This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

urlfraudcheck redirect

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I am very unskilled at computers. But I believe I'm infected with the urlfraudcheck because I see it pop up in the address bar, as well as jump.com and city search and a million other sites I am being redirected to. i have run Malware amillion times it doesn't pick up anything. I cannot get Windows updates because it says unable to display that webpage. My Norton picks up nothing. Can you help me? I've downloade Hijack this…do I post the log? Have NEVER done anything like this. Thanks, Kitten
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Thank you so much for your help. Again I appologize for my less than adequate skills. I dowloaded the TDSS killer. Ran it. It found a win 32 tdss. something…and I selected the cure option and rebooted. But I got so far as looking for the saved "log" and I can't locate it. Not because it's not there..but because I'm not sure where or how to locate it from c/???If you could briefly walk me through where this log is..I will post it straight away. Sorry. I have second laptop…so I guess I could work on step2. Thanks, Kitten
It should be something similar to C:\TDSSKiller.2.4.17.0_11.02.2011_13.48.35_log.txt

Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Ahh I see. 2011/02/13 17:20:18.0531 0376 TDSS rootkit removing tool 2.4.17.0 Feb 10 2011 11:07:20 2011/02/13 17:20:20.0531 0376 ================================================================================ 2011/02/13 17:20:20.0531 0376 SystemInfo: 2011/02/13 17:20:20.0531 0376 2011/02/13 17:20:20.0531 0376 OS Version: 5.1.2600 ServicePack: 3.0 2011/02/13 17:20:20.0531 0376 Product type: Workstation 2011/02/13 17:20:20.0531 0376 ComputerName: OWNER-0520282D7 2011/02/13 17:20:20.0531 0376 UserName: Administrator 2011/02/13 17:20:20.0531 0376 Windows directory: C:\WINDOWS 2011/02/13 17:20:20.0531 0376 System windows directory: C:\WINDOWS 2011/02/13 17:20:20.0531 0376 Processor architecture: Intel x86 2011/02/13 17:20:20.0531 0376 Number of processors: 2 2011/02/13 17:20:20.0531 0376 Page size: 0x1000 2011/02/13 17:20:20.0531 0376 Boot type: Normal boot 2011/02/13 17:20:20.0531 0376 ================================================================================ 2011/02/13 17:20:22.0656 0376 Initialize success 2011/02/13 17:20:30.0187 3616 ================================================================================ 2011/02/13 17:20:30.0187 3616 Scan started 2011/02/13 17:20:30.0187 3616 Mode: Manual; 2011/02/13 17:20:30.0187 3616 ================================================================================ 2011/02/13 17:20:31.0546 3616 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/02/13 17:20:31.0593 3616 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 2011/02/13 17:20:31.0656 3616 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/02/13 17:20:31.0718 3616 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2011/02/13 17:20:31.0937 3616 AmdK8 (efbb0956baed786e137351b5ca272aef) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 2011/02/13 17:20:32.0000 3616 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS 2011/02/13 17:20:32.0218 3616 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/02/13 17:20:32.0265 3616 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/02/13 17:20:32.0437 3616 ati2mtag (ec2743bf722d4356375a0a01b69a81e0) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/02/13 17:20:32.0656 3616 atiide (1842b56b3d3f195c36f62708d266b95e) C:\WINDOWS\system32\DRIVERS\atiide.sys 2011/02/13 17:20:32.0718 3616 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/02/13 17:20:32.0765 3616 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/02/13 17:20:32.0828 3616 BCM43XX (b89bcf0a25aeb3b47030ac83287f894a) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 2011/02/13 17:20:32.0984 3616 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/02/13 17:20:33.0296 3616 BHDrvx86 (83a2fec59a0a0fc73bf6598e901b2fbd) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys 2011/02/13 17:20:33.0453 3616 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/02/13 17:20:33.0531 3616 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/02/13 17:20:33.0625 3616 ccHP (e941e709847fa00e0dd6d58d2b8fb5e1) C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys 2011/02/13 17:20:33.0796 3616 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/02/13 17:20:33.0906 3616 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/02/13 17:20:33.0968 3616 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/02/13 17:20:34.0031 3616 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2011/02/13 17:20:34.0140 3616 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2011/02/13 17:20:34.0281 3616 datunidr (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\datunidr.sys 2011/02/13 17:20:34.0328 3616 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/02/13 17:20:34.0390 3616 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/02/13 17:20:34.0531 3616 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/02/13 17:20:34.0578 3616 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/02/13 17:20:34.0640 3616 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/02/13 17:20:34.0687 3616 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/02/13 17:20:34.0796 3616 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 2011/02/13 17:20:34.0843 3616 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 2011/02/13 17:20:34.0921 3616 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/02/13 17:20:34.0984 3616 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/02/13 17:20:35.0171 3616 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/02/13 17:20:35.0218 3616 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 2011/02/13 17:20:35.0296 3616 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/02/13 17:20:35.0375 3616 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/02/13 17:20:35.0515 3616 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/02/13 17:20:35.0578 3616 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/02/13 17:20:35.0609 3616 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/02/13 17:20:35.0656 3616 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 2011/02/13 17:20:35.0703 3616 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/02/13 17:20:35.0796 3616 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/02/13 17:20:35.0890 3616 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/02/13 17:20:36.0000 3616 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys 2011/02/13 17:20:36.0187 3616 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys 2011/02/13 17:20:36.0234 3616 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/02/13 17:20:36.0328 3616 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/02/13 17:20:36.0750 3616 IDSxpx86 (0308238c582a55d83d34feee39542793) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110211.002\IDSxpx86.sys 2011/02/13 17:20:36.0890 3616 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/02/13 17:20:36.0984 3616 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/02/13 17:20:37.0031 3616 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/02/13 17:20:37.0062 3616 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/02/13 17:20:37.0109 3616 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/02/13 17:20:37.0234 3616 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/02/13 17:20:37.0265 3616 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/02/13 17:20:37.0312 3616 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/02/13 17:20:37.0359 3616 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/02/13 17:20:37.0390 3616 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/02/13 17:20:37.0468 3616 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/02/13 17:20:37.0625 3616 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/02/13 17:20:37.0718 3616 MBAMSwissArmy (d68e165c3123aba3b1282eddb4213bd8) C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2011/02/13 17:20:37.0765 3616 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 2011/02/13 17:20:37.0828 3616 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys 2011/02/13 17:20:37.0859 3616 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/02/13 17:20:38.0015 3616 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/02/13 17:20:38.0046 3616 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/02/13 17:20:38.0093 3616 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/02/13 17:20:38.0156 3616 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/02/13 17:20:38.0203 3616 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys 2011/02/13 17:20:38.0328 3616 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/02/13 17:20:38.0406 3616 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/02/13 17:20:38.0546 3616 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/02/13 17:20:38.0625 3616 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/02/13 17:20:38.0656 3616 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/02/13 17:20:38.0671 3616 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/02/13 17:20:38.0718 3616 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/02/13 17:20:38.0750 3616 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/02/13 17:20:38.0796 3616 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/02/13 17:20:38.0953 3616 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/02/13 17:20:39.0250 3616 NAVENG (c8ef74e4d8105b1d02d58ea4734cf616) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVENG.SYS 2011/02/13 17:20:39.0312 3616 NAVEX15 (94b3164055d821a62944d9fe84036470) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVEX15.SYS 2011/02/13 17:20:39.0484 3616 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/02/13 17:20:39.0531 3616 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/02/13 17:20:39.0578 3616 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/02/13 17:20:39.0609 3616 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/02/13 17:20:39.0656 3616 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/02/13 17:20:39.0687 3616 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/02/13 17:20:39.0890 3616 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/02/13 17:20:39.0937 3616 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/02/13 17:20:39.0984 3616 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/02/13 17:20:40.0046 3616 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/02/13 17:20:40.0140 3616 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/02/13 17:20:40.0218 3616 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/02/13 17:20:40.0281 3616 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/02/13 17:20:40.0390 3616 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 2011/02/13 17:20:40.0437 3616 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/02/13 17:20:40.0484 3616 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/02/13 17:20:40.0546 3616 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/02/13 17:20:40.0593 3616 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/02/13 17:20:40.0734 3616 PCLEPCI (1bebe7de8508a02650cdce45c664c2a2) C:\WINDOWS\system32\drivers\pclepci.sys 2011/02/13 17:20:40.0859 3616 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/02/13 17:20:41.0078 3616 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/02/13 17:20:41.0109 3616 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/02/13 17:20:41.0140 3616 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/02/13 17:20:41.0312 3616 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/02/13 17:20:41.0421 3616 PTproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys 2011/02/13 17:20:41.0625 3616 PxHelp20 (617accada2e0a0f43ec6030bbac49513) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/02/13 17:20:41.0765 3616 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/02/13 17:20:41.0828 3616 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/02/13 17:20:41.0859 3616 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/02/13 17:20:41.0890 3616 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/02/13 17:20:42.0046 3616 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/02/13 17:20:42.0093 3616 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/02/13 17:20:42.0140 3616 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/02/13 17:20:42.0187 3616 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/02/13 17:20:42.0265 3616 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/02/13 17:20:42.0406 3616 rimmptsk (d85e3fa9f5b1f29bb4ed185c450d1470) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 2011/02/13 17:20:42.0562 3616 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/02/13 17:20:42.0578 3616 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/02/13 17:20:42.0625 3616 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 2011/02/13 17:20:42.0703 3616 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/02/13 17:20:42.0828 3616 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 2011/02/13 17:20:42.0906 3616 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys 2011/02/13 17:20:42.0937 3616 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys 2011/02/13 17:20:42.0968 3616 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/02/13 17:20:43.0031 3616 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/02/13 17:20:43.0093 3616 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/02/13 17:20:43.0250 3616 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/02/13 17:20:43.0406 3616 SRTSP (ec5c3c6260f4019b03dfaa03ec8cbf6a) C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS 2011/02/13 17:20:43.0515 3616 SRTSPX (55d5c37ed41231e3ac2063d16df50840) C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS 2011/02/13 17:20:43.0609 3616 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/02/13 17:20:43.0812 3616 STHDA (951801dfb54d86f611f0af47825476f9) C:\WINDOWS\system32\drivers\sthda.sys 2011/02/13 17:20:43.0953 3616 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/02/13 17:20:43.0984 3616 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/02/13 17:20:44.0109 3616 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/02/13 17:20:44.0343 3616 SymDS (56890bf9d9204b93042089d4b45ae671) C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS 2011/02/13 17:20:44.0531 3616 SymEFA (1c91df5188150510a6f0cf78f7d94b69) C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS 2011/02/13 17:20:44.0656 3616 SymEvent (961b48b86f94d4cc8ceb483f8aa89374) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2011/02/13 17:20:44.0718 3616 SymIRON (dc80fbf0a348e54853ef82eed4e11e35) C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS 2011/02/13 17:20:44.0921 3616 SYMTDI (41aad61f87ca8e3b5d0f7fe7fba0797d) C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS 2011/02/13 17:20:45.0140 3616 SynTP (fa2daa32bed908023272a0f77d625dae) C:\WINDOWS\system32\DRIVERS\SynTP.sys 2011/02/13 17:20:45.0203 3616 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/02/13 17:20:45.0281 3616 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/02/13 17:20:45.0437 3616 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/02/13 17:20:45.0500 3616 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/02/13 17:20:45.0562 3616 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/02/13 17:20:45.0640 3616 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/02/13 17:20:45.0781 3616 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/02/13 17:20:45.0937 3616 USB28xxBGA (9b01ce1eda6ad1acfd4f865d6cb0a790) C:\WINDOWS\system32\DRIVERS\emBDA.sys 2011/02/13 17:20:45.0984 3616 USB28xxOEM (c93e4f6bd1cbd163662e7c9be021b895) C:\WINDOWS\system32\DRIVERS\emOEM.sys 2011/02/13 17:20:46.0015 3616 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/02/13 17:20:46.0062 3616 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/02/13 17:20:46.0187 3616 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/02/13 17:20:46.0218 3616 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 2011/02/13 17:20:46.0265 3616 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/02/13 17:20:46.0296 3616 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/02/13 17:20:46.0328 3616 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/02/13 17:20:46.0484 3616 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/02/13 17:20:46.0546 3616 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/02/13 17:20:46.0625 3616 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/02/13 17:20:46.0703 3616 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 2011/02/13 17:20:46.0890 3616 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 2011/02/13 17:20:46.0937 3616 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 2011/02/13 17:20:46.0984 3616 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/02/13 17:20:47.0031 3616 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/02/13 17:20:47.0062 3616 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/02/13 17:20:47.0125 3616 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/02/13 17:20:47.0125 3616 ================================================================================ 2011/02/13 17:20:47.0125 3616 Scan finished 2011/02/13 17:20:47.0125 3616 ================================================================================ 2011/02/13 17:20:47.0140 4136 Detected object count: 1 2011/02/13 17:21:26.0328 4136 \HardDisk0 - will be cured after reboot
I started the OTL thing, but i realized as I was entering all the "custom scan" stuff….the scan had already started! pfft! So I'm not sure whether to post the logs as they are or re-run the whole scan because I probably messed it up by not having the right values entered BEFORE the scan commenced?
This is the first run. Without re-running it.

OTL logfile created on: 2/13/2011 17:51:51 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 26.41 Gb Free Space | 35.44% Space Free | Partition Type: NTFS
Drive E: | 243.69 Mb Total Space | 118.16 Mb Free Space | 48.49% Space Free | Partition Type: FAT

Computer Name: OWNER-0520282D7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/13 17:49:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2010/12/18 11:51:21 | 002,424,560 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2010/01/13 08:49:21 | 000,124,816 | —- | M] (KeenHigh Tech.) – C:\Program Files\Philips\GoGear Mix Device Manager\main.exe
PRC - [2009/05/21 11:13:58 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/28 08:58:26 | 000,094,208 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqserv.exe
PRC - [2009/02/03 06:15:18 | 000,111,856 | —- | M] (Yahoo! Inc) – C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/06/05 15:06:32 | 000,125,208 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/27 08:04:28 | 000,656,040 | —- | M] () – C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe
PRC - [2008/03/27 08:04:22 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark Z2400 Series\lxdqmsdmon.exe
PRC - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) – C:\WINDOWS\system32\lxdqcoms.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | —- | M] (SigmaTel, Inc.) – C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2006/06/09 12:47:52 | 000,047,104 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\system32\ico.exe
PRC - [2005/07/22 19:33:48 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PRC - [2003/06/25 11:24:48 | 000,049,152 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe


========== Modules (SafeList) ==========

MOD - [2011/02/13 17:49:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
MOD - [2010/09/20 12:26:01 | 000,415,088 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll
MOD - [2010/08/23 09:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 01:02:02 | 000,653,120 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll
MOD - [2009/07/12 01:02:00 | 000,569,664 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe – (N360)
SRV - [2009/04/28 08:58:26 | 000,094,208 | —- | M] () [Auto | Running] – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdqserv.exe – (lxdqCATSCustConnectService)
SRV - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) [Auto | Running] – C:\WINDOWS\System32\lxdqcoms.exe – (lxdq_device)
SRV - [2007/10/11 10:49:46 | 000,076,016 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe – (DellAMBrokerService)
SRV - [2007/03/19 13:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)


========== Driver Services (SafeList) ==========

DRV - [2010/12/16 16:06:00 | 001,360,760 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVEX15.SYS – (NAVEX15)
DRV - [2010/12/16 16:06:00 | 000,086,008 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVENG.SYS – (NAVENG)
DRV - [2010/11/26 18:51:08 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/11/26 01:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2010/11/26 01:00:00 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/11/22 23:47:46 | 000,341,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110211.002\IDSXpx86.sys – (IDSxpx86)
DRV - [2010/11/22 19:20:07 | 000,691,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys – (BHDrvx86)
DRV - [2010/05/10 11:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/05/05 21:01:59 | 000,361,904 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS – (SYMTDI)
DRV - [2010/04/28 22:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS – (SymIRON)
DRV - [2010/04/21 20:02:20 | 000,173,104 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS – (SymEFA)
DRV - [2010/04/21 19:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS – (SRTSP)
DRV - [2010/04/21 19:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 17:22:57 | 000,501,888 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys – (ccHP)
DRV - [2010/02/17 11:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/10/14 20:50:05 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS – (SymDS)
DRV - [2008/04/13 11:46:22 | 000,015,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mpe.sys – (MPE)
DRV - [2008/04/13 09:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/12/04 22:26:40 | 002,782,208 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2007/08/23 19:29:10 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\datunidr.sys – (datunidr)
DRV - [2007/05/10 10:24:34 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/03/16 18:10:56 | 000,604,928 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2007/01/29 19:20:04 | 000,361,728 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2007/01/29 19:19:48 | 000,039,680 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2006/11/15 01:16:24 | 000,032,256 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2006/10/05 18:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys – (PTproct)
DRV - [2006/09/13 19:41:46 | 000,003,456 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\atiide.sys – (atiide)
DRV - [2006/07/01 22:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2006/03/08 12:35:10 | 000,191,872 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2005/12/01 01:40:56 | 000,936,960 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2005/12/01 01:40:12 | 000,192,512 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2005/12/01 01:40:08 | 000,669,696 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2005/02/09 10:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Pclepci.sys – (PCLEPCI)


========== Standard Registry (SafeList) ==========
Here's the other:

OTL Extras logfile created on: 2/13/2011 17:51:51 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 26.41 Gb Free Space | 35.44% Space Free | Partition Type: NTFS
Drive E: | 243.69 Mb Total Space | 118.16 Mb Free Space | 48.49% Space Free | Partition Type: FAT

Computer Name: OWNER-0520282D7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Grisoft\AVG Free\avginet.exe" = C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe" = C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe
"C:\Program Files\Grisoft\AVG Free\avgcc.exe" = C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\WINDOWS\system32\lxdqcoms.exe" = C:\WINDOWS\system32\lxdqcoms.exe:*:Enabled:Z2400 Series Server – ( )
"C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe" = C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\Documents and Settings\Administrator\Local Settings\Temp\lxdq\wireless\lxdqwpss.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\lxdq\wireless\lxdqwpss.exe:*:Enabled:
"C:\WINDOWS\system32\lxdqcfg.exe" = C:\WINDOWS\system32\lxdqcfg.exe:*:Enabled:Printer Communication System – ( )
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqtime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqtime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqwbgw.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqwbgw.exe:*:Enabled:Lexmark Web Gateway – ()
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0305052F-141B-FCEC-62B2-FB5668E7933E}" = Catalyst Control Center Graphics Full New
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0B26A979-EC68-4624-A647-98A506CEE048}" = GoGear Mix Device Manager
"{123F407A-BAD1-425F-9C17-334FB6DDC339}" = GoGear Mix Device Manager
"{16BE87BC-69F5-4D36-8CF0-E1CB3ACD5ED3}" = HP Driver Diagnostics
"{19754346-BF3D-F1FC-9AF3-B84C216E93D7}" = Catalyst Control Center Graphics Full Existing
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 23
"{296554E6-A322-EEC8-2185-DF6E624CA990}" = Skins
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{39F55A85-B356-64D7-F2BC-1E6C70A73FB8}" = CCC Help English
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{690BE098-6D0D-493D-B079-BD7E8F81A141}" = Opera 10.10
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{771221C5-FD0B-1197-355C-B2AFAA860483}" = ccc-core-preinstall
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{882EE1CB-C2FB-657F-AA98-7DC91FC72447}" = Catalyst Control Center Core Implementation
"{89D2879E-F327-3B5F-F7C6-6E107C816671}" = ccc-utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FD66F0B-38FF-4834-88FF-56DC214A62ED}" = hp deskjet 5800
"{90E00409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Outlook 2003
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.6
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BF13AA9D-E4CE-4015-9778-ECC1D4FB06E4}" = Mouse Suite for Laptop Computers
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C4B7FD4E-6AFD-AE07-FB7E-B9AB9B39232E}" = ccc-core-static
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C7EC0699-D82C-4451-B701-C98C330D43AF}" = hp deskjet 3500
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D13D0C87-46BA-E646-BC40-C7B0D305A75F}" = Catalyst Control Center Graphics Previews Common
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}" = Pinnacle TVCenter Pro
"{F40F05BE-47BB-72E2-4064-078B69F39BDA}" = Catalyst Control Center Graphics Light
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"Amazing Slow Downer" = Amazing Slow Downer (remove only)
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"ATI Display Driver" = ATI Display Driver
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"conduitEngine" = Conduit Engine
"ExpressBurn" = Express Burn Disc Burning Software
"ExpressRip" = Express Rip
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Lexmark Z2400 Series" = Lexmark Z2400 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"N360" = Norton Security Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Soft32 Toolbar" = Soft32 Toolbar
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WavePad" = WavePad Sound Editor
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Mail Advisor" = Yahoo! Mail Advisor
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/13/2011 18:54:47 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/13/2011 18:54:47 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/13/2011 18:54:47 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/13/2011 19:04:55 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/13/2011 19:04:56 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/13/2011 20:19:29 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/13/2011 20:19:29 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/13/2011 20:19:29 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/13/2011 20:19:30 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/13/2011 20:19:30 | Computer Name = OWNER-0520282D7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 2/13/2011 14:51:36 | Computer Name = OWNER-0520282D7 | Source = DCOM | ID = 10010
Description = The server {3C16E079-E4C7-493C-BE9F-E0F2BB0B7430} did not register
with DCOM within the required timeout.

Error - 2/13/2011 15:01:40 | Computer Name = OWNER-0520282D7 | Source = Schedule | ID = 7901
Description = The At12.job command failed to start due to the following error: %%2147942405

Error - 2/13/2011 15:55:00 | Computer Name = OWNER-0520282D7 | Source = Schedule | ID = 7901
Description = The At13.job command failed to start due to the following error: %%2147942405

Error - 2/13/2011 16:55:00 | Computer Name = OWNER-0520282D7 | Source = Schedule | ID = 7901
Description = The At14.job command failed to start due to the following error: %%2147942405

Error - 2/13/2011 17:55:00 | Computer Name = OWNER-0520282D7 | Source = Schedule | ID = 7901
Description = The At16.job command failed to start due to the following error: %%2147942405

Error - 2/13/2011 18:55:00 | Computer Name = OWNER-0520282D7 | Source = Schedule | ID = 7901
Description = The At15.job command failed to start due to the following error: %%2147942405

Error - 2/13/2011 19:55:00 | Computer Name = OWNER-0520282D7 | Source = Schedule | ID = 7901
Description = The At17.job command failed to start due to the following error: %%2147942405

Error - 2/13/2011 20:26:00 | Computer Name = OWNER-0520282D7 | Source = ati2mtag | ID = 45062
Description = CRT invalid display type

Error - 2/13/2011 20:28:31 | Computer Name = OWNER-0520282D7 | Source = ati2mtag | ID = 45062
Description = CRT invalid display type

Error - 2/13/2011 20:55:00 | Computer Name = OWNER-0520282D7 | Source = Schedule | ID = 7901
Description = The At18.job command failed to start due to the following error: %%2147942405


< End of report >
No, and I didn't save it into a seperate folder for repasting? Is there any chance it would be saved somewhere. I looked in my c drive like before and I didn't find anything like the last time.
I don't know if this is the full thing

OTL logfile created on: 2/13/2011 17:51:51 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 26.41 Gb Free Space | 35.44% Space Free | Partition Type: NTFS
Drive E: | 243.69 Mb Total Space | 118.16 Mb Free Space | 48.49% Space Free | Partition Type: FAT

Computer Name: OWNER-0520282D7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/13 17:49:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2010/12/18 11:51:21 | 002,424,560 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2010/01/13 08:49:21 | 000,124,816 | —- | M] (KeenHigh Tech.) – C:\Program Files\Philips\GoGear Mix Device Manager\main.exe
PRC - [2009/05/21 11:13:58 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/28 08:58:26 | 000,094,208 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqserv.exe
PRC - [2009/02/03 06:15:18 | 000,111,856 | —- | M] (Yahoo! Inc) – C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/06/05 15:06:32 | 000,125,208 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/27 08:04:28 | 000,656,040 | —- | M] () – C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe
PRC - [2008/03/27 08:04:22 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark Z2400 Series\lxdqmsdmon.exe
PRC - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) – C:\WINDOWS\system32\lxdqcoms.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | —- | M] (SigmaTel, Inc.) – C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2006/06/09 12:47:52 | 000,047,104 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\system32\ico.exe
PRC - [2005/07/22 19:33:48 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PRC - [2003/06/25 11:24:48 | 000,049,152 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe


========== Modules (SafeList) ==========

MOD - [2011/02/13 17:49:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
MOD - [2010/09/20 12:26:01 | 000,415,088 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll
MOD - [2010/08/23 09:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 01:02:02 | 000,653,120 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll
MOD - [2009/07/12 01:02:00 | 000,569,664 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe – (N360)
SRV - [2009/04/28 08:58:26 | 000,094,208 | —- | M] () [Auto | Running] – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdqserv.exe – (lxdqCATSCustConnectService)
SRV - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) [Auto | Running] – C:\WINDOWS\System32\lxdqcoms.exe – (lxdq_device)
SRV - [2007/10/11 10:49:46 | 000,076,016 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe – (DellAMBrokerService)
SRV - [2007/03/19 13:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)


========== Driver Services (SafeList) ==========

DRV - [2010/12/16 16:06:00 | 001,360,760 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVEX15.SYS – (NAVEX15)
DRV - [2010/12/16 16:06:00 | 000,086,008 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVENG.SYS – (NAVENG)
DRV - [2010/11/26 18:51:08 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/11/26 01:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2010/11/26 01:00:00 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/11/22 23:47:46 | 000,341,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110211.002\IDSXpx86.sys – (IDSxpx86)
DRV - [2010/11/22 19:20:07 | 000,691,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys – (BHDrvx86)
DRV - [2010/05/10 11:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/05/05 21:01:59 | 000,361,904 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS – (SYMTDI)
DRV - [2010/04/28 22:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS – (SymIRON)
DRV - [2010/04/21 20:02:20 | 000,173,104 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS – (SymEFA)
DRV - [2010/04/21 19:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS – (SRTSP)
DRV - [2010/04/21 19:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 17:22:57 | 000,501,888 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys – (ccHP)
DRV - [2010/02/17 11:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/10/14 20:50:05 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS – (SymDS)
DRV - [2008/04/13 11:46:22 | 000,015,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mpe.sys – (MPE)
DRV - [2008/04/13 09:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/12/04 22:26:40 | 002,782,208 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2007/08/23 19:29:10 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\datunidr.sys – (datunidr)
DRV - [2007/05/10 10:24:34 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/03/16 18:10:56 | 000,604,928 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2007/01/29 19:20:04 | 000,361,728 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2007/01/29 19:19:48 | 000,039,680 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2006/11/15 01:16:24 | 000,032,256 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2006/10/05 18:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys – (PTproct)
DRV - [2006/09/13 19:41:46 | 000,003,456 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\atiide.sys – (atiide)
DRV - [2006/07/01 22:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2006/03/08 12:35:10 | 000,191,872 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2005/12/01 01:40:56 | 000,936,960 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2005/12/01 01:40:12 | 000,192,512 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2005/12/01 01:40:08 | 000,669,696 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2005/02/09 10:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Pclepci.sys – (PCLEPCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://my.yahoo.com/
IE - HKCU\..\URLSearchHook: {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="
FF - prefs.js..browser.startup.homepage: "http://www.myyahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {d1fce654-5fd1-48ad-b13c-5064736120b7}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/11/27 10:11:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/11/26 18:52:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/22 11:21:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/22 11:21:11 | 000,000,000 | —D | M]

[2010/08/30 11:35:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/02/13 13:11:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions
[2010/11/27 14:50:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/13 09:09:41 | 000,000,000 | —D | M] (Soft32 Community Toolbar) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions\{d1fce654-5fd1-48ad-b13c-5064736120b7}
[2010/05/26 14:18:50 | 000,002,333 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\searchplugins\askcom.xml
[2010/11/25 14:40:31 | 000,001,919 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\searchplugins\bing-zugo.xml
[2011/02/13 13:11:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/14 06:14:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/26 07:59:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/13 12:27:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/26 18:52:22 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN
[2010/11/27 10:11:43 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
[2008/12/23 21:36:41 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/01/07 08:52:26 | 000,001,003 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.8minutedating.com
O1 - Hosts: 127.0.0.1 whysohardx.com
O1 - Hosts: 127.0.0.1 protectyourpc-11.com
O1 - Hosts: 127.0.0.1 checkserverstatux.com
O1 - Hosts: 127.0.0.1 xinmin.cn
O1 - Hosts: 127.0.0.1 xy95.cn
O1 - Hosts: 127.0.0.1 koralda.com
O1 - Hosts: 127.0.0.1 weirden.com
O1 - Hosts: 127.0.0.1 nanocloudcontroller.com
O1 - Hosts: 127.0.0.1 coo0lnet.net
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Soft32 Toolbar) - {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Soft32 Toolbar) - {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Soft32 Toolbar) - {D1FCE654-5FD1-48AD-B13C-5064736120B7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [lxdqamon] C:\Program Files\Lexmark Z2400 Series\lxdqamon.exe ()
O4 - HKLM..\Run: [lxdqmon.exe] C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe ()
O4 - HKLM..\Run: [PMX Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips Device Manager.lnk = C:\Program Files\Philips\GoGear Mix Device Manager\main.exe (KeenHigh Tech.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1227671349171 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\Hp\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/01 19:45:27 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{e4dbdb18-3679-11de-be63-0015c5c8c6f3}\Shell - "" = AutoRun
O33 - MountPoints2\{e4dbdb18-3679-11de-be63-0015c5c8c6f3}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e4dbdb18-3679-11de-be63-0015c5c8c6f3}\Shell\AutoRun\command - "" = E:\ImageViewer4.exe -COPYFILE
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: attrript - (C:\WINDOWS\system32\comspgrd.dll) - File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/13 17:34:00 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/02/13 12:27:39 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/13 12:27:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/13 12:27:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/13 09:13:47 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/02/13 09:13:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\HiJackThis
[2011/02/13 09:09:14 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/02/13 09:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Soft32
[2011/02/13 09:04:15 | 000,000,000 | —D | C] – C:\Program Files\ConduitEngine
[2011/02/13 09:04:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\ConduitEngine
[2011/02/13 09:04:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Conduit
[2011/02/13 09:04:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp
[2011/02/13 09:04:11 | 000,000,000 | —D | C] – C:\Program Files\Soft32
[2011/02/13 09:02:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Soft32 Downloads
[2011/02/13 09:01:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2011/02/12 18:59:15 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2011/02/10 11:08:26 | 001,366,104 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/01/22 11:27:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/01/22 11:27:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/01/22 11:26:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/22 11:09:31 | 000,000,000 | —D | C] – C:\Config.Msi
[2009/10/15 20:32:46 | 000,409,600 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcoin.dll
[2007/11/28 14:19:08 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdqpmui.dll
[2007/11/28 14:16:04 | 001,101,824 | —- | C] ( ) – C:\WINDOWS\System32\lxdqserv.dll
[2007/11/28 14:13:38 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdqlmpm.dll
[2007/11/28 14:13:30 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdqiesc.dll
[2007/11/28 14:13:22 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcomm.dll
[2007/11/28 14:12:26 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdqhbn3.dll
[2007/11/28 14:12:08 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\lxdqusb1.dll
[2007/11/28 14:11:48 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcomc.dll
[2007/11/28 14:10:52 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdqprox.dll
[2007/11/28 14:09:32 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\lxdqhcp.dll
[2007/11/28 14:09:18 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdqinpa.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/13 17:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/02/13 17:26:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/13 17:25:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/13 17:25:25 | 2011,213,824 | -HS- | M] () – C:\hiberfil.sys
[2011/02/13 17:18:48 | 001,366,104 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/02/13 16:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/02/13 16:34:11 | 000,002,463 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/02/13 15:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2011/02/13 14:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2011/02/13 13:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2011/02/13 12:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2011/02/13 12:01:39 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/02/13 10:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/02/13 09:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/02/13 08:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/02/13 07:51:25 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/13 06:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/02/12 20:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2011/02/12 19:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2011/02/12 18:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2011/02/11 23:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2011/02/11 22:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2011/02/11 21:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2011/02/11 16:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/02/11 07:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2011/02/08 05:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/02/08 04:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/02/08 03:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/02/08 02:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/02/08 01:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/02/08 00:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/02/03 09:38:33 | 000,011,776 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/24 12:37:32 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2011/01/15 09:29:31 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/13 09:13:47 | 000,002,463 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/02/12 10:47:52 | 2011,213,824 | -HS- | C] () – C:\hiberfil.sys
[2011/01/26 19:27:05 | 004,154,392 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\102_3008.MOV
[2011/01/26 19:10:10 | 079,390,015 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\102_2708.MOV
[2010/11/08 10:12:40 | 000,000,006 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\completescan
[2010/11/08 09:57:27 | 000,000,010 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\install
[2010/09/19 12:07:05 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\lxdqrwrd.ini
[2010/09/19 12:07:00 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDQinst.dll
[2009/09/01 14:33:34 | 000,010,288 | —- | C] () – C:\WINDOWS\hpdj3500.ini
[2009/07/14 08:02:58 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdqgrd.dll
[2008/06/01 19:45:27 | 000,000,022 | —- | C] () – C:\WINDOWS\VFO.INI
[2008/03/31 18:47:44 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdqvs.dll
[2008/01/23 19:58:27 | 000,011,776 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/15 19:47:04 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/01/14 21:40:31 | 000,000,134 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2008/01/14 21:40:29 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2008/01/14 21:37:53 | 000,000,103 | —- | C] () – C:\WINDOWS\System32\hptrace.ini
[2008/01/14 21:34:26 | 000,013,099 | —- | C] () – C:\WINDOWS\hpdj5800.ini
[2008/01/06 20:45:11 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2008/01/06 09:36:30 | 000,131,014 | —- | C] () – C:\WINDOWS\System32\DellPM.ini
[2008/01/02 16:53:50 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/01/02 16:53:49 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/01/02 07:28:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2005/08/09 15:13:31 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 15:13:31 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/08/09 15:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/10/28 16:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Amazon
[2008/01/14 21:55:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Earthsim
[2010/11/28 15:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ElevatedDiagnostics
[2011/02/13 09:04:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2010/07/24 10:33:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\NCH Swift Sound
[2010/08/24 10:19:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\OpenOffice.org
[2009/11/17 11:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Opera
[2010/10/28 18:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\PCDr
[2010/05/26 08:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Roni Music
[2008/11/25 20:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2008/11/26 08:26:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Windows Search
[2008/01/14 21:55:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Earthsim
[2010/07/28 14:20:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/06/01 19:06:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/05/02 18:19:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/11/26 15:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/16 07:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/27 12:33:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/28 15:29:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/02/11 16:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/02/08 02:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/02/13 09:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2011/02/13 10:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2011/02/13 12:01:39 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2011/02/13 12:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2011/02/13 13:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2011/02/13 15:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2011/02/13 14:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2011/02/13 16:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2011/02/13 17:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2011/02/12 18:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2011/02/08 04:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/02/12 19:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2011/02/12 20:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2011/02/11 22:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2011/02/11 21:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2011/02/11 23:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2011/02/08 00:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/02/08 03:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/02/08 01:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/02/13 06:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2011/02/08 05:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2011/02/11 07:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2011/02/13 08:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2010/07/31 14:20:04 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\expressburnShakeIcon.job
[2010/07/31 14:20:05 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/01/24 12:37:32 | 000,000,298 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< netsvcs >

< drivers32 >

< %SYSTEMDRIVE%\*.* >
[2008/06/01 19:45:27 | 000,000,095 | —- | M] () – C:\AUTOEXEC.BAT
[2008/01/15 07:41:40 | 000,000,200 | -HS- | M] () – C:\boot.ini
[2008/01/02 15:47:22 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/02/13 17:25:25 | 2011,213,824 | -HS- | M] () – C:\hiberfil.sys
[2010/01/20 14:17:48 | 000,010,606 | —- | M] () – C:\hpfr3500.log
[2008/01/02 15:47:22 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/01/02 15:47:22 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/03/15 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/06/01 20:41:18 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/13 17:25:23 | 1409,286,144 | -HS- | M] () – C:\pagefile.sys
[2011/02/13 17:21:34 | 000,046,126 | —- | M] () – C:\TDSSKiller.2.4.17.0_13.02.2011_17.20.18_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/01/02 15:46:47 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/08/13 11:02:22 | 000,147,968 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdqdrpp.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/11/15 18:24:56 | 000,001,738 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< CREATERESTOREPOINT >

< %systemroot%\System32\config\*.sav >
[2008/01/02 07:26:23 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/01/02 07:26:23 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/01/02 07:26:23 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/01 20:48:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/01/06 20:38:25 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/01/02 15:53:11 | 000,000,079 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/02/13 17:18:48 | 001,366,104 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008/01/02 15:53:11 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Administrator\Favorites\Desktop.ini
[2011/02/12 12:24:06 | 000,000,388 | —- | M] () – C:\Documents and Settings\Administrator\Favorites\DOWNLOADS.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/13 17:42:23 | 001,081,344 | —- | M] () – C:\Documents and Settings\Administrator\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 13:37:24

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
Yikes, thought I was helping before, by finding the OLD txt file. But I ran the scan again. this time without all the inputs and changed variables..I'm assuming. Here's what it gave me:

OTL logfile created on: 2/13/2011 17:51:51 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 26.41 Gb Free Space | 35.44% Space Free | Partition Type: NTFS
Drive E: | 243.69 Mb Total Space | 118.16 Mb Free Space | 48.49% Space Free | Partition Type: FAT

Computer Name: OWNER-0520282D7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/13 17:49:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2010/12/18 11:51:21 | 002,424,560 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2010/01/13 08:49:21 | 000,124,816 | —- | M] (KeenHigh Tech.) – C:\Program Files\Philips\GoGear Mix Device Manager\main.exe
PRC - [2009/05/21 11:13:58 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/28 08:58:26 | 000,094,208 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqserv.exe
PRC - [2009/02/03 06:15:18 | 000,111,856 | —- | M] (Yahoo! Inc) – C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/06/05 15:06:32 | 000,125,208 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/27 08:04:28 | 000,656,040 | —- | M] () – C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe
PRC - [2008/03/27 08:04:22 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark Z2400 Series\lxdqmsdmon.exe
PRC - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) – C:\WINDOWS\system32\lxdqcoms.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | —- | M] (SigmaTel, Inc.) – C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2006/06/09 12:47:52 | 000,047,104 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\system32\ico.exe
PRC - [2005/07/22 19:33:48 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PRC - [2003/06/25 11:24:48 | 000,049,152 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe


========== Modules (SafeList) ==========

MOD - [2011/02/13 17:49:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
MOD - [2010/09/20 12:26:01 | 000,415,088 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll
MOD - [2010/08/23 09:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 01:02:02 | 000,653,120 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll
MOD - [2009/07/12 01:02:00 | 000,569,664 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe – (N360)
SRV - [2009/04/28 08:58:26 | 000,094,208 | —- | M] () [Auto | Running] – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdqserv.exe – (lxdqCATSCustConnectService)
SRV - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) [Auto | Running] – C:\WINDOWS\System32\lxdqcoms.exe – (lxdq_device)
SRV - [2007/10/11 10:49:46 | 000,076,016 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe – (DellAMBrokerService)
SRV - [2007/03/19 13:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)


========== Driver Services (SafeList) ==========

DRV - [2010/12/16 16:06:00 | 001,360,760 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVEX15.SYS – (NAVEX15)
DRV - [2010/12/16 16:06:00 | 000,086,008 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVENG.SYS – (NAVENG)
DRV - [2010/11/26 18:51:08 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/11/26 01:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2010/11/26 01:00:00 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/11/22 23:47:46 | 000,341,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110211.002\IDSXpx86.sys – (IDSxpx86)
DRV - [2010/11/22 19:20:07 | 000,691,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys – (BHDrvx86)
DRV - [2010/05/10 11:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/05/05 21:01:59 | 000,361,904 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS – (SYMTDI)
DRV - [2010/04/28 22:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS – (SymIRON)
DRV - [2010/04/21 20:02:20 | 000,173,104 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS – (SymEFA)
DRV - [2010/04/21 19:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS – (SRTSP)
DRV - [2010/04/21 19:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 17:22:57 | 000,501,888 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys – (ccHP)
DRV - [2010/02/17 11:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/10/14 20:50:05 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS – (SymDS)
DRV - [2008/04/13 11:46:22 | 000,015,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mpe.sys – (MPE)
DRV - [2008/04/13 09:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/12/04 22:26:40 | 002,782,208 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2007/08/23 19:29:10 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\datunidr.sys – (datunidr)
DRV - [2007/05/10 10:24:34 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/03/16 18:10:56 | 000,604,928 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2007/01/29 19:20:04 | 000,361,728 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2007/01/29 19:19:48 | 000,039,680 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2006/11/15 01:16:24 | 000,032,256 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2006/10/05 18:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys – (PTproct)
DRV - [2006/09/13 19:41:46 | 000,003,456 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\atiide.sys – (atiide)
DRV - [2006/07/01 22:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2006/03/08 12:35:10 | 000,191,872 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2005/12/01 01:40:56 | 000,936,960 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2005/12/01 01:40:12 | 000,192,512 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2005/12/01 01:40:08 | 000,669,696 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2005/02/09 10:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Pclepci.sys – (PCLEPCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://my.yahoo.com/
IE - HKCU\..\URLSearchHook: {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="
FF - prefs.js..browser.startup.homepage: "http://www.myyahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {d1fce654-5fd1-48ad-b13c-5064736120b7}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/11/27 10:11:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/11/26 18:52:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/22 11:21:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/22 11:21:11 | 000,000,000 | —D | M]

[2010/08/30 11:35:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/02/13 13:11:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions
[2010/11/27 14:50:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/13 09:09:41 | 000,000,000 | —D | M] (Soft32 Community Toolbar) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions\{d1fce654-5fd1-48ad-b13c-5064736120b7}
[2010/05/26 14:18:50 | 000,002,333 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\searchplugins\askcom.xml
[2010/11/25 14:40:31 | 000,001,919 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\searchplugins\bing-zugo.xml
[2011/02/13 13:11:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/14 06:14:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/26 07:59:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/13 12:27:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/26 18:52:22 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN
[2010/11/27 10:11:43 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
[2008/12/23 21:36:41 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/01/07 08:52:26 | 000,001,003 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.8minutedating.com
O1 - Hosts: 127.0.0.1 whysohardx.com
O1 - Hosts: 127.0.0.1 protectyourpc-11.com
O1 - Hosts: 127.0.0.1 checkserverstatux.com
O1 - Hosts: 127.0.0.1 xinmin.cn
O1 - Hosts: 127.0.0.1 xy95.cn
O1 - Hosts: 127.0.0.1 koralda.com
O1 - Hosts: 127.0.0.1 weirden.com
O1 - Hosts: 127.0.0.1 nanocloudcontroller.com
O1 - Hosts: 127.0.0.1 coo0lnet.net
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Soft32 Toolbar) - {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Soft32 Toolbar) - {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Soft32 Toolbar) - {D1FCE654-5FD1-48AD-B13C-5064736120B7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [lxdqamon] C:\Program Files\Lexmark Z2400 Series\lxdqamon.exe ()
O4 - HKLM..\Run: [lxdqmon.exe] C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe ()
O4 - HKLM..\Run: [PMX Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips Device Manager.lnk = C:\Program Files\Philips\GoGear Mix Device Manager\main.exe (KeenHigh Tech.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1227671349171 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\Hp\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/01 19:45:27 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{e4dbdb18-3679-11de-be63-0015c5c8c6f3}\Shell - "" = AutoRun
O33 - MountPoints2\{e4dbdb18-3679-11de-be63-0015c5c8c6f3}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e4dbdb18-3679-11de-be63-0015c5c8c6f3}\Shell\AutoRun\command - "" = E:\ImageViewer4.exe -COPYFILE
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: attrript - (C:\WINDOWS\system32\comspgrd.dll) - File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/13 17:34:00 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/02/13 12:27:39 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/13 12:27:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/13 12:27:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/13 09:13:47 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/02/13 09:13:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\HiJackThis
[2011/02/13 09:09:14 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/02/13 09:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Soft32
[2011/02/13 09:04:15 | 000,000,000 | —D | C] – C:\Program Files\ConduitEngine
[2011/02/13 09:04:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\ConduitEngine
[2011/02/13 09:04:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Conduit
[2011/02/13 09:04:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp
[2011/02/13 09:04:11 | 000,000,000 | —D | C] – C:\Program Files\Soft32
[2011/02/13 09:02:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Soft32 Downloads
[2011/02/13 09:01:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2011/02/12 18:59:15 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2011/02/10 11:08:26 | 001,366,104 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/01/22 11:27:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/01/22 11:27:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/01/22 11:26:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/22 11:09:31 | 000,000,000 | —D | C] – C:\Config.Msi
[2009/10/15 20:32:46 | 000,409,600 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcoin.dll
[2007/11/28 14:19:08 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdqpmui.dll
[2007/11/28 14:16:04 | 001,101,824 | —- | C] ( ) – C:\WINDOWS\System32\lxdqserv.dll
[2007/11/28 14:13:38 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdqlmpm.dll
[2007/11/28 14:13:30 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdqiesc.dll
[2007/11/28 14:13:22 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcomm.dll
[2007/11/28 14:12:26 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdqhbn3.dll
[2007/11/28 14:12:08 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\lxdqusb1.dll
[2007/11/28 14:11:48 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcomc.dll
[2007/11/28 14:10:52 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdqprox.dll
[2007/11/28 14:09:32 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\lxdqhcp.dll
[2007/11/28 14:09:18 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdqinpa.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/13 17:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/02/13 17:26:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/13 17:25:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/13 17:25:25 | 2011,213,824 | -HS- | M] () – C:\hiberfil.sys
[2011/02/13 17:18:48 | 001,366,104 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/02/13 16:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/02/13 16:34:11 | 000,002,463 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/02/13 15:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2011/02/13 14:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2011/02/13 13:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2011/02/13 12:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2011/02/13 12:01:39 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/02/13 10:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/02/13 09:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/02/13 08:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/02/13 07:51:25 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/13 06:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/02/12 20:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2011/02/12 19:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2011/02/12 18:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2011/02/11 23:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2011/02/11 22:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2011/02/11 21:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2011/02/11 16:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/02/11 07:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2011/02/08 05:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/02/08 04:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/02/08 03:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/02/08 02:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/02/08 01:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/02/08 00:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/02/03 09:38:33 | 000,011,776 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/24 12:37:32 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2011/01/15 09:29:31 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/13 09:13:47 | 000,002,463 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/02/12 10:47:52 | 2011,213,824 | -HS- | C] () – C:\hiberfil.sys
[2011/01/26 19:27:05 | 004,154,392 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\102_3008.MOV
[2011/01/26 19:10:10 | 079,390,015 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\102_2708.MOV
[2010/11/08 10:12:40 | 000,000,006 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\completescan
[2010/11/08 09:57:27 | 000,000,010 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\install
[2010/09/19 12:07:05 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\lxdqrwrd.ini
[2010/09/19 12:07:00 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDQinst.dll
[2009/09/01 14:33:34 | 000,010,288 | —- | C] () – C:\WINDOWS\hpdj3500.ini
[2009/07/14 08:02:58 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdqgrd.dll
[2008/06/01 19:45:27 | 000,000,022 | —- | C] () – C:\WINDOWS\VFO.INI
[2008/03/31 18:47:44 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdqvs.dll
[2008/01/23 19:58:27 | 000,011,776 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/15 19:47:04 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/01/14 21:40:31 | 000,000,134 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2008/01/14 21:40:29 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2008/01/14 21:37:53 | 000,000,103 | —- | C] () – C:\WINDOWS\System32\hptrace.ini
[2008/01/14 21:34:26 | 000,013,099 | —- | C] () – C:\WINDOWS\hpdj5800.ini
[2008/01/06 20:45:11 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2008/01/06 09:36:30 | 000,131,014 | —- | C] () – C:\WINDOWS\System32\DellPM.ini
[2008/01/02 16:53:50 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/01/02 16:53:49 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/01/02 07:28:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2005/08/09 15:13:31 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 15:13:31 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/08/09 15:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/10/28 16:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Amazon
[2008/01/14 21:55:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Earthsim
[2010/11/28 15:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ElevatedDiagnostics
[2011/02/13 09:04:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2010/07/24 10:33:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\NCH Swift Sound
[2010/08/24 10:19:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\OpenOffice.org
[2009/11/17 11:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Opera
[2010/10/28 18:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\PCDr
[2010/05/26 08:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Roni Music
[2008/11/25 20:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2008/11/26 08:26:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Windows Search
[2008/01/14 21:55:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Earthsim
[2010/07/28 14:20:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/06/01 19:06:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/05/02 18:19:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/11/26 15:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/16 07:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/27 12:33:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/28 15:29:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/02/11 16:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/02/08 02:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/02/13 09:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2011/02/13 10:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2011/02/13 12:01:39 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2011/02/13 12:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2011/02/13 13:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2011/02/13 15:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2011/02/13 14:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2011/02/13 16:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2011/02/13 17:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2011/02/12 18:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2011/02/08 04:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/02/12 19:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2011/02/12 20:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2011/02/11 22:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2011/02/11 21:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2011/02/11 23:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2011/02/08 00:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/02/08 03:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/02/08 01:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/02/13 06:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2011/02/08 05:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2011/02/11 07:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2011/02/13 08:55:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2010/07/31 14:20:04 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\expressburnShakeIcon.job
[2010/07/31 14:20:05 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/01/24 12:37:32 | 000,000,298 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< netsvcs >

< drivers32 >

< %SYSTEMDRIVE%\*.* >
[2008/06/01 19:45:27 | 000,000,095 | —- | M] () – C:\AUTOEXEC.BAT
[2008/01/15 07:41:40 | 000,000,200 | -HS- | M] () – C:\boot.ini
[2008/01/02 15:47:22 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/02/13 17:25:25 | 2011,213,824 | -HS- | M] () – C:\hiberfil.sys
[2010/01/20 14:17:48 | 000,010,606 | —- | M] () – C:\hpfr3500.log
[2008/01/02 15:47:22 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/01/02 15:47:22 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/03/15 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/06/01 20:41:18 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/13 17:25:23 | 1409,286,144 | -HS- | M] () – C:\pagefile.sys
[2011/02/13 17:21:34 | 000,046,126 | —- | M] () – C:\TDSSKiller.2.4.17.0_13.02.2011_17.20.18_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/01/02 15:46:47 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/08/13 11:02:22 | 000,147,968 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdqdrpp.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/11/15 18:24:56 | 000,001,738 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< CREATERESTOREPOINT >

< %systemroot%\System32\config\*.sav >
[2008/01/02 07:26:23 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/01/02 07:26:23 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/01/02 07:26:23 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/01 20:48:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/01/06 20:38:25 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/01/02 15:53:11 | 000,000,079 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/02/13 17:18:48 | 001,366,104 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008/01/02 15:53:11 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Administrator\Favorites\Desktop.ini
[2011/02/12 12:24:06 | 000,000,388 | —- | M] () – C:\Documents and Settings\Administrator\Favorites\DOWNLOADS.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/13 17:42:23 | 001,081,344 | —- | M] () – C:\Documents and Settings\Administrator\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 13:37:24

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
I'm just trying to get combo fix to download TO my desktop and it will only go to my download folder in my documents. I can create a desktop shortcut….but that's not the same thing. Before I run the thing……Am I downloading it wrong, or does the program itself NEED to be on the desktop? Arghhh. I could CHOOSE where TDSSKiller was going to download to…but because the combo fix is an executable file it automatically starts downlowding the thing? Am I doing it wrong?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI