 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At56.job
[2011/01/05 20:16:19 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At44.job
[2011/01/05 20:16:19 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2011/01/05 08:04:30 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At30.job
[2011/01/05 08:04:30 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/01/04 05:43:57 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At26.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At53.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At50.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At29.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At27.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At55.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2011/01/04 02:32:01 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At67.job
[2011/01/03 12:42:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/03 08:47:35 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At32.job
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At31.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/01/03 06:33:38 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At51.job
[2010/12/30 08:49:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At54.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At48.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At28.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At25.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At68.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At52.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At49.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2010/12/30 02:26:21 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/13 10:47:50 | 000,398,744 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/12/13 08:40:21 | 000,135,096 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/12/13 08:40:21 | 000,061,960 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/12/11 11:30:01 | 000,014,739 | —- | M] () – C:\WINDOWS\System32\12543.js
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/08 17:29:10 | 000,000,637 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:08 | 000,000,166 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:54 | 000,001,094 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:37 | 000,001,138 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:17 | 000,087,228 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2011/01/03 05:09:44 | 001,228,854 | —- | C] () – C:\fsqwr.bmp
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/02 08:08:23 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/11/28 14:16:59 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/11/15 13:18:45 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\start
[2010/11/15 13:18:07 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\completescan
[2010/11/15 13:11:32 | 000,000,010 | —- | C] () – C:\Documents and Settings\Becki\Application Data\install
[2008/09/14 13:49:35 | 000,000,110 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2007/10/05 18:07:08 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\drivers\AsProbe.sys
[2006/06/26 16:58:10 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/04/09 21:21:26 | 000,000,209 | —- | C] () – C:\WINDOWS\KA.INI
[2006/03/22 12:42:09 | 000,000,192 | —- | C] () – C:\WINDOWS\elitemediagroup.ini
[2006/03/21 16:11:25 | 000,000,434 | —- | C] () – C:\WINDOWS\rcycu.dll
[2006/01/24 14:52:40 | 000,006,144 | —- | C] () – C:\Documents and Settings\Becki\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/12/26 16:12:24 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/30 21:24:59 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Stephen.ini
[2005/06/19 17:25:05 | 000,000,327 | —- | C] () – C:\WINDOWS\AudStu.INI
[2005/06/19 11:36:16 | 000,000,000 | —- | C] () – C:\WINDOWS\musiceditor.INI
[2005/06/05 14:10:11 | 000,000,327 | —- | C] () – C:\WINDOWS\beatbox.INI
[2005/06/05 14:10:11 | 000,000,317 | —- | C] () – C:\WINDOWS\sampler.INI
[2005/06/05 14:10:11 | 000,000,028 | —- | C] () – C:\WINDOWS\robota.INI
[2005/06/04 17:46:50 | 000,000,237 | —- | C] () – C:\WINDOWS\musicmaker.INI
[2005/06/04 17:39:52 | 000,000,024 | —- | C] () – C:\WINDOWS\magix.ini
[2005/06/04 17:39:51 | 000,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2005/04/25 13:27:00 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2005/04/08 12:33:05 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/03/21 16:33:05 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Becki.ini
[2005/03/19 15:10:08 | 000,000,244 | —- | C] () – C:\WINDOWS\qwimp.ini
[2005/03/19 15:08:06 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/03/19 14:48:59 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/03/06 13:02:00 | 000,374,784 | —- | C] () – C:\WINDOWS\3dg32.dll
[2005/03/06 13:02:00 | 000,000,250 | —- | C] () – C:\WINDOWS\3dr.ini
[2005/03/04 12:36:50 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/02/27 17:18:15 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2005/02/27 17:18:15 | 000,302,592 | —- | C] () – C:\WINDOWS\System32\pgp.dll
[2005/02/27 17:18:15 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2005/02/27 17:18:15 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\keydb.dll
[2005/02/27 17:18:15 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\simple.dll
[2005/02/27 17:18:15 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\bn.dll
[2005/02/27 15:12:31 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2005/02/27 15:12:31 | 000,006,138 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2005/02/26 13:24:32 | 000,000,227 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2005/02/26 11:37:30 | 000,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2005/02/26 11:23:35 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/02/26 11:17:50 | 000,003,630 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2005/02/26 05:48:23 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll

========== LOP Check ==========

[2009/11/03 12:25:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\110
[2009/10/30 10:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\122DE
[2009/04/06 00:52:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1230
[2009/03/05 21:19:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\123E
[2009/11/09 12:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\13280
[2009/04/01 18:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\132FD
[2010/01/29 20:49:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\147D
[2009/11/02 09:12:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\16399
[2009/07/17 18:50:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1D3E
[2009/04/13 09:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1F119
[2009/03/30 15:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\22119
[2009/11/07 13:39:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\241C5
[2009/05/17 16:56:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2D399
[2009/10/30 07:33:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\33399
[2009/07/19 14:53:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\3437A
[2009/02/25 09:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/03/23 09:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\E119
[2011/01/08 21:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eFdDi06300
[2010/01/22 13:43:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/05/24 10:57:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/11/05 21:34:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005/04/06 10:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/10/22 11:33:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2005/02/27 16:26:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/11/18 12:13:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/03/09 17:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Total 3D Home
[2005/03/04 12:58:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/03/27 19:49:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/05/03 17:10:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2011/01/08 16:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2005/03/26 11:13:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Aim
[2010/12/31 03:17:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\FrostWire
[2007/10/05 18:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Grisoft
[2010/11/14 12:00:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\LimeWire
[2007/02/10 23:22:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\OurPictures
[2009/11/05 21:34:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\PlayFirst
[2008/10/22 11:32:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Sandlot Games
[2006/06/09 10:58:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Snapfish
[2005/05/04 11:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\spweng
[2005/04/28 17:40:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Ulead Systems
[2007/06/20 12:29:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Viewpoint
[2010/12/30 02:26:21 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2011/01/08 16:13:03 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2011/01/08 17:05:14 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2011/01/05 08:04:30 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/01/05 20:16:19 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2011/01/08 19:03:47 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At25.job
[2011/01/04 05:43:57 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At26.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At27.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At28.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At29.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/01/05 08:04:30 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At30.job
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At31.job
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At32.job
[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At33.job
[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At34.job
[2011/01/08 11:20:26 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At35.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At36.job
[2011/01/08 13:57:04 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At37.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At38.job
[2011/01/08 16:13:04 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At39.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At40.job
[2011/01/08 17:05:14 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At41.job
[2011/01/08 09:12:50 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At42.job
[2011/01/08 19:03:47 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At43.job
[2011/01/05 20:16:19 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At44.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At45.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At46.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At47.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At48.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At49.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At50.job
[2011/01/03 06:33:38 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At51.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At52.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At53.job
[2010/12/30 08:49:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At54.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At55.job
[2011/01/07 08:26:15 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At56.job
[2011/01/09 08:35:37 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At57.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At58.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At59.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At60.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At61.job
[2011/01/08 14:40:21 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At62.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At63.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At64.job
[2011/01/08 18:50:51 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At65.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At66.job
[2011/01/04 02:32:01 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At67.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At68.job
[2011/01/08 20:26:13 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At69.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At70.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At71.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At72.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At9.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/02/26 11:03:18 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/01/08 14:11:42 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2005/02/26 11:03:18 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/02/27 16:03:16 | 000,000,227 | —- | M] () – C:\CtDrvIns.log
[2005/02/27 16:03:16 | 000,013,340 | —- | M] () – C:\CtDrvStp.log
[2005/11/27 22:15:22 | 000,057,868 | —- | M] () – C:\EasyShare.dmp
[2006/01/28 14:26:31 | 000,809,853 | —- | M] () – C:\EasyShareInstall.log
[2011/01/03 08:47:35 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2005/02/26 11:03:18 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/03/27 19:49:52 | 000,000,732 | -H– | M] () – C:\IPH.PH
[2005/06/19 17:25:20 | 000,000,746 | -HS- | M] () – C:\midi studio 2005.Key
[2005/02/26 11:03:18 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/25 08:37:31 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/09 08:19:54 | 3932,160,000 | -HS- | M] () – C:\pagefile.sys
[2008/11/22 15:26:37 | 000,064,762 | —- | M] () – C:\playground.log
[2011/01/08 14:54:19 | 000,000,359 | —- | M] () – C:\rkill.log
[2011/01/08 12:16:14 | 000,001,257 | —- | M] () – C:\sti.log
[2009/03/29 15:19:08 | 000,000,032 | —- | M] () – C:\wizard.txt
[2005/11/29 15:03:44 | 000,000,000 | —- | M] () – C:\wptUpgrader.log
[2009/02/21 16:01:09 | 000,000,146 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/02/26 11:02:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2004/05/18 16:26:04 | 000,000,208 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo! Mail.url
[2004/05/18 16:13:06 | 000,000,207 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo!.url

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/02/26 05:46:29 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/02/26 05:46:29 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/02/26 05:46:29 | 000,888,832 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2006/09/13 13:34:37 | 000,000,154 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Create & Print Home.url
[2008/09/25 08:45:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2008/09/25 08:45:37 | 000,001,568 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2005/02/26 11:03:24 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2005/02/26 15:36:22 | 000,001,512 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-10 08:31:28

========== Alternate Data Streams ==========

@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEB25EAE
@Alternate Data Stream - 202 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24FECE50
@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61AF2B29
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FE30AB2

< End of report >


OTL Extras logfile created on: 1/9/2011 10:04:26 AM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = F:\Cleanup Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 3750 3750 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.42 Gb Total Space | 4.37 Gb Free Space | 17.88% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.41 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive E: | 40.33 Gb Total Space | 32.91 Gb Free Space | 81.60% Space Free | Partition Type: NTFS
Drive F: | 495.22 Mb Total Space | 346.01 Mb Free Space | 69.87% Space Free | Partition Type: FAT

Computer Name: P4P800E-3GHZE | User Name: Becki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "D:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "D:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"G:\Program Files\aim.exe" = G:\Program Files\aim.exe:*:Enabled:AOL Instant Messenger – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software

Updater – ()
"D:\Program Files\Yahoo!\Messenger\YPager.exe" = D:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger – File not found
"D:\Program Files\Yahoo!\Messenger\YServer.exe" = D:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"G:\Program Files\aim.exe" = G:\Program Files\aim.exe:*:Enabled:AOL Instant Messenger – File not found
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – File not found
"D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe" = D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – ()
"D:\Program Files\Skype\Phone\Skype.exe" = D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – File not found
"D:\RECYCLER\NPROTECT\00006551.exe" = D:\RECYCLER\NPROTECT\00006551.exe:*:Enabled:Skype – File not found
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe – File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – File not found
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"G:\Program Files\LimeWire\LimeWire.exe" = G:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"G:\Program Files\FrostWire\FrostWire.exe" = G:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – File not found
"D:\Program Files\FrostWire\FrostWire.exe" = D:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (FrostWire Group)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{01BDFB08-EE88-4E5E-94A6-AE9EDCFA40C5}" = Microsoft IntelliPoint 4.0
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03B48041-B2CD-476A-87D6-79D0488559A2}" = Desktop Restore
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2405FEDD-9E40-4438-9765-A37A2B389E1A}" = Shoppers' Hotline Control Center
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 22
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B0F52AC-EF5C-4831-B221-06C782E41280}" = Quicken 2008
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4F1DA6BF-3614-48A1-9970-9E90F646789E}" = Ulead VideoStudio 8.0
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{55937F00-A69B-4049-8D3A-1C7729742B6F}" = BUM
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5B18F34B-9620-4702-A051-49832F9860AB}" = Total 3D Home
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{76703039-C98C-4e62-A12C-4D7066BE9985}" = The Sims™ 2 University Life Collection
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9C244239-ED8E-40f1-937F-51C706CD2160}" = The Sims™ 2 Deluxe
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A59BB15D-51B7-F12B-4548-8C0368243441}" = EA Download Manager UI
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1973749-F5E7-40EB-B528-F2B78685B9FF}" = essvcpt
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D39A2674-F79F-410A-00A0-B19F6EA1D054}" = The Sims Carnival BumperBlast
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DF0B1D6F-DEC5-4831-00B7-FC2ACB464C31}" = The Sims Carnival SnapCity
"{DFE94B9F-0AFA-4A97-9F5B-DF2A2608238B}" = Shoppers' Hotline Control Center
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Celebration! Stuff
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_6" = AIM 6
"AOL Instant Messenger" = AOL Instant Messenger
"ASUS Probe V2.23.04" = ASUS Probe V2.23.04
"ASUS Probe V2.25.02" = ASUS Probe V2.25.02
"AsusUpdate" = AsusUpdate
"ATI Display Driver" = ATI Display Driver
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"BFGC" = Big Fish Games Client
"BFG-Dream Chronicles" = Dream Chronicles
"BFG-Dream Chronicles - The Chosen Child" = Dream Chronicles: The Chosen Child
"BFG-Dream Chronicles 2 - The Eternal Maze" = Dream Chronicles ™ 2: The Eternal Maze
"BFG-Strange Cases - The Tarot Card Mystery" = Strange Cases: The Tarot Card Mystery
"CCleaner" = CCleaner
"CDex" = CDex extraction audio
"CEP - Colour Enable Packages_is1" = CEP (Color Enable Package) v.9.0 (beta)
"Click'N Design 3D" = Click'N Design 3D
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"CreataCard Gold 3" = CreataCard Gold 3
"Creative PC-CAM Center" = Creative PC-CAM Center
"Creative PD1131" = Creative WebCam NX Pro Driver (1.02.03.0218)
"Creative WebCam Monitor" = Creative WebCam Monitor
"Creative WebCam NX Pro User's Guide English" = Creative WebCam NX Pro User's Guide (English)
"EA Download Manager" = EA Download Manager
"Foxit Reader" = Foxit Reader
"FrostWire" = FrostWire 4.21.3
"FTDICOMM" = FTDI USB Serial Converter Drivers
"hp deskjet 940c series" = hp deskjet 940c series (Remove only)
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"JumpStart Artist" = JumpStart Artist
"KeePass Password Safe_is1" = KeePass Password Safe 0.98b
"LimeWire" = LimeWire 5.5.16
"MAGIX Media Manager silver" = MAGIX Media Manager silver
"MAGIX music maker 2005 deLuxe" = MAGIX music maker 2005 deLuxe
"MAGIX music studio 2005 deLuxe" = MAGIX music studio 2005 deLuxe
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Memorex 6142 USB" = Memorex 6142 USB
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Motherboard Monitor 5_is1" = Motherboard Monitor 5
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"My Photo Adventure" = My Photo Adventure
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"Publix Preschool Pals" = Publix Preschool Pals
"RealAlt_is1" = Real Alternative 1.43
"RocketLife" = RocketLife
"Secunia PSI" = Secunia PSI (2.0.0.1003)
"Shareaza" = Shareaza
"The Cat in the Hat" = The Cat in the Hat
"Tweak UI 2.10" = Tweak UI
"UltimateBet" = UltimateBet
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Virtools3DLifePlayer" = Virtools 3D Life Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/8/2011 5:04:31 PM | Computer Name = P4P800E-3GHZE | Source = Application Hang | ID = 1002
Description = Hanging application Kodak Software Updater.exe, version 0.0.0.0, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/8/2011 5:06:26 PM | Computer Name = P4P800E-3GHZE | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/8/2011 6:04:41 PM | Computer Name = P4P800E-3GHZE | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.

Error - 1/8/2011 6:19:02 PM | Computer Name = P4P800E-3GHZE | Source = MsiInstaller | ID = 11905
Description = Product: Ask Toolbar – Error 1905.Module C:\Program Files\Ask.com\GenericAskToolbar.dll
failed to unregister. HRESULT -2147220472. Contact your support personnel.

Error - 1/8/2011 8:04:24 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 1/8/2011 8:04:25 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 1/8/2011 8:04:40 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 1/8/2011 8:04:40 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 1/8/2011 8:04:40 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 1/9/2011 9:35:28 AM | Computer Name = P4P800E-3GHZE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

[ System Events ]
Error - 1/8/2011 9:15:44 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/8/2011 9:16:44 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 1/8/2011 9:17:14 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/8/2011 9:18:14 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/8/2011 9:19:14 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/8/2011 9:20:15 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/8/2011 9:20:45 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/8/2011 9:27:46 PM | Computer Name = P4P800E-3GHZE | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2

Error - 1/9/2011 9:13:26 AM | Computer Name = P4P800E-3GHZE | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2

Error - 1/9/2011 9:20:35 AM | Computer Name = P4P800E-3GHZE | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2


< End of report >
Hi fleadhfan,

FrostWire and Limewire
You have FrostWire and Limewire, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing them.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall FrostWire and Limewire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep them please do not use them until your computer is cleaned.

First

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP),
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\RunOnceEx: [] File not found
O36 - AppCertDlls: fastndll - (C:\WINDOWS\system32\ipxrvr32.dll) - C:\WINDOWS\System32\ipxrvr32.dll File not found
[2010/12/11 11:30:01 | 000,014,739 | —- | M] () – C:\WINDOWS\System32\12543.js
[2008/05/24 10:57:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/10/05 18:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Grisoft
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox

:Files
C:\WINDOWS\tasks\At*.job
ipconfig /flushdns /c
C:\fsqwr.bmp
C:\WINDOWS\TEMP\xawjqrjfi\qldfnbeaffm.exe

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Next

Please read carefully and follow these steps.


Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following

    C:\Documents and Settings\All Users\Application Data\122DE\*.* /s
    C:\Documents and Settings\All Users\Application Data\1F119\*.* /s
    C:\Documents and Settings\All Users\Application Data\eFdDi06300\*.* /s
    /md5start
    spoolsv.*
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows, OTL.Txt, no Extras.Txt this time.

Please post back with
  • GooredFix log
  • OTL fix log
  • TDSKiller log
  • new OTL log
How's the computer?

Thanks
A quick clarification, please. For the first OTL run, are the LOP and Purity boxes to be checked or unchecked, and should output be set to minimal or standard? Thanks.
Hi fleadhfan, The first OTL run is a fix. There is no need to check any of the boxes as the tool doesn't use them during a fix. Just follow the instructions as posted. :)
First, I couldn't agree with you more about LimeWire and FrostWire. I've warned them in the past about the use of such programs, but now I'll insist that they not be used - since I'm their support and have to deal with the fallout.

Second, and the really good news, is that Microsoft Update is now accessible. I didn't have it look for and install needed updates yet pending our finishing the cleanup work, but I got past the point i could get to before, and to the page with the 'check for updates' button. Checked Windows Security Center, and it correctly reports Avira as being installed and running, and Windows Firewall on (to be replaced by Comodo after you tell me we're finished). Hadn't checked that before, but remembered a recent fix I did for someone else where it caused Windows Security Center to erroneously report what was installed and working, so figured I'd have a look. Everything else seems operationally normal as well.

Here are the latest logs in the requested order:

GooredFix by jpshortstuff (03.07.10.1)
Log created at 18:13 on 09/01/2011 (Becki)
Firefox version 3.6.13 (en-US)

========== GooredScan ==========

Removing Orphan:
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox" -> Success!
Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{3D28ECD4-DCFF-4863-B1EF-93C84A532140} -> Success!
Deleting C:\Documents and Settings\Becki\Local Settings\Application Data\{3D28ECD4-DCFF-4863-B1EF-93C84A532140} -> Success!
Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367} -> Success!
Deleting C:\Documents and Settings\Stephen\Local Settings\Application Data\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367} -> Success!

========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
(none)

C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\
[removed] [20:13 08/05/2008]
[removed] [15:59 15/04/2009]
{20a82645-c095-46ed-80e3-08825760534b} [14:47 30/12/2009]
{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [16:28 01/06/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [16:09 29/12/2009]
"[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [16:17 31/01/2009]

-=E.O.F=-


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\\fastndll:C:\WINDOWS\system32\ipxrvr32.dll deleted successfully.
C:\WINDOWS\system32\12543.js moved successfully.
C:\Documents and Settings\All Users\Application Data\Grisoft\AVG Anti-Spyware 7.5\Downloads folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Grisoft\AVG Anti-Spyware 7.5 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Grisoft folder moved successfully.
C:\Documents and Settings\Becki\Application Data\Grisoft\AVG Antispyware 7.5\Reports folder moved successfully.
C:\Documents and Settings\Becki\Application Data\Grisoft\AVG Antispyware 7.5\quarantine folder moved successfully.
C:\Documents and Settings\Becki\Application Data\Grisoft\AVG Antispyware 7.5 folder moved successfully.
C:\Documents and Settings\Becki\Application Data\Grisoft folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f963a5b-e555-4543-90e2-c3908898db71}\ not found.
File C:\Program Files\AVG\AVG8\Firefox not found.
========== FILES ==========
C:\WINDOWS\tasks\At1.job moved successfully.
C:\WINDOWS\tasks\At10.job moved successfully.
C:\WINDOWS\tasks\At11.job moved successfully.
C:\WINDOWS\tasks\At12.job moved successfully.
C:\WINDOWS\tasks\At13.job moved successfully.
C:\WINDOWS\tasks\At14.job moved successfully.
C:\WINDOWS\tasks\At15.job moved successfully.
C:\WINDOWS\tasks\At16.job moved successfully.
C:\WINDOWS\tasks\At17.job moved successfully.
C:\WINDOWS\tasks\At18.job moved successfully.
C:\WINDOWS\tasks\At19.job moved successfully.
C:\WINDOWS\tasks\At2.job moved successfully.
C:\WINDOWS\tasks\At20.job moved successfully.
C:\WINDOWS\tasks\At21.job moved successfully.
C:\WINDOWS\tasks\At22.job moved successfully.
C:\WINDOWS\tasks\At23.job moved successfully.
C:\WINDOWS\tasks\At24.job moved successfully.
C:\WINDOWS\tasks\At25.job moved successfully.
C:\WINDOWS\tasks\At26.job moved successfully.
C:\WINDOWS\tasks\At27.job moved successfully.
C:\WINDOWS\tasks\At28.job moved successfully.
C:\WINDOWS\tasks\At29.job moved successfully.
C:\WINDOWS\tasks\At3.job moved successfully.
C:\WINDOWS\tasks\At30.job moved successfully.
C:\WINDOWS\tasks\At31.job moved successfully.
C:\WINDOWS\tasks\At32.job moved successfully.
C:\WINDOWS\tasks\At33.job moved successfully.
C:\WINDOWS\tasks\At34.job moved successfully.
C:\WINDOWS\tasks\At35.job moved successfully.
C:\WINDOWS\tasks\At36.job moved successfully.
C:\WINDOWS\tasks\At37.job moved successfully.
C:\WINDOWS\tasks\At38.job moved successfully.
C:\WINDOWS\tasks\At39.job moved successfully.
C:\WINDOWS\tasks\At4.job moved successfully.
C:\WINDOWS\tasks\At40.job moved successfully.
C:\WINDOWS\tasks\At41.job moved successfully.
C:\WINDOWS\tasks\At42.job moved successfully.
C:\WINDOWS\tasks\At43.job moved successfully.
C:\WINDOWS\tasks\At44.job moved successfully.
C:\WINDOWS\tasks\At45.job moved successfully.
C:\WINDOWS\tasks\At46.job moved successfully.
C:\WINDOWS\tasks\At47.job moved successfully.
C:\WINDOWS\tasks\At48.job moved successfully.
C:\WINDOWS\tasks\At49.job moved successfully.
C:\WINDOWS\tasks\At5.job moved successfully.
C:\WINDOWS\tasks\At50.job moved successfully.
C:\WINDOWS\tasks\At51.job moved successfully.
C:\WINDOWS\tasks\At52.job moved successfully.
C:\WINDOWS\tasks\At53.job moved successfully.
C:\WINDOWS\tasks\At54.job moved successfully.
C:\WINDOWS\tasks\At55.job moved successfully.
C:\WINDOWS\tasks\At56.job moved successfully.
C:\WINDOWS\tasks\At57.job moved successfully.
C:\WINDOWS\tasks\At58.job moved successfully.
C:\WINDOWS\tasks\At59.job moved successfully.
C:\WINDOWS\tasks\At6.job moved successfully.
C:\WINDOWS\tasks\At60.job moved successfully.
C:\WINDOWS\tasks\At61.job moved successfully.
C:\WINDOWS\tasks\At62.job moved successfully.
C:\WINDOWS\tasks\At63.job moved successfully.
C:\WINDOWS\tasks\At64.job moved successfully.
C:\WINDOWS\tasks\At65.job moved successfully.
C:\WINDOWS\tasks\At66.job moved successfully.
C:\WINDOWS\tasks\At67.job moved successfully.
C:\WINDOWS\tasks\At68.job moved successfully.
C:\WINDOWS\tasks\At69.job moved successfully.
C:\WINDOWS\tasks\At7.job moved successfully.
C:\WINDOWS\tasks\At70.job moved successfully.
C:\WINDOWS\tasks\At71.job moved successfully.
C:\WINDOWS\tasks\At72.job moved successfully.
C:\WINDOWS\tasks\At8.job moved successfully.
C:\WINDOWS\tasks\At9.job moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
F:\Cleanup Tools\cmd.bat deleted successfully.
F:\Cleanup Tools\cmd.txt deleted successfully.
C:\fsqwr.bmp moved successfully.
File\Folder C:\WINDOWS\TEMP\xawjqrjfi\qldfnbeaffm.exe not found.
========== COMMANDS ==========
Unable to start service SrService!

[EMPTYTEMP]

User: All Users

User: Becki
->Temp folder emptied: 1539823784 bytes
->Temporary Internet Files folder emptied: 17144081 bytes
->Java cache emptied: 206024893 bytes
->FireFox cache emptied: 37549452 bytes
->Flash cache emptied: 5291 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 232091227 bytes
->Java cache emptied: 1113175 bytes
->Flash cache emptied: 105899 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 195363625 bytes
->Java cache emptied: 2187456 bytes
->Flash cache emptied: 136414 bytes

User: Stephen
->Temp folder emptied: 2050875395 bytes
->Temporary Internet Files folder emptied: 6198860 bytes
->Java cache emptied: 51217277 bytes
->FireFox cache emptied: 42348452 bytes
->Flash cache emptied: 43204 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2162283 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 184639983 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 91138808 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 485998 bytes
RecycleBin emptied: 854 bytes

Total Files Cleaned = 4,445.00 mb


OTL by OldTimer - Version 3.2.20.1 log created on 01092011_182741

Files\Folders moved on Reboot…
C:\Documents and Settings\Becki\Local Settings\Temporary Internet Files\Content.IE5\RNO9D406\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\Becki\Local Settings\Temporary Internet Files\Content.IE5\OVSP3UDW\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z22YUB4Q\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z22YUB4Q\guide_opendns_com[2].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GUXQQ88R\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\53ZTSXQO\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3SBV55F0\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3SBV55F0\guide_opendns_com[2].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3SBV55F0\guide_opendns_com[3].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\38HKOAF6\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1KRHQVKL\guide_opendns_com[1].txt moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1KRHQVKL\guide_opendns_com[2].txt moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\QAORQUZT\guide_opendns_com[2].txt moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\SURMKNH8\main[3].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OACGKF0N\main[1].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OACGKF0N\main[2].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OACGKF0N\main[3].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OACGKF0N\main[4].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JZPG60YG\main[3].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JZPG60YG\main[4].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JZPG60YG\main[5].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JZPG60YG\main[6].htm moved successfully.
C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3XXPJ0AN\main[1].htm moved successfully.

Registry entries deleted on Reboot…


2011/01/09 18:44:40.0531 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
2011/01/09 18:44:40.0531 ================================================================================
2011/01/09 18:44:40.0531 SystemInfo:
2011/01/09 18:44:40.0531
2011/01/09 18:44:40.0531 OS Version: 5.1.2600 ServicePack: 3.0
2011/01/09 18:44:40.0531 Product type: Workstation
2011/01/09 18:44:40.0531 ComputerName: P4P800E-3GHZE
2011/01/09 18:44:40.0546 UserName: Becki
2011/01/09 18:44:40.0546 Windows directory: C:\WINDOWS
2011/01/09 18:44:40.0546 System windows directory: C:\WINDOWS
2011/01/09 18:44:40.0546 Processor architecture: Intel x86
2011/01/09 18:44:40.0546 Number of processors: 2
2011/01/09 18:44:40.0546 Page size: 0x1000
2011/01/09 18:44:40.0546 Boot type: Normal boot
2011/01/09 18:44:40.0546 ================================================================================
2011/01/09 18:44:40.0781 Initialize success
2011/01/09 18:44:52.0921 ================================================================================
2011/01/09 18:44:52.0921 Scan started
2011/01/09 18:44:52.0921 Mode: Manual;
2011/01/09 18:44:52.0921 ================================================================================
2011/01/09 18:44:53.0421 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/01/09 18:44:53.0453 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/01/09 18:44:53.0515 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/01/09 18:44:53.0578 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/01/09 18:44:53.0625 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/01/09 18:44:53.0734 ALCXSENS (fbbcb95f677cbaa924140b6ea2d9a97b) C:\WINDOWS\system32\drivers\ALCXSENS.SYS
2011/01/09 18:44:53.0812 ALCXWDM (bc5c55b49c4bd1fdfaaa128fe21f9fea) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2011/01/09 18:44:53.0906 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/01/09 18:44:54.0000 aslm75 (71356a1370739e25375a1d17b6ae318f) C:\WINDOWS\system32\drivers\aslm75.sys
2011/01/09 18:44:54.0031 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/01/09 18:44:54.0078 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/01/09 18:44:54.0187 ati2mtag (956c7ec3a9de96f785b829beb41e3c3e) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2011/01/09 18:44:54.0234 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/01/09 18:44:54.0281 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/01/09 18:44:54.0437 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) D:\Program Files\Avira\AntiVir Desktop\avgio.sys
2011/01/09 18:44:54.0515 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
2011/01/09 18:44:54.0546 avipbb (da39805e2bad99d37fce9477dd94e7f2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/01/09 18:44:54.0578 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/01/09 18:44:54.0609 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/01/09 18:44:54.0656 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/01/09 18:44:54.0687 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/01/09 18:44:54.0718 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/01/09 18:44:54.0750 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/01/09 18:44:54.0921 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/01/09 18:44:54.0968 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/01/09 18:44:55.0031 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/01/09 18:44:55.0062 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/01/09 18:44:55.0109 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/01/09 18:44:55.0187 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/01/09 18:44:55.0281 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/01/09 18:44:55.0312 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/01/09 18:44:55.0359 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/01/09 18:44:55.0375 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/01/09 18:44:55.0421 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/01/09 18:44:55.0468 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/01/09 18:44:55.0500 FTDIBUS (782f67cfc6c362257916bbb50bc55de9) C:\WINDOWS\system32\drivers\ftdibus.sys
2011/01/09 18:44:55.0515 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/01/09 18:44:55.0562 FTSER2K (4a995111f44cd6f35775865903f4f41e) C:\WINDOWS\system32\drivers\ftser2k.sys
2011/01/09 18:44:55.0593 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
2011/01/09 18:44:55.0640 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/01/09 18:44:55.0671 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/01/09 18:44:55.0750 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/01/09 18:44:55.0812 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/01/09 18:44:55.0859 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/01/09 18:44:55.0921 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/01/09 18:44:55.0968 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/01/09 18:44:56.0000 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/01/09 18:44:56.0031 IPFilter (d0b3dee109af605885c46a59bfc24cd2) C:\WINDOWS\system32\DRIVERS\IPFilter.sys
2011/01/09 18:44:56.0062 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/01/09 18:44:56.0093 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/01/09 18:44:56.0140 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/01/09 18:44:56.0171 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/01/09 18:44:56.0203 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/01/09 18:44:56.0234 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/01/09 18:44:56.0281 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/01/09 18:44:56.0312 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/01/09 18:44:56.0375 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/01/09 18:44:56.0453 mbmiodrvr (290fb01f7f51eff0960599404a09f8d6) C:\WINDOWS\system32\mbmiodrvr.sys
2011/01/09 18:44:56.0484 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/01/09 18:44:56.0531 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/01/09 18:44:56.0562 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/01/09 18:44:56.0625 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/01/09 18:44:56.0671 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/01/09 18:44:56.0718 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/01/09 18:44:56.0781 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/01/09 18:44:56.0843 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/01/09 18:44:56.0890 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/01/09 18:44:56.0906 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/01/09 18:44:56.0937 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/01/09 18:44:56.0984 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/01/09 18:44:57.0015 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/01/09 18:44:57.0046 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
2011/01/09 18:44:57.0078 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/01/09 18:44:57.0140 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/01/09 18:44:57.0156 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/01/09 18:44:57.0218 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/01/09 18:44:57.0234 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/01/09 18:44:57.0265 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/01/09 18:44:57.0312 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/01/09 18:44:57.0343 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/01/09 18:44:57.0390 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/01/09 18:44:57.0421 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/01/09 18:44:57.0500 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/01/09 18:44:57.0546 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/01/09 18:44:57.0593 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/01/09 18:44:57.0671 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
2011/01/09 18:44:57.0703 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/01/09 18:44:57.0781 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/01/09 18:44:57.0921 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/01/09 18:44:57.0937 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/01/09 18:44:57.0984 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/01/09 18:44:58.0015 P1131VID (b95ed663febab84752b5738b27393f7c) C:\WINDOWS\system32\DRIVERS\P1131Vid.sys
2011/01/09 18:44:58.0062 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/01/09 18:44:58.0093 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/01/09 18:44:58.0125 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/01/09 18:44:58.0171 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/01/09 18:44:58.0234 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/01/09 18:44:58.0265 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/01/09 18:44:58.0421 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/01/09 18:44:58.0453 PQNTDrv (4228630829c0e521c43d882a00533374) C:\WINDOWS\system32\drivers\PQNTDrv.sys
2011/01/09 18:44:58.0484 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/01/09 18:44:58.0531 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\WINDOWS\system32\DRIVERS\psi_mf.sys
2011/01/09 18:44:58.0562 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/01/09 18:44:58.0593 PxHelp20 (0c8da0a8b0d227319c285e0eae65defd) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
2011/01/09 18:44:58.0718 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/01/09 18:44:58.0765 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/01/09 18:44:58.0796 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/01/09 18:44:58.0828 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/01/09 18:44:58.0859 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/01/09 18:44:58.0890 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/01/09 18:44:58.0937 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/01/09 18:44:58.0984 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/01/09 18:44:59.0046 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/01/09 18:44:59.0109 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/01/09 18:44:59.0140 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/01/09 18:44:59.0187 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/01/09 18:44:59.0250 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/01/09 18:44:59.0296 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/01/09 18:44:59.0359 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/01/09 18:44:59.0406 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/01/09 18:44:59.0468 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/01/09 18:44:59.0500 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/01/09 18:44:59.0531 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/01/09 18:44:59.0578 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/01/09 18:44:59.0687 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/01/09 18:44:59.0750 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/01/09 18:44:59.0812 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/01/09 18:44:59.0843 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/01/09 18:44:59.0890 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/01/09 18:44:59.0953 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/01/09 18:45:00.0031 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/01/09 18:45:00.0093 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/01/09 18:45:00.0140 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/01/09 18:45:00.0187 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/01/09 18:45:00.0203 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/01/09 18:45:00.0234 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/01/09 18:45:00.0265 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/01/09 18:45:00.0343 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/01/09 18:45:00.0390 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/01/09 18:45:00.0437 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
2011/01/09 18:45:00.0500 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/01/09 18:45:00.0593 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/01/09 18:45:00.0640 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/01/09 18:45:00.0703 yukonwxp (4fd408e42b3e516732e607bed06f39fb) C:\WINDOWS\system32\DRIVERS\yukonwxp.sys
2011/01/09 18:45:00.0734 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/01/09 18:45:00.0843 ================================================================================
2011/01/09 18:45:00.0843 Scan finished
2011/01/09 18:45:00.0843 ================================================================================
2011/01/09 18:45:00.0859 Detected object count: 1
2011/01/09 18:45:48.0156 \HardDisk0 - will be cured after reboot
2011/01/09 18:45:48.0156 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2011/01/09 18:46:35.0546 Deinitialize success


OTL logfile created on: 1/9/2011 6:52:25 PM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = F:\Cleanup Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 95.00% Paging File free
Paging file location(s): C:\pagefile.sys 3750 3750 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.42 Gb Total Space | 8.84 Gb Free Space | 36.20% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.44 Gb Free Space | 55.65% Space Free | Partition Type: NTFS
Drive E: | 40.33 Gb Total Space | 32.91 Gb Free Space | 81.61% Space Free | Partition Type: NTFS
Drive F: | 495.22 Mb Total Space | 341.90 Mb Free Space | 69.04% Space Free | Partition Type: FAT

Computer Name: P4P800E-3GHZE | User Name: Becki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - F:\Cleanup Tools\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Secunia\PSI\psia.exe (Secunia)
PRC - D:\Program Files\Secunia\PSI\sua.exe (Secunia)
PRC - D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - D:\Program Files\Motherboard Monitor 5\MBM5.exe (Alex van Kaam)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
PRC - C:\Program Files\Microsoft Hardware\Mouse\point32.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - F:\Cleanup Tools\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\Becki\Local Settings\Temp\IadHide5.dll (BackWeb)
MOD - C:\Program Files\Microsoft Hardware\Mouse\Msh_zwf.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Spooler) – C:\WINDOWS\System32\spoolsv.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Secunia PSI Agent) – D:\Program Files\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) – D:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (AntiVirSchedulerService) – D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – D:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (mbmiodrvr) – C:\WINDOWS\system32\mbmiodrvr.sys ([removed])
DRV - (P1131VID) Creative WebCam NX Pro (WDM) – C:\WINDOWS\system32\drivers\P1131Vid.sys (Creative Technology Ltd.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yukonwxp.sys (Marvell Semiconductor Inc.)
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (IPFilter) – C:\WINDOWS\system32\drivers\ipfilter.sys (Microsoft Corporation)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (aslm75) – C:\WINDOWS\system32\drivers\ASLM75.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {3D28ECD4-DCFF-4863-B1EF-93C84A532140}:1.9.1
FF - prefs.js..extensions.enabledItems: {082AF3DD-1069-4377-B0C1-AEA1EFD7B367}:1.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/01/08 19:10:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/01/08 19:11:09 | 000,000,000 | —D | M]

[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions
[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions\[removed]
[2011/01/08 22:52:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions
[2009/12/30 09:47:54 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/01 11:28:46 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/05/08 15:13:40 | 000,000,000 | —D | M] (Move Media Player) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
[2009/04/15 10:59:49 | 000,000,000 | —D | M] (Oberon Game Host) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BECKI\LOCAL SETTINGS\APPLICATION DATA\{3D28ECD4-DCFF-4863-B1EF-93C84A532140}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\STEPHEN\LOCAL SETTINGS\APPLICATION DATA\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367}
[2009/01/31 11:17:34 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/09 07:34:56 | 000,000,000 | —D | M] (Skype extension for Firefox) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/01/31 11:17:52 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2010/01/12 04:21:51 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/11/30 11:21:02 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

O1 HOSTS File: ([2011/01/08 15:42:46 | 000,001,003 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.8minutedating.com
O1 - Hosts: 127.0.0.1 whysohardx.com
O1 - Hosts: 127.0.0.1 protectyourpc-11.com
O1 - Hosts: 127.0.0.1 checkserverstatux.com
O1 - Hosts: 127.0.0.1 xinmin.cn
O1 - Hosts: 127.0.0.1 xy95.cn
O1 - Hosts: 127.0.0.1 koralda.com
O1 - Hosts: 127.0.0.1 weirden.com
O1 - Hosts: 127.0.0.1 nanocloudcontroller.com
O1 - Hosts: 127.0.0.1 coo0lnet.net
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ASUS Probe] D:\Program Files\ASUS\Asus Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avgnt] D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [MBM 5] D:\Program Files\Motherboard Monitor 5\MBM5.EXE (Alex van Kaam)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = D:\Program Files\CreataCard\Gold\FMRemind.exe (Micrografx, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = D:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_22.dll (Sun Microsystems, Inc.)
O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - Reg Error: Value error. File not found
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\aim.exe File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://download.games.yahoo.com/games/web_…nx.1.0.0.55.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1109450619359 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1294543693234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab (cpbrkpie Control)
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} http://www.imgag.com/cp/install/AxCtp2.cab (Create & Print ActiveX Plug-in)
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} http://di.imgag.com/imgag/cp/install/Crusher.cab (Creative Toolbox Plug-in)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} file:///C:/Documents%20and%20Settings/Becki/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://download.games.yahoo.com/games/web_…r/goldfever.cab (TikGames Online Control)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} http://games.myspace.com/gameshell/games/c…sh.1.0.0.47.cab (CPlayFirstWeddingDashControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: J:\ireland\ireland 115.jpg
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Becki\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/26 11:03:18 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell - "" = AutoRun
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun\command - "" = K:\MediaManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/09 18:43:22 | 001,345,624 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Becki\Desktop\TDSSKiller.exe
[2011/01/09 18:13:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Desktop\GooredFix Backups
[2011/01/08 20:29:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/01/08 20:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Application Data\Avira
[2011/01/08 19:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/01/08 19:22:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/01/08 19:10:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/08 19:09:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/01/08 17:01:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/01/08 17:01:08 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/01/08 17:01:07 | 000,135,096 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/01/08 17:01:07 | 000,061,960 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/01/08 17:01:07 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/01/08 17:01:07 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/01/08 17:01:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2011/01/08 16:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader
[2011/01/08 16:46:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2011/01/08 16:42:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/01/08 15:51:00 | 000,000,000 | —D | C] – C:\WINDOWS\Internet Logs
[2011/01/03 04:16:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\eFdDi06300
[2010/12/26 09:12:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/12/21 04:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Start Menu\Programs\FrostWire
[2010/12/19 13:32:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2010/12/19 13:32:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/12/14 16:42:42 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM

========== Files - Modified Within 30 Days ==========

[2011/01/09 18:49:43 | 033,689,600 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2011/01/09 18:49:41 | 015,939,584 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2011/01/09 18:48:32 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/09 18:47:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/09 18:07:38 | 001,232,020 | —- | M] () – C:\Documents and Settings\Becki\Desktop\tdsskiller.zip
[2011/01/09 16:55:02 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/08 19:22:51 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/01/08 17:29:10 | 000,000,637 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:11 | 000,000,166 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:55 | 000,001,094 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:39 | 000,001,138 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:18 | 000,087,228 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2011/01/08 15:42:46 | 000,001,003 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/01/08 14:11:42 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/01/03 12:42:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/16 09:47:52 | 001,345,624 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Becki\Desktop\TDSSKiller.exe
[2010/12/13 10:47:50 | 000,398,744 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/12/13 08:40:21 | 000,135,096 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/12/13 08:40:21 | 000,061,960 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys

========== Files Created - No Company Name ==========

[2011/01/09 18:42:19 | 001,232,020 | —- | C] () – C:\Documents and Settings\Becki\Desktop\tdsskiller.zip
[2011/01/08 17:29:10 | 000,000,637 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:08 | 000,000,166 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:54 | 000,001,094 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:37 | 000,001,138 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:17 | 000,087,228 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/02 08:08:23 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/11/28 14:16:59 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/11/15 13:18:45 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\start
[2010/11/15 13:18:07 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\completescan
[2010/11/15 13:11:32 | 000,000,010 | —- | C] () – C:\Documents and Settings\Becki\Application Data\install
[2008/09/14 13:49:35 | 000,000,110 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2007/10/05 18:07:08 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\drivers\AsProbe.sys
[2006/06/26 16:58:10 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/04/09 21:21:26 | 000,000,209 | —- | C] () – C:\WINDOWS\KA.INI
[2006/03/22 12:42:09 | 000,000,192 | —- | C] () – C:\WINDOWS\elitemediagroup.ini
[2006/03/21 16:11:25 | 000,000,434 | —- | C] () – C:\WINDOWS\rcycu.dll
[2006/01/24 14:52:40 | 000,006,144 | —- | C] () – C:\Documents and Settings\Becki\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/12/26 16:12:24 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/30 21:24:59 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Stephen.ini
[2005/06/19 17:25:05 | 000,000,327 | —- | C] () – C:\WINDOWS\AudStu.INI
[2005/06/19 11:36:16 | 000,000,000 | —- | C] () – C:\WINDOWS\musiceditor.INI
[2005/06/05 14:10:11 | 000,000,327 | —- | C] () – C:\WINDOWS\beatbox.INI
[2005/06/05 14:10:11 | 000,000,317 | —- | C] () – C:\WINDOWS\sampler.INI
[2005/06/05 14:10:11 | 000,000,028 | —- | C] () – C:\WINDOWS\robota.INI
[2005/06/04 17:46:50 | 000,000,237 | —- | C] () – C:\WINDOWS\musicmaker.INI
[2005/06/04 17:39:52 | 000,000,024 | —- | C] () – C:\WINDOWS\magix.ini
[2005/06/04 17:39:51 | 000,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2005/04/25 13:27:00 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2005/04/08 12:33:05 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/03/21 16:33:05 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Becki.ini
[2005/03/19 15:10:08 | 000,000,244 | —- | C] () – C:\WINDOWS\qwimp.ini
[2005/03/19 15:08:06 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/03/19 14:48:59 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/03/06 13:02:00 | 000,374,784 | —- | C] () – C:\WINDOWS\3dg32.dll
[2005/03/06 13:02:00 | 000,000,250 | —- | C] () – C:\WINDOWS\3dr.ini
[2005/03/04 12:36:50 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/02/27 17:18:15 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2005/02/27 17:18:15 | 000,302,592 | —- | C] () – C:\WINDOWS\System32\pgp.dll
[2005/02/27 17:18:15 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2005/02/27 17:18:15 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\keydb.dll
[2005/02/27 17:18:15 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\simple.dll
[2005/02/27 17:18:15 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\bn.dll
[2005/02/27 15:12:31 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2005/02/27 15:12:31 | 000,006,138 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2005/02/26 13:24:32 | 000,000,227 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2005/02/26 11:37:30 | 000,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2005/02/26 11:23:35 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/02/26 11:17:50 | 000,003,630 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2005/02/26 05:48:23 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll

========== Custom Scans ==========


< C:\Documents and Settings\All Users\Application Data\122DE\*.* /s >
[2008/12/01 11:12:04 | 000,002,242 | —- | M] () – C:\Documents and Settings\All Users\Application Data\122DE\{3205C0E5-2478-498D-991D-8DC6C965AB56}.swf

< C:\Documents and Settings\All Users\Application Data\1F119\*.* /s >
[2009/03/23 09:20:14 | 000,002,242 | —- | M] () – C:\Documents and Settings\All Users\Application Data\1F119\{18C29C20-0B91-4226-89C0-C238042C5EEA}.swf

< C:\Documents and Settings\All Users\Application Data\eFdDi06300\*.* /s >
[2011/01/05 12:14:36 | 000,000,094 | —- | M] () – C:\Documents and Settings\All Users\Application Data\eFdDi06300\eFdDi06300


< MD5 for: SPOOLSV.EXE >
[2010/08/17 08:19:36 | 000,058,880 | —- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 – C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010/08/17 08:17:06 | 000,058,880 | —- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F – C:\WINDOWS\system32\dllcache\spoolsv.exe
[2005/06/10 19:17:13 | 000,057,856 | —- | M] (Microsoft Corporation) MD5=AD3D9D191AEA7B5445FE1D82FFBB4788 – C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[2008/04/13 19:12:36 | 000,057,856 | —- | M] (Microsoft Corporation) MD5=D8E14A61ACC1D4A6CD0D38AEBAC7FA3B – C:\WINDOWS\$NtUninstallKB2347290$\spoolsv.exe
[2008/04/13 19:12:36 | 000,057,856 | —- | M] (Microsoft Corporation) MD5=D8E14A61ACC1D4A6CD0D38AEBAC7FA3B – C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
[2005/06/10 18:53:32 | 000,057,856 | —- | M] (Microsoft Corporation) MD5=DA81EC57ACD4CDC3D4C51CF3D409AF9F – C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEB25EAE
@Alternate Data Stream - 202 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24FECE50
@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61AF2B29
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FE30AB2

< End of report >
Hi fleadhfan,

Looks much better.

(to be replaced by Comodo after you tell me we're finished). Hadn't checked that before, but remembered a recent fix I did for someone else where it caused Windows Security Center to erroneously report what was installed and working, so figured I'd have a look.

Was that Comodo you were refering to or something else? We will deal with firewalls and updates as part of the All Clean speech at the end.

OTL couldn't set a Restore Point, let's make sure everything is set as it should be.

First make sure System Restore is turned on.

  • Click your start button
  • right click on My Computer and select properties
  • Click the System Restore tab
  • Make sure there isn't a check mark beside Turn off System Restore
  • If it is checked click it to clear it
  • click Apply, click OK

If everthing is ok there, create a Restore point
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create

You have several folders in C:\Documents and Settings\All Users\Application Data with a numerical name. The ones we checked contain a single shockwave file. Do you know anything about these?

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
FF - prefs.js..extensions.enabledItems: {3D28ECD4-DCFF-4863-B1EF-93C84A532140}:1.9.1
FF - prefs.js..extensions.enabledItems: {082AF3DD-1069-4377-B0C1-AEA1EFD7B367}:1.9.1
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab (cpbrkpie Control)

:Files
C:\DOCUMENTS AND SETTINGS\BECKI\LOCAL SETTINGS\APPLICATION DATA\{3D28ECD4-DCFF-4863-B1EF-93C84A532140}
C:\DOCUMENTS AND SETTINGS\STEPHEN\LOCAL SETTINGS\APPLICATION DATA\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367}
C:\Documents and Settings\All Users\Application Data\eFdDi06300

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.


You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with
  • OTL fix log
  • MBAM log
Still running ok?

Thanks
Re Comodo, I meant that only the Windows firewall was on at the moment, and that after we were through disinfecting the system I intend to install Comodo Personal Firewall. System was already set to allow restore points so don't know why OTL couldn't create one, but I have now done so manually. Re the All Users-App Data alphanumerically named folders each containing a single shockwave file, no, I don't have any idea what they are, and neither did my son or his wife. I'm all in favor of deleting them, and if they are needed by a legitimate program it can recreate them on the fly, or we can do a repair/reinstall as required. Do you agree? Updated Java to v23. Updated and ran MBAM; no malicious items found. Still running like a charm, and noticed when I turned it on this evening that a Microsoft update had been automatically installed, so that functionally is definitely restored. Also verified full manual access to Microsoft Update. Here are the OTL and MBAM logs: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Prefs.js: {3D28ECD4-DCFF-4863-B1EF-93C84A532140}:1.9.1 removed from extensions.enabledItems Prefs.js: {082AF3DD-1069-4377-B0C1-AEA1EFD7B367}:1.9.1 removed from extensions.enabledItems Starting removal of ActiveX control {9522B3FB-7A2B-4646-8AF6-36E7F593073C} C:\WINDOWS\Downloaded Program Files\cpbrkpie.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}\ not found. ========== FILES ========== File\Folder C:\DOCUMENTS AND SETTINGS\BECKI\LOCAL SETTINGS\APPLICATION DATA\{3D28ECD4-DCFF-4863-B1EF-93C84A532140} not found. File\Folder C:\DOCUMENTS AND SETTINGS\STEPHEN\LOCAL SETTINGS\APPLICATION DATA\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367} not found. C:\Documents and Settings\All Users\Application Data\eFdDi06300 folder moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: All Users User: Becki ->Temp folder emptied: 10167177 bytes ->Temporary Internet Files folder emptied: 18552600 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 4401603 bytes ->Flash cache emptied: 671 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33213 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Stephen ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 279192 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 32.00 mb OTL by OldTimer - Version 3.2.20.1 log created on 01102011_180408 Files\Folders moved on Reboot… C:\Documents and Settings\Becki\Local Settings\Temp\IadHide5.dll moved successfully. Registry entries deleted on Reboot… Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5500 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/10/2011 6:15:44 PM mbam-log-2011-01-10 (18-15-44).txt Scan type: Quick scan Objects scanned: 143286 Time elapsed: 2 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi fleadhfan,

OTL didn't have a problem creating a restore point that time.

I'm all in favor of deleting them, and if they are needed by a legitimate program it can recreate them on the fly, or we can do a repair/reinstall as required. Do you agree?

Yes, I just didn't want to remove something that you knowing placed there. We'll clean them up and there is one more scan to do to check our handiwork.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
[2009/11/03 12:25:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\110
[2009/10/30 10:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\122DE
[2009/04/06 00:52:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1230
[2009/03/05 21:19:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\123E
[2009/11/09 12:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\13280
[2009/04/01 18:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\132FD
[2010/01/29 20:49:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\147D
[2009/11/02 09:12:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\16399
[2009/07/17 18:50:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1D3E
[2009/04/13 09:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1F119
[2009/03/30 15:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\22119
[2009/11/07 13:39:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\241C5
[2009/05/17 16:56:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2D399
[2009/10/30 07:33:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\33399
[2009/07/19 14:53:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\3437A
[2009/02/25 09:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/03/23 09:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\E119

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use Firfox you will be asked to install an additional component, please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

Please post back with
  • OTL fix log
  • ESET log

Thanks
Here are the OTL and ESET logs. ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\Documents and Settings\All Users\Application Data\110 folder moved successfully. C:\Documents and Settings\All Users\Application Data\122DE folder moved successfully. C:\Documents and Settings\All Users\Application Data\1230 folder moved successfully. C:\Documents and Settings\All Users\Application Data\123E folder moved successfully. C:\Documents and Settings\All Users\Application Data\13280 folder moved successfully. C:\Documents and Settings\All Users\Application Data\132FD folder moved successfully. C:\Documents and Settings\All Users\Application Data\147D folder moved successfully. C:\Documents and Settings\All Users\Application Data\16399 folder moved successfully. C:\Documents and Settings\All Users\Application Data\1D3E folder moved successfully. C:\Documents and Settings\All Users\Application Data\1F119 folder moved successfully. C:\Documents and Settings\All Users\Application Data\22119 folder moved successfully. C:\Documents and Settings\All Users\Application Data\241C5 folder moved successfully. C:\Documents and Settings\All Users\Application Data\2D399 folder moved successfully. C:\Documents and Settings\All Users\Application Data\33399 folder moved successfully. C:\Documents and Settings\All Users\Application Data\3437A folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore\plugins\{696D3152-4F7A-4462-355F-51737669496D} folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore\plugins\{696D3136-4A6C-374C-4837-5779504C5455} folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore\plugins\{64653157-664A-4542-6A4C-6A39334B3934} folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore\plugins\{64653150-6D73-7770-5F76-636F6D57765A} folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore\plugins\{64653137-6737-6936-486A-3566764D7375} folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore\plugins\{64613142-4B62-7879-6563-337541545364} folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore\plugins folder moved successfully. C:\Documents and Settings\All Users\Application Data\acccore folder moved successfully. C:\Documents and Settings\All Users\Application Data\E119 folder moved successfully. OTL by OldTimer - Version 3.2.20.1 log created on 01112011_175743 —————————————— ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=491f2961b55df74eb30b102eb36a7c9b # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-01-11 11:37:38 # local_time=2011-01-11 06:37:38 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775141 100 93 173656 30380434 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=89148 # found=2 # cleaned=0 # scan_time=1994 C:\Documents and Settings\Becki\Desktop\GooredFix Backups\C\Documents and Settings\Becki\Local Settings\Application Data\{3D28ECD4-DCFF-4863-B1EF-93C84A532140}\chrome\content\overlay.xul probably a variant of Win32/Agent.NVQFFQI trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Becki\Desktop\GooredFix Backups\C\Documents and Settings\Stephen\Local Settings\Application Data\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367}\chrome\content\overlay.xul probably a variant of Win32/Agent.NVQFFQI trojan (unable to clean) 00000000000000000000000000000000 I
Hi fleadhfan,

Nothing to worry about in the ESET log. It found some files we have already quarantined. These will be removed during the tools clean up.

We need to replace a file.

Next, create this batch file.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad.
Do Not copy the word CODE

copy "C:\WINDOWS\system32\dllcache\spoolsv.exe" "C:\WINDOWS\system32\spoolsv.exe"

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "myfix.bat"
  • Click save
You will have a new file on your desktop called myfix.bat with an icon that looks like this 📎bat.PNG

Double click myfix.bat to run it.


Reboot your computer.


After the reboot
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows, OTL.Txt no Extra.txt this time.

Please post back with
  • OTL.txt
If all looks well and you have no other problems we'll clean up the tools and send you on your way after you post back.

Thanks
Ran the bat and OTL. In glancing at the OTL log, some of the host file 'O1 Hosts' url entries look pretty dodgy. Are they?

Anyway, here's the log.

OTL logfile created on: 1/12/2011 6:03:50 PM - Run 3
OTL by OldTimer - Version 3.2.20.1 Folder = F:\Cleanup Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 95.00% Paging File free
Paging file location(s): C:\pagefile.sys 3750 3750 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.42 Gb Total Space | 8.27 Gb Free Space | 33.85% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.43 Gb Free Space | 55.58% Space Free | Partition Type: NTFS
Drive E: | 40.33 Gb Total Space | 32.91 Gb Free Space | 81.61% Space Free | Partition Type: NTFS
Drive F: | 495.22 Mb Total Space | 341.09 Mb Free Space | 68.88% Space Free | Partition Type: FAT

Computer Name: P4P800E-3GHZE | User Name: Becki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - F:\Cleanup Tools\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Secunia\PSI\psia.exe (Secunia)
PRC - D:\Program Files\Secunia\PSI\sua.exe (Secunia)
PRC - D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - D:\Program Files\Motherboard Monitor 5\MBM5.exe (Alex van Kaam)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
PRC - C:\Program Files\Microsoft Hardware\Mouse\point32.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - F:\Cleanup Tools\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\Becki\Local Settings\Temp\IadHide5.dll (BackWeb)
MOD - C:\Program Files\Microsoft Hardware\Mouse\Msh_zwf.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Secunia PSI Agent) – D:\Program Files\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) – D:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (AntiVirSchedulerService) – D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – D:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (mbmiodrvr) – C:\WINDOWS\system32\mbmiodrvr.sys ([removed])
DRV - (P1131VID) Creative WebCam NX Pro (WDM) – C:\WINDOWS\system32\drivers\P1131Vid.sys (Creative Technology Ltd.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yukonwxp.sys (Marvell Semiconductor Inc.)
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (IPFilter) – C:\WINDOWS\system32\drivers\ipfilter.sys (Microsoft Corporation)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (aslm75) – C:\WINDOWS\system32\drivers\ASLM75.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/01/08 19:10:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/01/08 19:11:09 | 000,000,000 | —D | M]

[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions
[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions\[removed]
[2011/01/11 17:59:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions
[2009/12/30 09:47:54 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/01 11:28:46 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/05/08 15:13:40 | 000,000,000 | —D | M] (Move Media Player) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
[2009/04/15 10:59:49 | 000,000,000 | —D | M] (Oberon Game Host) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
[2009/01/31 11:17:34 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/09 07:34:56 | 000,000,000 | —D | M] (Skype extension for Firefox) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/01/31 11:17:52 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2010/01/12 04:21:51 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/11/30 11:21:02 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/10 17:58:20 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

O1 HOSTS File: ([2011/01/08 15:42:46 | 000,001,003 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.8minutedating.com
O1 - Hosts: 127.0.0.1 whysohardx.com
O1 - Hosts: 127.0.0.1 protectyourpc-11.com
O1 - Hosts: 127.0.0.1 checkserverstatux.com
O1 - Hosts: 127.0.0.1 xinmin.cn
O1 - Hosts: 127.0.0.1 xy95.cn
O1 - Hosts: 127.0.0.1 koralda.com
O1 - Hosts: 127.0.0.1 weirden.com
O1 - Hosts: 127.0.0.1 nanocloudcontroller.com
O1 - Hosts: 127.0.0.1 coo0lnet.net
O4 - HKLM..\Run: [ASUS Probe] D:\Program Files\ASUS\Asus Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avgnt] D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [MBM 5] D:\Program Files\Motherboard Monitor 5\MBM5.EXE (Alex van Kaam)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = D:\Program Files\CreataCard\Gold\FMRemind.exe (Micrografx, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = D:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data]
O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - Reg Error: Value error. File not found
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\aim.exe File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://download.games.yahoo.com/games/web_…nx.1.0.0.55.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1109450619359 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1294543693234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} http://www.imgag.com/cp/install/AxCtp2.cab (Create & Print ActiveX Plug-in)
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} http://di.imgag.com/imgag/cp/install/Crusher.cab (Creative Toolbox Plug-in)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} file:///C:/Documents%20and%20Settings/Becki/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://download.games.yahoo.com/games/web_…r/goldfever.cab (TikGames Online Control)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} http://games.myspace.com/gameshell/games/c…sh.1.0.0.47.cab (CPlayFirstWeddingDashControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: J:\ireland\ireland 115.jpg
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Becki\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/26 11:03:18 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell - "" = AutoRun
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun\command - "" = K:\MediaManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/12 17:58:24 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\spoolsv.exe
[2011/01/11 18:01:18 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/10 17:58:18 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/01/10 17:58:18 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/01/10 17:58:18 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/01/10 11:03:00 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011/01/09 23:41:38 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/01/09 23:39:32 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2011/01/09 23:39:32 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2011/01/09 18:43:22 | 001,345,624 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Becki\Desktop\TDSSKiller.exe
[2011/01/09 18:13:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Desktop\GooredFix Backups
[2011/01/08 20:29:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/01/08 20:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Application Data\Avira
[2011/01/08 19:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/01/08 19:22:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/01/08 19:10:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/08 19:09:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/01/08 17:01:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/01/08 17:01:08 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/01/08 17:01:07 | 000,135,096 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/01/08 17:01:07 | 000,061,960 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/01/08 17:01:07 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/01/08 17:01:07 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/01/08 17:01:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2011/01/08 16:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader
[2011/01/08 16:46:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2011/01/08 16:42:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/01/08 15:51:00 | 000,000,000 | —D | C] – C:\WINDOWS\Internet Logs
[2010/12/26 09:12:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/12/21 04:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Start Menu\Programs\FrostWire
[2010/12/19 13:32:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2010/12/19 13:32:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/12/14 16:42:42 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM

========== Files - Modified Within 30 Days ==========

[2011/01/12 18:01:43 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/12 18:01:41 | 033,689,600 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2011/01/12 18:01:39 | 015,939,584 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2011/01/12 17:59:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/12 17:57:52 | 000,000,081 | —- | M] () – C:\Documents and Settings\Becki\Desktop\myfix.bat
[2011/01/10 12:42:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/10 11:19:28 | 000,309,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/10 11:03:50 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/01/09 18:07:38 | 001,232,020 | —- | M] () – C:\Documents and Settings\Becki\Desktop\tdsskiller.zip
[2011/01/09 16:55:02 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/08 19:22:51 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/01/08 17:29:10 | 000,000,637 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:11 | 000,000,166 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:55 | 000,001,094 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:39 | 000,001,138 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:18 | 000,087,228 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2011/01/08 15:42:46 | 000,001,003 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/01/08 14:11:42 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/16 09:47:52 | 001,345,624 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Becki\Desktop\TDSSKiller.exe

========== Files Created - No Company Name ==========

[2011/01/12 17:57:52 | 000,000,081 | —- | C] () – C:\Documents and Settings\Becki\Desktop\myfix.bat
[2011/01/10 11:01:04 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/01/09 18:42:19 | 001,232,020 | —- | C] () – C:\Documents and Settings\Becki\Desktop\tdsskiller.zip
[2011/01/08 17:29:10 | 000,000,637 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:08 | 000,000,166 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:54 | 000,001,094 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:37 | 000,001,138 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:17 | 000,087,228 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/02 08:08:23 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/11/28 14:16:59 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/11/15 13:18:45 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\start
[2010/11/15 13:18:07 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\completescan
[2010/11/15 13:11:32 | 000,000,010 | —- | C] () – C:\Documents and Settings\Becki\Application Data\install
[2008/09/14 13:49:35 | 000,000,110 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2007/10/05 18:07:08 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\drivers\AsProbe.sys
[2006/06/26 16:58:10 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/04/09 21:21:26 | 000,000,209 | —- | C] () – C:\WINDOWS\KA.INI
[2006/03/22 12:42:09 | 000,000,192 | —- | C] () – C:\WINDOWS\elitemediagroup.ini
[2006/03/21 16:11:25 | 000,000,434 | —- | C] () – C:\WINDOWS\rcycu.dll
[2006/01/24 14:52:40 | 000,006,144 | —- | C] () – C:\Documents and Settings\Becki\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/12/26 16:12:24 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/30 21:24:59 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Stephen.ini
[2005/06/19 17:25:05 | 000,000,327 | —- | C] () – C:\WINDOWS\AudStu.INI
[2005/06/19 11:36:16 | 000,000,000 | —- | C] () – C:\WINDOWS\musiceditor.INI
[2005/06/05 14:10:11 | 000,000,327 | —- | C] () – C:\WINDOWS\beatbox.INI
[2005/06/05 14:10:11 | 000,000,317 | —- | C] () – C:\WINDOWS\sampler.INI
[2005/06/05 14:10:11 | 000,000,028 | —- | C] () – C:\WINDOWS\robota.INI
[2005/06/04 17:46:50 | 000,000,237 | —- | C] () – C:\WINDOWS\musicmaker.INI
[2005/06/04 17:39:52 | 000,000,024 | —- | C] () – C:\WINDOWS\magix.ini
[2005/06/04 17:39:51 | 000,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2005/04/25 13:27:00 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2005/04/08 12:33:05 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/03/21 16:33:05 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Becki.ini
[2005/03/19 15:10:08 | 000,000,244 | —- | C] () – C:\WINDOWS\qwimp.ini
[2005/03/19 15:08:06 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/03/19 14:48:59 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/03/06 13:02:00 | 000,374,784 | —- | C] () – C:\WINDOWS\3dg32.dll
[2005/03/06 13:02:00 | 000,000,250 | —- | C] () – C:\WINDOWS\3dr.ini
[2005/03/04 12:36:50 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/02/27 17:18:15 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2005/02/27 17:18:15 | 000,302,592 | —- | C] () – C:\WINDOWS\System32\pgp.dll
[2005/02/27 17:18:15 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2005/02/27 17:18:15 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\keydb.dll
[2005/02/27 17:18:15 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\simple.dll
[2005/02/27 17:18:15 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\bn.dll
[2005/02/27 15:12:31 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2005/02/27 15:12:31 | 000,006,138 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2005/02/26 13:24:32 | 000,000,227 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2005/02/26 11:37:30 | 000,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2005/02/26 11:23:35 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/02/26 11:17:50 | 000,003,630 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2005/02/26 05:48:23 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEB25EAE
@Alternate Data Stream - 202 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24FECE50
@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61AF2B29
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FE30AB2

< End of report >
Hi fleadhfan,

Looks good.

Those o1 lines in the OTL log are ok. Traffic to and from those sites are being blocked by your Hosts file. More on this later. You can google those sites, You will find they are not places to visit. Bbe sure to use "" around them when you search. "xy95.cn"

We'll clean up the tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • TDSSKiller.exe
  • TDSSKiller.zip
  • myfix.bat
  • GooredFix.exe
  • GooredFix Backups
You can also delete C:\TDSSKiller.[Version]_[Date]_[Time]_log.txt

Next

* Create a new restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
* Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep MBAM updated and use it regularly.

ESET can be uninstalled via add/remove programs.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

You are planning on installing Comodo and already have Avira and MBAM.

For resident antispyware I suggest either

Windows Defender
OR
Winpatrol

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI