This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

google redirect

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i have run a scan and this is the results

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:26:37, on 11/02/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 SP3 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\ATI-CPanel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Owner\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PlaySushi - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Go to PlaySushi web site - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - C:\Program Files\PlaySushi\PSText.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1276430777812
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 6643 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
hi thanks here is the results

OTL logfile created on: 11/02/2011 13:53:10 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.30 Gb Total Space | 20.08 Gb Free Space | 53.85% Space Free | Partition Type: NTFS
Drive D: | 2.52 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: TURNER-HOME | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
PRC - C:\ATI-CPanel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe ()
PRC - C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrksk.exe ( )


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ATKKeyboardService) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriverxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilterxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShimxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSErHrxpx) – C:\WINDOWS\System32\Drivers\AVGIDSxx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (szkgfs) – C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (szkg5) – C:\WINDOWS\system32\DRIVERS\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (EIO) – C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (RecAgent) – C:\WINDOWS\system32\DRIVERS\RecAgent.sys (Smart Link)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (Slntamr) – C:\WINDOWS\system32\drivers\slntamr.sys ( )
DRV - (Mtlmnt5) – C:\WINDOWS\system32\drivers\mtlmnt5.sys ( )
DRV - (Mtlstrm) – C:\WINDOWS\system32\drivers\mtlstrm.sys ( )
DRV - (SlNtHal) – C:\WINDOWS\system32\drivers\slnthal.sys ( )
DRV - (SlWdmSup) – C:\WINDOWS\system32\drivers\slwdmsup.sys (Vireo Software)
DRV - (NtMtlFax) – C:\WINDOWS\system32\drivers\ntmtlfax.sys ( )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/07/28 21:05:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions

O1 HOSTS File: ([2004/08/04 12:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Lexmark 3100 Series] C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [LXBRKsk] C:\Program Files\Lexmark 3100 Series\lxbrksk.exe ( )
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 00 02 00 00 [binary data]
O9 - Extra Button: Go to PlaySushi web site - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - C:\Program Files\PlaySushi\PSText.dll ()
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1276430777812 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/06/08 16:17:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/08/16 12:57:50 | 000,000,154 | R— | M] () - D:\autorun.cfg – [ UDF ]
O32 - AutoRun File - [2010/10/05 14:53:16 | 000,214,344 | R— | M] (Sports Interactive) - D:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2006/09/11 13:26:42 | 000,000,027 | R— | M] () - D:\autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56871556046913536)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/11 11:45:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\STOPzilla
[2011/02/11 11:45:02 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2011/02/11 11:45:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2011/02/11 11:45:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/02/10 18:21:38 | 000,546,256 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/02/10 18:21:38 | 000,452,048 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/02/10 18:21:38 | 000,132,560 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/02/10 18:21:38 | 000,022,992 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/02/10 18:21:36 | 000,398,800 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/02/10 18:21:36 | 000,067,024 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/02/10 18:21:36 | 000,028,624 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/02/10 18:21:34 | 000,738,768 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/02/10 18:21:34 | 000,390,608 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/02/10 18:21:34 | 000,230,864 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/02/10 10:59:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/02/10 10:59:10 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/10 10:59:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/10 10:59:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/10 10:59:06 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/10 10:59:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/10 10:56:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2011/02/10 10:56:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/02/10 10:56:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/02/10 10:56:11 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/01/21 14:44:37 | 000,439,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2011/01/16 08:49:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Lisa Work
[2011/01/15 07:04:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\End of Life Care
[2010/06/21 09:35:58 | 000,155,648 | —- | C] ( ) – C:\WINDOWS\System32\flashshl.dll
[2010/06/08 17:05:18 | 001,301,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2010/06/08 17:05:18 | 000,548,952 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slntamr.sys
[2010/06/08 17:05:18 | 000,221,736 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2010/06/08 17:05:18 | 000,167,384 | —- | C] ( ) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2010/06/08 17:05:18 | 000,086,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slnthal.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/11 12:17:30 | 000,481,000 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/11 12:17:30 | 000,079,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/11 11:54:55 | 000,000,310 | -HS- | M] () – C:\WINDOWS\tasks\Octomntob.job
[2011/02/11 11:54:38 | 000,000,240 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/02/11 11:53:31 | 000,000,022 | —- | M] () – C:\WINDOWS\FLASHKSK.INI
[2011/02/11 11:53:25 | 000,003,206 | —- | M] () – C:\WINDOWS\LXBRCAH.ini
[2011/02/11 11:53:21 | 000,013,688 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/11 11:53:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/10 18:21:38 | 000,546,256 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/02/10 18:21:38 | 000,452,048 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/02/10 18:21:38 | 000,132,560 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/02/10 18:21:38 | 000,022,992 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/02/10 18:21:36 | 000,398,800 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/02/10 18:21:36 | 000,067,024 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/02/10 18:21:36 | 000,028,624 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/02/10 18:21:34 | 000,738,768 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/02/10 18:21:34 | 000,390,608 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/02/10 18:21:34 | 000,230,864 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/02/10 18:12:56 | 000,026,112 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Monday.doc
[2011/02/10 17:46:56 | 000,133,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/10 11:12:47 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/10 10:59:10 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 10:56:17 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/10 10:47:37 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/02/09 05:22:51 | 000,050,688 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Resident Bath Preferences & Record[1].xls
[2011/02/05 15:26:48 | 000,002,201 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\FMRTE.lnk
[2011/02/03 17:44:02 | 000,026,624 | —- | M] () – C:\Documents and Settings\Owner\My Documents\266349_cv current 3[1].doc
[2011/01/26 21:52:14 | 000,069,632 | RHS- | M] () – C:\WINDOWS\System32\CatRootf.dll
[2011/01/26 17:14:50 | 007,586,816 | —- | M] () – C:\Documents and Settings\Owner\My Documents\1st Choice Pre Jan 2011 vista[1].ppt
[2011/01/21 14:44:37 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2011/01/21 14:44:37 | 000,439,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2011/01/14 20:29:00 | 000,000,324 | —- | M] () – C:\WINDOWS\lexstat.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/11 11:54:38 | 000,000,240 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/02/10 18:12:56 | 000,026,112 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Monday.doc
[2011/02/10 10:59:10 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 10:56:17 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/09 05:22:51 | 000,050,688 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Resident Bath Preferences & Record[1].xls
[2011/02/03 17:44:02 | 000,026,624 | —- | C] () – C:\Documents and Settings\Owner\My Documents\266349_cv current 3[1].doc
[2011/01/26 21:52:14 | 000,069,632 | RHS- | C] () – C:\WINDOWS\System32\CatRootf.dll
[2011/01/26 21:52:14 | 000,000,310 | -HS- | C] () – C:\WINDOWS\tasks\Octomntob.job
[2011/01/26 17:14:50 | 007,586,816 | —- | C] () – C:\Documents and Settings\Owner\My Documents\1st Choice Pre Jan 2011 vista[1].ppt
[2010/12/12 17:28:17 | 000,124,362 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1547161642-115176313-725345543-1003-0.dat
[2010/12/03 12:24:56 | 000,124,362 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/07/27 16:13:12 | 000,078,344 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/06/21 09:35:58 | 000,000,022 | —- | C] () – C:\WINDOWS\FLASHKSK.INI
[2010/06/21 09:35:57 | 000,000,468 | —- | C] () – C:\WINDOWS\LXBRFMT.INI
[2010/06/21 09:35:55 | 000,003,206 | —- | C] () – C:\WINDOWS\LXBRCAH.ini
[2010/06/21 09:35:53 | 000,002,178 | —- | C] () – C:\WINDOWS\System32\LXBRSET.INI
[2010/06/21 09:34:00 | 000,000,324 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/06/21 09:33:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbrvs.dll
[2010/06/21 09:32:53 | 000,000,181 | —- | C] () – C:\WINDOWS\System32\lxbrcoin.ini
[2010/06/19 11:04:39 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/06/13 17:50:43 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2010/06/08 17:05:18 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\slextspk.dll
[2010/06/08 17:05:18 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\SLGen.dll
[2010/06/08 17:03:30 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/06/08 16:28:52 | 000,046,592 | —- | C] () – C:\WINDOWS\System32\asfrench.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asrussian.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asgerman.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\aseng.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\askorean.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\asjapan.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\ASCHT.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\aschs.dll
[2010/06/08 16:28:52 | 000,010,496 | —- | C] () – C:\WINDOWS\System32\ATKOSDMini.DLL
[2010/06/08 16:28:52 | 000,000,018 | —- | C] () – C:\WINDOWS\System32\atkid.ini
[2006/08/11 13:45:20 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 13:43:10 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/08/11 13:43:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/11 13:43:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/08/11 13:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/11 13:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/08/11 13:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/03 16:44:54 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2004/08/04 12:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 12:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 12:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 12:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 12:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2003/07/02 16:04:32 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\coinst.dll
[1999/01/22 10:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2010/06/13 13:28:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/19 08:30:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/06/19 11:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2011/02/11 13:51:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/12/19 08:55:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/28 12:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar
[2010/11/28 12:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar Experience Image Manager
[2010/06/15 18:02:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG9
[2010/07/11 10:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\My Games
[2010/11/05 10:43:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sports Interactive
[2011/02/11 12:00:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2010/06/19 12:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Search
[2011/02/11 11:54:55 | 000,000,310 | -HS- | M] () – C:\WINDOWS\Tasks\Octomntob.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/06/08 16:17:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/14 08:54:54 | 000,000,210 | -HS- | M] () – C:\boot.ini
[2010/06/08 16:17:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/06/13 18:30:28 | 000,000,040 | —- | M] () – C:\CTJINI.INI
[2010/06/13 18:30:43 | 000,001,319 | —- | M] () – C:\drvpnp.dat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/06/08 16:17:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/08 16:17:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/06/13 12:55:08 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/11 11:53:11 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/06/13 18:30:41 | 000,000,657 | —- | M] () – C:\pnpID.dat
[2011/02/11 13:49:12 | 000,038,528 | —- | M] () – C:\TDSSKiller.2.4.17.0_11.02.2011_13.48.35_log.txt
[2011/02/11 13:50:07 | 000,038,528 | —- | M] () – C:\TDSSKiller.2.4.17.0_11.02.2011_13.49.41_log.txt
[2010/06/13 18:33:10 | 000,000,091 | —- | M] () – C:\temp.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/06/08 16:17:04 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/07/29 09:45:10 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBRPP5C.DLL
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/09/22 17:10:37 | 000,001,666 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/06/08 17:00:49 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/06/08 17:00:49 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/06/08 17:00:49 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/06/13 12:59:53 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/06/13 13:10:29 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/06/08 16:23:31 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2010/10/16 09:49:31 | 023,458,816 | —- | M] () – C:\Documents and Settings\Owner\My Documents\242.exe
[2010/06/19 12:37:21 | 000,889,416 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\dotNetFx40_Full_setup.exe
[2010/11/20 10:22:01 | 180,137,984 | —- | M] () – C:\Documents and Settings\Owner\My Documents\fm2011v11.1.1_pc_dit_patch.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/06/13 13:10:29 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Owner\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/11 13:53:08 | 000,065,536 | —- | M] () – C:\Documents and Settings\Owner\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-10 11:12:47

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E

< End of report >


OTL Extras logfile created on: 11/02/2011 13:53:10 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.30 Gb Total Space | 20.08 Gb Free Space | 53.85% Space Free | Partition Type: NTFS
Drive D: | 2.52 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: TURNER-HOME | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:TCP" = 1900:TCP:LocalSubNet:Enabled:UDP 1900

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe" = C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe:*:Enabled:Football Manager 2010 – (Sports Interactive)
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 – (Firaxis Games)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Sports Interactive\Football Manager 2011\fm.exe" = C:\Program Files\Sports Interactive\Football Manager 2011\fm.exe:*:Enabled:Football Manager 2011 – (Sports Interactive)
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Disabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Disabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Disabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Disabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Disabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{22C29E59-2EF5-4B64-9B7F-9F7A69BC7D1A}" = FMRTE
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{73CB01A1-A9D0-41CA-B490-348880975F48}" = STOPzilla
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG 9.0
"BFG-Luxor 3" = Luxor 3
"Championship Manager 01-02" = Championship Manager 01-02
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Football Manager 2010" = Football Manager 2010
"Football Manager 2011" = Football Manager 2011
"ie8" = Windows Internet Explorer 8
"Lexmark 3100 Series" = Lexmark 3100 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Playsushi" = Playsushi
"uTorrent" = µTorrent
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/02/2011 08:17:22 | Computer Name = TURNER-HOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}


< End of report >
2011/02/11 13:49:41.0875 3248 TDSS rootkit removing tool 2.4.17.0 Feb 10 2011 11:07:20 2011/02/11 13:49:42.0281 3248 ================================================================================ 2011/02/11 13:49:42.0281 3248 SystemInfo: 2011/02/11 13:49:42.0281 3248 2011/02/11 13:49:42.0281 3248 OS Version: 5.1.2600 ServicePack: 3.0 2011/02/11 13:49:42.0281 3248 Product type: Workstation 2011/02/11 13:49:42.0281 3248 ComputerName: TURNER-HOME 2011/02/11 13:49:42.0281 3248 UserName: Owner 2011/02/11 13:49:42.0281 3248 Windows directory: C:\WINDOWS 2011/02/11 13:49:42.0281 3248 System windows directory: C:\WINDOWS 2011/02/11 13:49:42.0281 3248 Processor architecture: Intel x86 2011/02/11 13:49:42.0281 3248 Number of processors: 2 2011/02/11 13:49:42.0281 3248 Page size: 0x1000 2011/02/11 13:49:42.0281 3248 Boot type: Normal boot 2011/02/11 13:49:42.0281 3248 ================================================================================ 2011/02/11 13:49:43.0078 3248 Initialize success 2011/02/11 13:49:46.0109 4028 ================================================================================ 2011/02/11 13:49:46.0109 4028 Scan started 2011/02/11 13:49:46.0109 4028 Mode: Manual; 2011/02/11 13:49:46.0109 4028 ================================================================================ 2011/02/11 13:49:46.0906 4028 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/02/11 13:49:47.0000 4028 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/02/11 13:49:47.0156 4028 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/02/11 13:49:47.0250 4028 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2011/02/11 13:49:47.0328 4028 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 2011/02/11 13:49:47.0609 4028 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS\system32\drivers\ALCXSENS.SYS 2011/02/11 13:49:47.0765 4028 ALCXWDM (647b8e33e1166829889502a3df2a7ba8) C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2011/02/11 13:49:48.0265 4028 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/02/11 13:49:48.0656 4028 asuskbnt (f5c2ccdb273a546e9c3a15250f1d9165) C:\WINDOWS\system32\drivers\atkkbnt.sys 2011/02/11 13:49:48.0765 4028 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/02/11 13:49:48.0843 4028 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/02/11 13:49:49.0046 4028 ati2mtag (b650aa7456a56dcab2d4ab80ea5124ac) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/02/11 13:49:49.0171 4028 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/02/11 13:49:49.0250 4028 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/02/11 13:49:49.0375 4028 AVGIDSDriverxpx (97670687f6c8f35e7b611f2ce1f94472) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys 2011/02/11 13:49:49.0484 4028 AVGIDSErHrxpx (277fc6b0f0be23bae7e63f184034b2fe) C:\WINDOWS\system32\Drivers\AVGIDSxx.sys 2011/02/11 13:49:49.0578 4028 AVGIDSFilterxpx (dba65f23b686bdf043bbb54e55c72887) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys 2011/02/11 13:49:49.0593 4028 AVGIDSShimxpx (a552461aab7a36c2465ff19e59af08bf) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys 2011/02/11 13:49:49.0734 4028 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\system32\Drivers\avgldx86.sys 2011/02/11 13:49:49.0812 4028 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\WINDOWS\system32\Drivers\avgmfx86.sys 2011/02/11 13:49:49.0890 4028 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\WINDOWS\system32\Drivers\avgrkx86.sys 2011/02/11 13:49:49.0984 4028 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\WINDOWS\system32\Drivers\avgtdix.sys 2011/02/11 13:49:50.0062 4028 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/02/11 13:49:50.0140 4028 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/02/11 13:49:50.0296 4028 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/02/11 13:49:50.0375 4028 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/02/11 13:49:50.0484 4028 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/02/11 13:49:50.0890 4028 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/02/11 13:49:51.0046 4028 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/02/11 13:49:51.0140 4028 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/02/11 13:49:51.0187 4028 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/02/11 13:49:51.0281 4028 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/02/11 13:49:51.0453 4028 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/02/11 13:49:51.0546 4028 EIO (0daf3544804650526751c478aeccce63) C:\WINDOWS\system32\drivers\EIO.sys 2011/02/11 13:49:51.0656 4028 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/02/11 13:49:51.0734 4028 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/02/11 13:49:51.0812 4028 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/02/11 13:49:51.0890 4028 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/02/11 13:49:51.0968 4028 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/02/11 13:49:52.0062 4028 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/02/11 13:49:52.0140 4028 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/02/11 13:49:52.0218 4028 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/02/11 13:49:52.0406 4028 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/02/11 13:49:52.0640 4028 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/02/11 13:49:52.0718 4028 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/02/11 13:49:52.0890 4028 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/02/11 13:49:52.0984 4028 intelppm (8ac105ee95caddecb93710b40678198b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/02/11 13:49:53.0062 4028 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/02/11 13:49:53.0140 4028 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/02/11 13:49:53.0218 4028 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/02/11 13:49:53.0296 4028 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/02/11 13:49:53.0375 4028 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/02/11 13:49:53.0453 4028 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/02/11 13:49:53.0562 4028 is3srv (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\drivers\is3srv.sys 2011/02/11 13:49:53.0656 4028 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/02/11 13:49:53.0750 4028 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/02/11 13:49:53.0828 4028 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/02/11 13:49:53.0921 4028 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/02/11 13:49:54.0093 4028 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/02/11 13:49:54.0203 4028 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/02/11 13:49:54.0281 4028 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 2011/02/11 13:49:54.0375 4028 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/02/11 13:49:54.0453 4028 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/02/11 13:49:54.0609 4028 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/02/11 13:49:54.0734 4028 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/02/11 13:49:54.0828 4028 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/02/11 13:49:54.0921 4028 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/02/11 13:49:54.0984 4028 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/02/11 13:49:55.0046 4028 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/02/11 13:49:55.0140 4028 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/02/11 13:49:55.0250 4028 Mtlmnt5 (32ce8d0359672bcb720bf82c86a50d71) C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys 2011/02/11 13:49:55.0437 4028 Mtlstrm (8ada829d3d7cf2db7b1c41f3c7beaa79) C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys 2011/02/11 13:49:55.0531 4028 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/02/11 13:49:55.0625 4028 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/02/11 13:49:55.0703 4028 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/02/11 13:49:55.0781 4028 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/02/11 13:49:55.0859 4028 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/02/11 13:49:55.0953 4028 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/02/11 13:49:56.0031 4028 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/02/11 13:49:56.0109 4028 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/02/11 13:49:56.0218 4028 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/02/11 13:49:56.0281 4028 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/02/11 13:49:56.0406 4028 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/02/11 13:49:56.0515 4028 NtMtlFax (f11e04e2d0034172eb2938d0bbc7b05b) C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys 2011/02/11 13:49:56.0593 4028 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/02/11 13:49:56.0968 4028 nv (5645072033c2e51386e91bc137c0beb5) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/02/11 13:49:57.0109 4028 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/02/11 13:49:57.0187 4028 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/02/11 13:49:57.0265 4028 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/02/11 13:49:57.0343 4028 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/02/11 13:49:57.0421 4028 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/02/11 13:49:57.0484 4028 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/02/11 13:49:57.0562 4028 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/02/11 13:49:57.0718 4028 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/02/11 13:49:57.0812 4028 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/02/11 13:49:58.0265 4028 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/02/11 13:49:58.0359 4028 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/02/11 13:49:58.0437 4028 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/02/11 13:49:58.0812 4028 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/02/11 13:49:58.0906 4028 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/02/11 13:49:58.0984 4028 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/02/11 13:49:59.0062 4028 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/02/11 13:49:59.0156 4028 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/02/11 13:49:59.0234 4028 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/02/11 13:49:59.0343 4028 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/02/11 13:49:59.0437 4028 RecAgent (e9aaa0092d74a9d371659c4c38882e12) C:\WINDOWS\system32\DRIVERS\RecAgent.sys 2011/02/11 13:49:59.0515 4028 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/02/11 13:49:59.0609 4028 RTL8023xp (3529828ec571fb2f64f6b142f9109993) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 2011/02/11 13:49:59.0703 4028 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 2011/02/11 13:49:59.0812 4028 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/02/11 13:49:59.0859 4028 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/02/11 13:50:00.0000 4028 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/02/11 13:50:00.0078 4028 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/02/11 13:50:00.0140 4028 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/02/11 13:50:00.0250 4028 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/02/11 13:50:00.0453 4028 Slntamr (c1a825aef40774bab5bed0e64022b089) C:\WINDOWS\system32\DRIVERS\slntamr.sys 2011/02/11 13:50:00.0546 4028 SlNtHal (d84ce5182f7d9f3e7e4ff0c36b16a466) C:\WINDOWS\system32\DRIVERS\Slnthal.sys 2011/02/11 13:50:00.0625 4028 SlWdmSup (4a35904e8ee6c103c815ee269cc7a7b9) C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys 2011/02/11 13:50:00.0781 4028 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/02/11 13:50:00.0875 4028 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/02/11 13:50:00.0984 4028 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/02/11 13:50:01.0078 4028 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/02/11 13:50:01.0171 4028 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/02/11 13:50:01.0515 4028 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/02/11 13:50:01.0640 4028 szkg5 (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\DRIVERS\szkg.sys 2011/02/11 13:50:01.0750 4028 szkgfs (410a02a920fa9daeec56364e839597c1) C:\WINDOWS\system32\drivers\szkgfs.sys 2011/02/11 13:50:01.0859 4028 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/02/11 13:50:01.0953 4028 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/02/11 13:50:02.0031 4028 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/02/11 13:50:02.0109 4028 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/02/11 13:50:02.0281 4028 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/02/11 13:50:02.0468 4028 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/02/11 13:50:02.0578 4028 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/02/11 13:50:02.0656 4028 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/02/11 13:50:02.0734 4028 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/02/11 13:50:02.0812 4028 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/02/11 13:50:02.0890 4028 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/02/11 13:50:02.0968 4028 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/02/11 13:50:03.0046 4028 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/02/11 13:50:03.0203 4028 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/02/11 13:50:03.0296 4028 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/02/11 13:50:03.0453 4028 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/02/11 13:50:03.0625 4028 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/02/11 13:50:03.0703 4028 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/02/11 13:50:03.0875 4028 ================================================================================ 2011/02/11 13:50:03.0875 4028 Scan finished 2011/02/11 13:50:03.0875 4028 ================================================================================ 2011/02/11 13:50:07.0546 3632 Deinitialize success
there was 2 logs this is the one you asked for not the other one 2011/02/11 13:48:35.0500 1540 TDSS rootkit removing tool 2.4.17.0 Feb 10 2011 11:07:20 2011/02/11 13:48:35.0828 1540 ================================================================================ 2011/02/11 13:48:35.0828 1540 SystemInfo: 2011/02/11 13:48:35.0828 1540 2011/02/11 13:48:35.0828 1540 OS Version: 5.1.2600 ServicePack: 3.0 2011/02/11 13:48:35.0828 1540 Product type: Workstation 2011/02/11 13:48:35.0828 1540 ComputerName: TURNER-HOME 2011/02/11 13:48:35.0828 1540 UserName: Owner 2011/02/11 13:48:35.0828 1540 Windows directory: C:\WINDOWS 2011/02/11 13:48:35.0828 1540 System windows directory: C:\WINDOWS 2011/02/11 13:48:35.0828 1540 Processor architecture: Intel x86 2011/02/11 13:48:35.0828 1540 Number of processors: 2 2011/02/11 13:48:35.0828 1540 Page size: 0x1000 2011/02/11 13:48:35.0828 1540 Boot type: Normal boot 2011/02/11 13:48:35.0828 1540 ================================================================================ 2011/02/11 13:48:36.0890 1540 Initialize success 2011/02/11 13:48:40.0937 1008 ================================================================================ 2011/02/11 13:48:40.0937 1008 Scan started 2011/02/11 13:48:40.0937 1008 Mode: Manual; 2011/02/11 13:48:40.0937 1008 ================================================================================ 2011/02/11 13:48:42.0296 1008 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/02/11 13:48:42.0421 1008 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/02/11 13:48:42.0640 1008 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/02/11 13:48:42.0750 1008 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2011/02/11 13:48:42.0828 1008 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 2011/02/11 13:48:43.0156 1008 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS\system32\drivers\ALCXSENS.SYS 2011/02/11 13:48:43.0375 1008 ALCXWDM (647b8e33e1166829889502a3df2a7ba8) C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2011/02/11 13:48:43.0656 1008 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/02/11 13:48:43.0921 1008 asuskbnt (f5c2ccdb273a546e9c3a15250f1d9165) C:\WINDOWS\system32\drivers\atkkbnt.sys 2011/02/11 13:48:44.0046 1008 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/02/11 13:48:44.0125 1008 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/02/11 13:48:44.0312 1008 ati2mtag (b650aa7456a56dcab2d4ab80ea5124ac) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/02/11 13:48:44.0484 1008 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/02/11 13:48:44.0562 1008 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/02/11 13:48:44.0687 1008 AVGIDSDriverxpx (97670687f6c8f35e7b611f2ce1f94472) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys 2011/02/11 13:48:44.0796 1008 AVGIDSErHrxpx (277fc6b0f0be23bae7e63f184034b2fe) C:\WINDOWS\system32\Drivers\AVGIDSxx.sys 2011/02/11 13:48:44.0890 1008 AVGIDSFilterxpx (dba65f23b686bdf043bbb54e55c72887) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys 2011/02/11 13:48:44.0906 1008 AVGIDSShimxpx (a552461aab7a36c2465ff19e59af08bf) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys 2011/02/11 13:48:45.0046 1008 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\system32\Drivers\avgldx86.sys 2011/02/11 13:48:45.0125 1008 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\WINDOWS\system32\Drivers\avgmfx86.sys 2011/02/11 13:48:45.0203 1008 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\WINDOWS\system32\Drivers\avgrkx86.sys 2011/02/11 13:48:45.0296 1008 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\WINDOWS\system32\Drivers\avgtdix.sys 2011/02/11 13:48:45.0375 1008 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/02/11 13:48:45.0468 1008 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/02/11 13:48:45.0593 1008 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/02/11 13:48:45.0671 1008 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/02/11 13:48:45.0765 1008 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/02/11 13:48:46.0171 1008 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/02/11 13:48:46.0343 1008 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/02/11 13:48:46.0484 1008 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/02/11 13:48:46.0546 1008 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/02/11 13:48:46.0640 1008 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/02/11 13:48:46.0796 1008 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/02/11 13:48:46.0906 1008 EIO (0daf3544804650526751c478aeccce63) C:\WINDOWS\system32\drivers\EIO.sys 2011/02/11 13:48:47.0015 1008 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/02/11 13:48:47.0093 1008 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/02/11 13:48:47.0171 1008 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/02/11 13:48:47.0250 1008 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/02/11 13:48:47.0328 1008 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/02/11 13:48:47.0406 1008 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/02/11 13:48:47.0484 1008 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/02/11 13:48:47.0578 1008 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/02/11 13:48:47.0750 1008 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/02/11 13:48:47.0984 1008 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/02/11 13:48:48.0078 1008 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/02/11 13:48:48.0234 1008 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/02/11 13:48:48.0312 1008 intelppm (8ac105ee95caddecb93710b40678198b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/02/11 13:48:48.0390 1008 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/02/11 13:48:48.0500 1008 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/02/11 13:48:48.0609 1008 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/02/11 13:48:48.0703 1008 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/02/11 13:48:48.0781 1008 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/02/11 13:48:48.0859 1008 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/02/11 13:48:48.0937 1008 is3srv (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\drivers\is3srv.sys 2011/02/11 13:48:49.0062 1008 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/02/11 13:48:49.0125 1008 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/02/11 13:48:49.0218 1008 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/02/11 13:48:49.0296 1008 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/02/11 13:48:49.0484 1008 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/02/11 13:48:49.0593 1008 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/02/11 13:48:49.0671 1008 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 2011/02/11 13:48:49.0765 1008 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/02/11 13:48:49.0828 1008 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/02/11 13:48:50.0000 1008 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/02/11 13:48:50.0125 1008 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/02/11 13:48:50.0250 1008 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/02/11 13:48:50.0343 1008 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/02/11 13:48:50.0406 1008 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/02/11 13:48:50.0484 1008 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/02/11 13:48:50.0578 1008 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/02/11 13:48:50.0671 1008 Mtlmnt5 (32ce8d0359672bcb720bf82c86a50d71) C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys 2011/02/11 13:48:50.0875 1008 Mtlstrm (8ada829d3d7cf2db7b1c41f3c7beaa79) C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys 2011/02/11 13:48:51.0062 1008 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/02/11 13:48:51.0156 1008 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/02/11 13:48:51.0234 1008 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/02/11 13:48:51.0312 1008 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/02/11 13:48:51.0390 1008 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/02/11 13:48:51.0468 1008 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/02/11 13:48:51.0546 1008 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/02/11 13:48:51.0640 1008 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/02/11 13:48:51.0734 1008 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/02/11 13:48:51.0812 1008 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/02/11 13:48:51.0921 1008 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/02/11 13:48:52.0093 1008 NtMtlFax (f11e04e2d0034172eb2938d0bbc7b05b) C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys 2011/02/11 13:48:52.0187 1008 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/02/11 13:48:52.0640 1008 nv (5645072033c2e51386e91bc137c0beb5) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/02/11 13:48:53.0046 1008 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/02/11 13:48:53.0125 1008 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/02/11 13:48:53.0203 1008 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/02/11 13:48:53.0328 1008 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/02/11 13:48:53.0390 1008 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/02/11 13:48:53.0484 1008 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/02/11 13:48:53.0546 1008 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/02/11 13:48:53.0703 1008 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/02/11 13:48:53.0796 1008 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/02/11 13:48:54.0265 1008 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/02/11 13:48:54.0359 1008 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/02/11 13:48:54.0437 1008 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/02/11 13:48:54.0812 1008 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/02/11 13:48:54.0906 1008 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/02/11 13:48:54.0984 1008 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/02/11 13:48:55.0062 1008 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/02/11 13:48:55.0156 1008 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/02/11 13:48:55.0234 1008 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/02/11 13:48:55.0343 1008 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/02/11 13:48:55.0421 1008 RecAgent (e9aaa0092d74a9d371659c4c38882e12) C:\WINDOWS\system32\DRIVERS\RecAgent.sys 2011/02/11 13:48:55.0500 1008 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/02/11 13:48:55.0609 1008 RTL8023xp (3529828ec571fb2f64f6b142f9109993) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 2011/02/11 13:48:55.0703 1008 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 2011/02/11 13:48:55.0796 1008 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/02/11 13:48:55.0843 1008 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/02/11 13:48:55.0984 1008 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/02/11 13:48:56.0078 1008 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/02/11 13:48:56.0140 1008 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/02/11 13:48:56.0234 1008 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/02/11 13:48:56.0437 1008 Slntamr (c1a825aef40774bab5bed0e64022b089) C:\WINDOWS\system32\DRIVERS\slntamr.sys 2011/02/11 13:48:56.0562 1008 SlNtHal (d84ce5182f7d9f3e7e4ff0c36b16a466) C:\WINDOWS\system32\DRIVERS\Slnthal.sys 2011/02/11 13:48:56.0640 1008 SlWdmSup (4a35904e8ee6c103c815ee269cc7a7b9) C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys 2011/02/11 13:48:56.0796 1008 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/02/11 13:48:56.0890 1008 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/02/11 13:48:57.0000 1008 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/02/11 13:48:57.0125 1008 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/02/11 13:48:57.0203 1008 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/02/11 13:48:57.0546 1008 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/02/11 13:48:57.0671 1008 szkg5 (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\DRIVERS\szkg.sys 2011/02/11 13:48:57.0781 1008 szkgfs (410a02a920fa9daeec56364e839597c1) C:\WINDOWS\system32\drivers\szkgfs.sys 2011/02/11 13:48:57.0890 1008 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/02/11 13:48:58.0000 1008 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/02/11 13:48:58.0078 1008 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/02/11 13:48:58.0156 1008 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/02/11 13:48:58.0328 1008 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/02/11 13:48:58.0515 1008 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/02/11 13:48:58.0640 1008 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/02/11 13:48:58.0718 1008 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/02/11 13:48:58.0796 1008 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/02/11 13:48:58.0875 1008 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/02/11 13:48:58.0953 1008 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/02/11 13:48:59.0031 1008 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/02/11 13:48:59.0109 1008 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/02/11 13:48:59.0265 1008 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/02/11 13:48:59.0359 1008 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/02/11 13:48:59.0515 1008 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/02/11 13:48:59.0703 1008 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/02/11 13:48:59.0765 1008 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/02/11 13:48:59.0953 1008 ================================================================================ 2011/02/11 13:48:59.0953 1008 Scan finished 2011/02/11 13:48:59.0953 1008 ================================================================================ 2011/02/11 13:49:12.0046 2316 Deinitialize success
We need to run Combofix,however it will not run with AVG installed so you need to uninstall it using the removal tool first,do not reinstall it until i tell you.

http://www.avg.com/us-en/download-tools (top one)



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
i have used the avg remover but combofix tells me it is still running but i can not find it anywhere on the pc??? also get these messages windows cannot find '32788R22FWJFW\n.pif windows cannot find '32788R22FWJFW\iexplore.exe windows cannot find 'NIRCMD'
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.







Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.





Next

Post a new OTL log and tell me how the computer is running.
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5747 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 12/02/2011 15:20:55 mbam-log-2011-02-12 (15-20-55).txt Scan type: Quick scan Objects scanned: 132889 Time elapsed: 4 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.PlaySushi) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome (PUP.PlaySushi) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components (PUP.PlaySushi) -> Quarantined and deleted successfully. Files Infected: c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest (PUP.PlaySushi) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\install.rdf (PUP.PlaySushi) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pstextlinks.jar (PUP.PlaySushi) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.dll (PUP.PlaySushi) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.xpt (PUP.PlaySushi) -> Quarantined and deleted successfully.
OTL logfile created on: 12/02/2011 16:09:35 - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.30 Gb Total Space | 18.54 Gb Free Space | 49.70% Space Free | Partition Type: NTFS
Drive D: | 2.52 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: TURNER-HOME | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
PRC - C:\ATI-CPanel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe ()
PRC - C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrksk.exe ( )


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ATKKeyboardService) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)


========== Driver Services (SafeList) ==========

DRV - (szkgfs) – C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (szkg5) – C:\WINDOWS\system32\DRIVERS\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (EIO) – C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (RecAgent) – C:\WINDOWS\system32\DRIVERS\RecAgent.sys (Smart Link)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (Slntamr) – C:\WINDOWS\system32\drivers\slntamr.sys ( )
DRV - (Mtlmnt5) – C:\WINDOWS\system32\drivers\mtlmnt5.sys ( )
DRV - (Mtlstrm) – C:\WINDOWS\system32\drivers\mtlstrm.sys ( )
DRV - (SlNtHal) – C:\WINDOWS\system32\drivers\slnthal.sys ( )
DRV - (SlWdmSup) – C:\WINDOWS\system32\drivers\slwdmsup.sys (Vireo Software)
DRV - (NtMtlFax) – C:\WINDOWS\system32\drivers\ntmtlfax.sys ( )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/07/28 21:05:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions

O1 HOSTS File: ([2004/08/04 12:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Lexmark 3100 Series] C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [LXBRKsk] C:\Program Files\Lexmark 3100 Series\lxbrksk.exe ( )
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 00 02 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1276430777812 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/06/08 16:17:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/08/16 12:57:50 | 000,000,154 | R— | M] () - D:\autorun.cfg – [ UDF ]
O32 - AutoRun File - [2010/10/05 14:53:16 | 000,214,344 | R— | M] (Sports Interactive) - D:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2006/09/11 13:26:42 | 000,000,027 | R— | M] () - D:\autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/12 15:23:02 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/12 13:42:55 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2011/02/12 13:32:08 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2011/02/12 13:22:29 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/02/12 13:22:29 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/02/12 13:02:49 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/02/12 12:40:08 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/02/12 12:35:12 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/12 12:24:59 | 000,000,000 | —D | C] – C:\32788R22FWJFW.1.tmp
[2011/02/12 12:13:50 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/02/12 12:03:37 | 000,000,000 | —D | C] – C:\Qoobox
[2011/02/11 11:45:02 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2011/02/11 11:45:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2011/02/11 11:45:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/02/10 18:21:38 | 000,546,256 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/02/10 18:21:38 | 000,452,048 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/02/10 18:21:38 | 000,132,560 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/02/10 18:21:38 | 000,022,992 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/02/10 18:21:36 | 000,398,800 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/02/10 18:21:36 | 000,067,024 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/02/10 18:21:36 | 000,028,624 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/02/10 18:21:34 | 000,738,768 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/02/10 18:21:34 | 000,390,608 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/02/10 18:21:34 | 000,230,864 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/02/10 10:59:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/02/10 10:59:10 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/10 10:59:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/10 10:59:06 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/10 10:59:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/10 10:56:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2011/02/10 10:56:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/02/10 10:56:11 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/01/21 14:44:37 | 000,439,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2011/01/16 08:49:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Lisa Work
[2011/01/15 07:04:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\End of Life Care
[2010/06/21 09:35:58 | 000,155,648 | —- | C] ( ) – C:\WINDOWS\System32\flashshl.dll
[2010/06/08 17:05:18 | 001,301,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2010/06/08 17:05:18 | 000,548,952 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slntamr.sys
[2010/06/08 17:05:18 | 000,221,736 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2010/06/08 17:05:18 | 000,167,384 | —- | C] ( ) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2010/06/08 17:05:18 | 000,086,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slnthal.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/12 15:22:22 | 000,000,120 | —- | M] () – C:\WINDOWS\System32\drivers\kgpfr2.cfg
[2011/02/12 13:44:10 | 000,000,240 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/02/12 13:43:07 | 000,000,022 | —- | M] () – C:\WINDOWS\FLASHKSK.INI
[2011/02/12 13:43:01 | 000,003,206 | —- | M] () – C:\WINDOWS\LXBRCAH.ini
[2011/02/12 13:42:59 | 000,013,688 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/12 13:42:59 | 000,000,310 | -HS- | M] () – C:\WINDOWS\tasks\Octomntob.job
[2011/02/12 13:42:54 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/12 13:42:51 | 2145,386,496 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2011/02/12 12:35:17 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/02/12 08:39:02 | 000,000,324 | —- | M] () – C:\WINDOWS\lexstat.ini
[2011/02/11 12:17:30 | 000,481,000 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/11 12:17:30 | 000,079,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/10 18:21:38 | 000,546,256 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/02/10 18:21:38 | 000,452,048 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/02/10 18:21:38 | 000,132,560 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/02/10 18:21:38 | 000,022,992 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/02/10 18:21:36 | 000,398,800 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/02/10 18:21:36 | 000,067,024 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/02/10 18:21:36 | 000,028,624 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/02/10 18:21:34 | 000,738,768 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/02/10 18:21:34 | 000,390,608 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/02/10 18:21:34 | 000,230,864 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/02/10 18:12:56 | 000,026,112 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Monday.doc
[2011/02/10 17:46:56 | 000,133,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/10 11:12:47 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/10 10:59:10 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 10:56:17 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/10 10:47:37 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/02/09 05:22:51 | 000,050,688 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Resident Bath Preferences & Record[1].xls
[2011/02/05 15:26:48 | 000,002,201 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\FMRTE.lnk
[2011/02/03 17:44:02 | 000,026,624 | —- | M] () – C:\Documents and Settings\Owner\My Documents\266349_cv current 3[1].doc
[2011/01/26 21:52:14 | 000,069,632 | RHS- | M] () – C:\WINDOWS\System32\CatRootf.dll
[2011/01/26 17:14:50 | 007,586,816 | —- | M] () – C:\Documents and Settings\Owner\My Documents\1st Choice Pre Jan 2011 vista[1].ppt
[2011/01/21 14:44:37 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2011/01/21 14:44:37 | 000,439,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/12 15:22:22 | 000,000,120 | —- | C] () – C:\WINDOWS\System32\drivers\kgpfr2.cfg
[2011/02/12 13:44:10 | 000,000,240 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/02/12 12:35:17 | 000,000,210 | —- | C] () – C:\Boot.bak
[2011/02/12 12:35:13 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/02/12 12:33:59 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/02/12 12:33:59 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/02/12 12:33:59 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/02/12 12:33:59 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/02/10 18:12:56 | 000,026,112 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Monday.doc
[2011/02/10 10:59:10 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 10:56:17 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/09 05:22:51 | 000,050,688 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Resident Bath Preferences & Record[1].xls
[2011/02/03 17:44:02 | 000,026,624 | —- | C] () – C:\Documents and Settings\Owner\My Documents\266349_cv current 3[1].doc
[2011/01/26 21:52:14 | 000,069,632 | RHS- | C] () – C:\WINDOWS\System32\CatRootf.dll
[2011/01/26 21:52:14 | 000,000,310 | -HS- | C] () – C:\WINDOWS\tasks\Octomntob.job
[2011/01/26 17:14:50 | 007,586,816 | —- | C] () – C:\Documents and Settings\Owner\My Documents\1st Choice Pre Jan 2011 vista[1].ppt
[2010/12/12 17:28:17 | 000,124,362 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1547161642-115176313-725345543-1003-0.dat
[2010/12/03 12:24:56 | 000,124,362 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/07/27 16:13:12 | 000,078,344 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/06/21 09:35:58 | 000,000,022 | —- | C] () – C:\WINDOWS\FLASHKSK.INI
[2010/06/21 09:35:57 | 000,000,468 | —- | C] () – C:\WINDOWS\LXBRFMT.INI
[2010/06/21 09:35:55 | 000,003,206 | —- | C] () – C:\WINDOWS\LXBRCAH.ini
[2010/06/21 09:35:53 | 000,002,178 | —- | C] () – C:\WINDOWS\System32\LXBRSET.INI
[2010/06/21 09:34:00 | 000,000,324 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/06/21 09:33:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbrvs.dll
[2010/06/21 09:32:53 | 000,000,181 | —- | C] () – C:\WINDOWS\System32\lxbrcoin.ini
[2010/06/19 11:04:39 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/06/13 17:50:43 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2010/06/08 17:05:18 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\slextspk.dll
[2010/06/08 17:05:18 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\SLGen.dll
[2010/06/08 17:03:30 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/06/08 16:28:52 | 000,046,592 | —- | C] () – C:\WINDOWS\System32\asfrench.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asrussian.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asgerman.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\aseng.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\askorean.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\asjapan.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\ASCHT.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\aschs.dll
[2010/06/08 16:28:52 | 000,010,496 | —- | C] () – C:\WINDOWS\System32\ATKOSDMini.DLL
[2010/06/08 16:28:52 | 000,000,018 | —- | C] () – C:\WINDOWS\System32\atkid.ini
[2006/08/11 13:45:20 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 13:43:10 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/08/11 13:43:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/11 13:43:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/08/11 13:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/11 13:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/08/11 13:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/03 16:44:54 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2003/07/02 16:04:32 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\coinst.dll
[1999/01/22 10:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2011/02/12 11:57:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/19 08:30:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/06/19 11:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2011/02/12 15:22:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/12/19 08:55:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/28 12:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar
[2010/11/28 12:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar Experience Image Manager
[2010/06/15 18:02:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG9
[2010/07/11 10:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\My Games
[2010/11/05 10:43:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sports Interactive
[2011/02/12 14:35:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2010/06/19 12:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Search
[2011/02/12 13:42:59 | 000,000,310 | -HS- | M] () – C:\WINDOWS\Tasks\Octomntob.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/06/08 16:17:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/14 08:54:54 | 000,000,210 | —- | M] () – C:\Boot.bak
[2011/02/12 12:35:17 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2010/06/08 16:17:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/06/13 18:30:28 | 000,000,040 | —- | M] () – C:\CTJINI.INI
[2010/06/13 18:30:43 | 000,001,319 | —- | M] () – C:\drvpnp.dat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/06/08 16:17:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/08 16:17:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/06/13 12:55:08 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/12 13:42:51 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/06/13 18:30:41 | 000,000,657 | —- | M] () – C:\pnpID.dat
[2011/02/11 13:49:12 | 000,038,528 | —- | M] () – C:\TDSSKiller.2.4.17.0_11.02.2011_13.48.35_log.txt
[2011/02/11 13:50:07 | 000,038,528 | —- | M] () – C:\TDSSKiller.2.4.17.0_11.02.2011_13.49.41_log.txt
[2010/06/13 18:33:10 | 000,000,091 | —- | M] () – C:\temp.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/06/08 16:17:04 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/07/29 09:45:10 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBRPP5C.DLL
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/09/22 17:10:37 | 000,001,666 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/06/08 17:00:49 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/06/08 17:00:49 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/06/08 17:00:49 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/06/13 12:59:53 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/06/13 13:10:29 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/06/08 16:23:31 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2010/10/16 09:49:31 | 023,458,816 | —- | M] () – C:\Documents and Settings\Owner\My Documents\242.exe
[2010/06/19 12:37:21 | 000,889,416 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\dotNetFx40_Full_setup.exe
[2010/11/20 10:22:01 | 180,137,984 | —- | M] () – C:\Documents and Settings\Owner\My Documents\fm2011v11.1.1_pc_dit_patch.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/06/13 13:10:29 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Owner\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/12 15:22:29 | 000,065,536 | —- | M] () – C:\Documents and Settings\Owner\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-10 11:12:47

========== Alternate Data Streams ==========

@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E

< End of report >


no extras report and the other scan found no threats
  • Please download Rootkit Unhooker and save it to your desktop.
    Link 1

  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"







Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\CatRootf.dll
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

  • Please provide the results from the scans in your next reply.




Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *avg*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI