This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

need help, pc freezing....

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

these are the logs of the OTL tool….

OTL Extras logfile created on: 2/28/2011 2:28:10 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\Maritza\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.78 Gb Total Space | 196.26 Gb Free Space | 84.31% Space Free | Partition Type: NTFS

Computer Name: MARITZA-454EDBC | User Name: Maritza | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"9322:TCP" = 9322:TCP:*:Enabled:EKDiscovery
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare – (MusicLab, LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" = C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe:*:Enabled:Kodak.AiO.HomeCenter – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Center\Kodak.Statistics.exe" = C:\Program Files\Kodak\AiO\Center\Kodak.Statistics.exe:*:Enabled:Kodak.AiO.Statistics – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe" = C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe:*:Enabled:Kodak.AiO.SetupUtility – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Firmware\KodakAiOUpdater.exe" = C:\Program Files\Kodak\AiO\Firmware\KodakAiOUpdater.exe:*:Enabled:Kodak.AiO.FwUpdater – (Eastman Kodak Company)
"C:\Documents and Settings\All Users\Application Data\Kodak\Installer\Setup.exe" = C:\Documents and Settings\All Users\Application Data\Kodak\Installer\Setup.exe:*:Enabled:Kodak.AiO.Installer – (KODAK)
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare – (MusicLab, LLC)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{29A41D4C-4843-121B-967E-E6598ED10D90}" = Quick Hit - Football
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support
"{5F624839-947D-46EA-BD63-FD847C1AC6F1}" = BearShare
"{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar
"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6DC8FA3F-8FFF-4B61-B90E-807D46A3539A}" = SymNet
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74AAE0C4-991F-4000-8D00-1B4B5A8A9A81}" = Mirar
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92BF38A8-5616-4209-87A3-D910B45A1D98}" = Homescan Internet Transporter
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1488D23-3191-4B04-8BFE-26080BE12233}" = Symantec Real Time Storage Protection Component
"{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton AntiVirus Help
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BearShare" = BearShare
"BearShare MediaBar" = MediaBar
"Borders Desktop" = Borders Desktop
"CToolbar_UNINSTALL" = Crawler Toolbar
"FTDICOMM" = FTDI USB Serial Converter Drivers
"GoToAssist" = GoToAssist 8.0.0.514
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"iMesh MediaBar" = MediaBar 2.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MyWebSearch bar Uninstall" = My Web Search
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"quickhit.football.QHFootball.4D5206CA741FBF5FD6AAD1A97F5076E917382B34.1" = Quick Hit - Football
"SelectRebatesUninstall" = ShopAtHome SelectRebates
"SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security (Symantec Corporation)
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/28/2011 3:49:27 PM | Computer Name = MARITZA-454EDBC | Source = Application Hang | ID = 1002
Description = Hanging application mshta.exe, version 7.0.5730.13, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/28/2011 3:52:31 PM | Computer Name = MARITZA-454EDBC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/28/2011 3:52:31 PM | Computer Name = MARITZA-454EDBC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/28/2011 3:52:38 PM | Computer Name = MARITZA-454EDBC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/28/2011 3:52:38 PM | Computer Name = MARITZA-454EDBC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/28/2011 3:55:36 PM | Computer Name = MARITZA-454EDBC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(KodakESP5200+0514._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/28/2011 3:55:36 PM | Computer Name = MARITZA-454EDBC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(KodakESP5200+0514._scanner._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/28/2011 3:55:36 PM | Computer Name = MARITZA-454EDBC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(KodakESP5200+0514._smb._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/28/2011 3:57:35 PM | Computer Name = MARITZA-454EDBC | Source = Application Hang | ID = 1002
Description = Hanging application mshta.exe, version 7.0.5730.13, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/28/2011 3:57:35 PM | Computer Name = MARITZA-454EDBC | Source = Application Hang | ID = 1002
Description = Hanging application mshta.exe, version 7.0.5730.13, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/20/2011 5:31:08 PM | Computer Name = MARITZA-454EDBC | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 2/20/2011 5:31:12 PM | Computer Name = MARITZA-454EDBC | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time-a.nist.gov,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 2/20/2011 5:31:12 PM | Computer Name = MARITZA-454EDBC | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 2/20/2011 5:32:32 PM | Computer Name = MARITZA-454EDBC | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 2/20/2011 5:46:12 PM | Computer Name = MARITZA-454EDBC | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time-a.nist.gov,0x1'. NtpClient will try the DNS lookup
again in 30 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 2/20/2011 5:46:12 PM | Computer Name = MARITZA-454EDBC | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 2/20/2011 5:47:56 PM | Computer Name = MARITZA-454EDBC | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time-a.nist.gov,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 2/20/2011 5:47:56 PM | Computer Name = MARITZA-454EDBC | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 2/20/2011 5:48:41 PM | Computer Name = MARITZA-454EDBC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 00219B19B8C8.

Error - 2/22/2011 7:11:35 PM | Computer Name = MARITZA-454EDBC | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >




OTL logfile created on: 2/28/2011 2:28:10 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\Maritza\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.78 Gb Total Space | 196.26 Gb Free Space | 84.31% Space Free | Partition Type: NTFS

Computer Name: MARITZA-454EDBC | User Name: Maritza | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Maritza\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe (MusicLab, LLC)
PRC - C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Maritza\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Kwanzy Service) – File not found
SRV - (HidServ) – File not found
SRV - (MyWebSearchService) – C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE (MyWebSearch.com)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (LiveUpdate Notice) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (comHost) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110228.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110228.003\NAVENG.SYS (Symantec Corporation)
DRV - (SYMIDSCO) – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20110215.001\SymIDSCo.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymIMMP) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SymIM) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (COH_Mon) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (IntcHdmiAddService) Intel® – C:\WINDOWS\system32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (CO_Mon) – C:\WINDOWS\system32\drivers\CO_Mon.sys (Symantec Corporation)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.mywebsearch.com/mywebsearch/…CxXj.IeiX5Jx.zQ
IE - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\MyWebSearch\bar\firefox\ [2009/12/22 12:05:30 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/03/28 12:11:26 | 000,001,551 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll ()
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC)
O2 - BHO: (Mirar) - {74AAE0C5-991F-4000-8D00-1B4B5A8A9A81} - C:\WINDOWS\system32\6178.dll ()
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Inbox Toolbar) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome)
O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll ()
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (Mirar) - {74AAE0C4-991F-4000-8D00-1B4B5A8A9A81} - C:\WINDOWS\system32\6178.dll ()
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (ShopAtHome Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome)
O3 - HKLM\..\Toolbar: (iMesh MediaBar) - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll (iMesh)
O3 - HKLM\..\Toolbar: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\..\Toolbar\WebBrowser: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\..\Toolbar\WebBrowser: (Mirar) - {74AAE0C4-991F-4000-8D00-1B4B5A8A9A81} - C:\WINDOWS\system32\6178.dll ()
O3 - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\..\Toolbar\WebBrowser: (ShopAtHome Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome)
O3 - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\..\Toolbar\WebBrowser: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE (Symantec Corporation)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe (MusicLab, LLC)
O4 - HKLM..\Run: [lvmrealgnwg] File not found
O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] File not found
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [xgpyfdxcnkus] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1214440339-1659004503-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\datamngr.dll) - C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngr.dll (MusicLab, LLC)
O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll) - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/28 15:35:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17465059307421696)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/28 14:02:13 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Maritza\Desktop\OTL.exe
[2011/02/01 17:25:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/02/01 17:24:55 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/02/01 17:24:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/02/01 17:23:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/02/01 17:22:54 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/02/01 17:22:41 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/02/01 17:20:30 | 004,184,352 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2011/02/01 17:20:07 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/02/01 17:20:04 | 000,000,000 | -HSD | C] – C:\Config.Msi
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/28 14:30:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{67D1CDF4-3E96-49F0-98F5-AC94118F6F89}.job
[2011/02/28 14:28:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{AC7889A6-366B-4ADC-ADDE-9728E4376C8E}.job
[2011/02/28 14:02:16 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Maritza\Desktop\OTL.exe
[2011/02/28 13:53:21 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/28 13:52:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/03 14:21:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/02/01 17:25:46 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/01 17:23:07 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/01/31 20:00:00 | 000,000,626 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Maritza.job
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/01 17:25:46 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/01 17:23:07 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/11/07 18:32:43 | 000,000,059 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/11/07 18:32:33 | 000,729,088 | —- | C] () – C:\WINDOWS\System32\6178.dll
[2009/10/25 19:42:26 | 000,086,082 | —- | C] () – C:\WINDOWS\System32\ftdiunin.exe
[2009/10/25 19:42:26 | 000,000,110 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/03/28 15:04:06 | 000,003,402 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate
[2009/01/28 15:37:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/28 15:33:56 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/01/28 13:53:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/01/28 13:51:40 | 002,026,604 | —- | C] () – C:\WINDOWS\System32\igkrng500.bin
[2009/01/28 13:51:40 | 000,442,964 | —- | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2009/01/28 13:51:40 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4977.dll
[2009/01/28 07:19:27 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/28 07:18:43 | 000,146,808 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/14 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 06:00:00 | 000,432,686 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 06:00:00 | 000,067,516 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 06:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/04/15 10:52:33 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/04/15 10:52:33 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========

[2010/12/07 20:35:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\12EA
[2011/01/28 21:13:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2FFA
[2010/12/19 08:38:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\51E4
[2010/03/24 18:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\8213
[2010/12/28 11:55:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BearShare
[2009/01/28 13:48:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2011/02/01 17:25:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/12/28 11:56:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{A471C4AE-B27B-4761-9BCF-82FAAAAA2D01}
[2011/01/16 20:41:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\bearsharemediabartb
[2009/02/18 19:48:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/11/07 18:32:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\DealAssistant
[2010/10/17 17:31:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\Inbox Toolbar
[2010/11/04 14:30:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\LimeWire
[2010/10/17 17:30:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\PCRx
[2010/10/17 17:30:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\RebateInformer
[2010/03/15 10:08:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\Temp
[2009/06/20 11:18:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Carlos\Application Data\Uniblue
[2010/12/28 12:26:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Guest 2\Application Data\bearsharemediabartb
[2011/01/17 08:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Guest 2\Application Data\Inbox Toolbar
[2010/11/22 21:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Maritza\Application Data\bearsharemediabartb
[2010/11/22 21:59:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Maritza\Application Data\Inbox Toolbar
[2011/01/05 15:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Maritza\Application Data\PCRx
[2010/11/22 21:57:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Maritza\Application Data\RebateInformer
[2010/03/19 11:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Maritza\Application Data\Temp
[2010/11/14 12:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Rocio\Application Data\bearsharemediabartb
[2010/05/31 18:13:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Rocio\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/11/03 19:04:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Rocio\Application Data\Inbox Toolbar
[2010/12/17 21:01:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Rocio\Application Data\LimeWire
[2010/11/03 18:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Rocio\Application Data\PCRx
[2010/10/26 16:41:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Rocio\Application Data\RebateInformer
[2011/02/28 14:30:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{67D1CDF4-3E96-49F0-98F5-AC94118F6F89}.job
[2011/02/28 14:28:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{AC7889A6-366B-4ADC-ADDE-9728E4376C8E}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/01/28 15:35:50 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/19 11:40:05 | 000,000,210 | -HS- | M] () – C:\boot.ini
[2009/01/28 15:35:50 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/01/28 15:35:50 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/28 15:35:50 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 06:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/28 13:52:11 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/05/25 13:16:04 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/05/25 20:12:40 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/05/26 09:36:38 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/05/26 11:08:44 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2010/05/26 16:10:05 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2010/05/26 16:14:58 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2010/05/26 18:29:40 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2010/05/27 09:32:21 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2010/05/27 10:16:38 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2010/05/27 14:50:39 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2010/05/27 17:19:14 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2010/05/28 10:50:54 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2010/05/28 12:03:07 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2010/05/28 15:11:01 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2010/05/28 15:30:41 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2010/05/28 20:58:07 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2010/05/29 10:52:58 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2010/05/30 16:48:18 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/05/31 15:45:38 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2010/05/29 20:42:28 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2010/05/25 13:16:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/05/25 20:12:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/05/26 09:36:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/05/26 11:08:44 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/05/26 16:10:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/05/26 16:14:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/05/26 18:29:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/05/27 09:32:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/05/27 10:16:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/05/27 14:50:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/05/27 17:19:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/05/28 10:50:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/05/28 12:03:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/05/28 15:11:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/05/28 15:30:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/05/28 20:58:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/05/29 10:52:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/05/30 16:48:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/05/31 15:45:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/05/29 20:42:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/03/23 18:05:53 | 000,000,000 | —- | M] () – C:\testwma.raw
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/28 15:35:35 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/08/03 08:33:06 | 000,192,512 | —- | M] (Eastman Kodak Company) – C:\WINDOWS\system32\spool\prtprocs\w32x86\EKIJ5000PPR.dll
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/28 07:18:05 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/28 07:18:05 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/28 07:18:05 | 000,913,408 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/28 15:35:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/28 15:41:08 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Maritza\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/28 15:41:08 | 000,000,079 | —- | M] () – C:\Documents and Settings\Maritza\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/02/28 14:02:16 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Maritza\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-08 05:42:17

< End of report >



Forgot to mention that this pc has 5 account users ans everytime i tried to erase them it freezes my pc

thnx for your time :D
Hello lamar and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Before we begin your fix I would like to see the log from the following scan:

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the GMER log in your next reply. If you encounter any problems with the scan come back and let me know.
Hi Jontom thnx for helping me with this one

it took me a lil bit to reply because the pc kept freezing on me everytime i run the rroktkit scan , i disconect it from the internet and it was the onle way it worked?? (maybe im crazy) lol

anyways heres the result of the scan, let me know if i am missing something


thnx







GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-01 03:07:37
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST325031 rev.4.AD
Running: gmer.exe; Driver: C:\DOCUME~1\Maritza\LOCALS~1\Temp\awkiqfoc.sys


—- System - GMER 1.0.15 —-

SSDT 89349670 ZwAlertResumeThread
SSDT 89268408 ZwAlertThread
SSDT 89346998 ZwAllocateVirtualMemory
SSDT 891BDD68 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0x9B234020]
SSDT 891743E8 ZwCreateMutant
SSDT 88D14B28 ZwCreateThread
SSDT 8936BEF8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0x9B2342A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0x9B234800]
SSDT 88D22818 ZwFreeVirtualMemory
SSDT 893497D8 ZwImpersonateAnonymousToken
SSDT 892B01F0 ZwImpersonateThread
SSDT 892092B8 ZwMapViewOfSection
SSDT 89174368 ZwOpenEvent
SSDT 88D137B0 ZwOpenProcessToken
SSDT 88D492A8 ZwOpenSection
SSDT 892685A8 ZwOpenThreadToken
SSDT 892698D0 ZwResumeThread
SSDT 88D090F0 ZwSetContextThread
SSDT 88C726B0 ZwSetInformationProcess
SSDT 892B03A8 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0x9B234A50]
SSDT 8924B330 ZwSuspendProcess
SSDT 88D27248 ZwSuspendThread
SSDT 89349F08 ZwTerminateProcess
SSDT 88674680 ZwTerminateThread
SSDT 88673AF0 ZwUnmapViewOfSection
SSDT 88D27E70 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2C90 8050452C 4 Bytes CALL 3ED95C74

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device 990B9D20

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hello lamar

it took me a lil bit to reply because the pc kept freezing on me everytime i run the rroktkit scan

No problem at all :)

Please do the following:

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
hi JOnTom below is the log generated bycombofix (could u give me some good advise after we fix the pc, on which free AV or internet security is good to get?)


thnx






ComboFix 11-02-28.07 - Maritza 03/01/2011 14:04:40.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1648 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Maritza\GoToAssistDownloadHelper.exe
C:\Install.exe
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn.html
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\2.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\2.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\2.bin\F3DTactl.dll
c:\program files\MyWebSearch\bar\2.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\2.bin\F3HKSTUB.DLL
c:\program files\MyWebSearch\bar\2.bin\F3HTmlmu.dll
c:\program files\MyWebSearch\bar\2.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\2.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\2.bin\F3REGHK.DLL
c:\program files\MyWebSearch\bar\2.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\2.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\2.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\2.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\2.bin\M3AUXSTB.DLL
c:\program files\MyWebSearch\bar\2.bin\M3DLGHK.DLL
c:\program files\MyWebSearch\bar\2.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\2.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\2.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\2.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\2.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\2.bin\M3MSg.dll
c:\program files\MyWebSearch\bar\2.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\2.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\2.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\2.bin\m3SrchMn.exe.vir
c:\program files\MyWebSearch\bar\2.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\2.bin\mwsoemon.exe.vir
c:\program files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
c:\program files\MyWebSearch\bar\2.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\00129D32
c:\program files\MyWebSearch\bar\Cache\0020D805
c:\program files\MyWebSearch\bar\Cache\00212143.zQ
c:\program files\MyWebSearch\bar\Cache\00212460.bin
c:\program files\MyWebSearch\bar\Cache\00212569.bin
c:\program files\MyWebSearch\bar\Cache\0021279C.bin
c:\program files\MyWebSearch\bar\Cache\00212A8A.bin
c:\program files\MyWebSearch\bar\Cache\01543F93.bin
c:\program files\MyWebSearch\bar\Cache\0154406E.bin
c:\program files\MyWebSearch\bar\Cache\02CED424
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\firefox\CHROME.MANIFEST
c:\program files\MyWebSearch\bar\firefox\chrome\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\firefox\INSTALL.RDF
c:\program files\MyWebSearch\bar\firefox\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Message\COMMON\8_step1.gif
c:\program files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.htm
c:\program files\MyWebSearch\bar\Message\COMMON\bkwebfet.jpg
c:\program files\MyWebSearch\bar\Message\COMMON\bkzwinky.jpg
c:\program files\MyWebSearch\bar\Message\COMMON\blubtn2d.png
c:\program files\MyWebSearch\bar\Message\COMMON\blubtn2r.png
c:\program files\MyWebSearch\bar\Message\COMMON\blubtn3d.png
c:\program files\MyWebSearch\bar\Message\COMMON\blubtn3r.png
c:\program files\MyWebSearch\bar\Message\COMMON\center.htm
c:\program files\MyWebSearch\bar\Message\COMMON\index.htm
c:\program files\MyWebSearch\bar\Message\COMMON\logo_ZJ.png
c:\program files\MyWebSearch\bar\Message\COMMON\logo_ZR.png
c:\program files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
c:\program files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\protect.htm
c:\program files\MyWebSearch\bar\Message\COMMON\reb_bg.png
c:\program files\MyWebSearch\bar\Message\COMMON\rebbtnbg.png
c:\program files\MyWebSearch\bar\Message\COMMON\rebbtnn1.png
c:\program files\MyWebSearch\bar\Message\COMMON\rebbtnn2.png
c:\program files\MyWebSearch\bar\Message\COMMON\rebbtny1.png
c:\program files\MyWebSearch\bar\Message\COMMON\rebbtny2.png
c:\program files\MyWebSearch\bar\Message\COMMON\rebclose.png
c:\program files\MyWebSearch\bar\Message\COMMON\rebut.htm
c:\program files\MyWebSearch\bar\Message\COMMON\rebut2.htm
c:\program files\MyWebSearch\bar\Message\COMMON\rebut3.htm
c:\program files\MyWebSearch\bar\Message\COMMON\rebut3b.htm
c:\program files\MyWebSearch\bar\Message\COMMON\repmidsm.png
c:\program files\MyWebSearch\bar\Message\COMMON\shield.png
c:\program files\MyWebSearch\bar\Message\COMMON\shocked.gif
c:\program files\MyWebSearch\bar\Message\COMMON\stop.gif
c:\program files\MyWebSearch\bar\Message\COMMON\systray.htm
c:\program files\MyWebSearch\bar\Message\COMMON\systrayp.htm
c:\program files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
c:\program files\MyWebSearch\bar\Message\COMMON\warn.gif
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\SelectRebates
c:\program files\SelectRebates\FFToolbar\chrome.manifest
c:\program files\SelectRebates\FFToolbar\chrome\sahtoolbar.jar
c:\program files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\install.rdf
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebates.exe
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesApi.exe
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\SelectRebatesDownload.exe
c:\program files\SelectRebates\SelectRebatesUninstall.exe
c:\program files\SelectRebates\SRebates.dll
c:\program files\SelectRebates\SRFF3.dll
c:\program files\SelectRebates\Toolbar\AddtoList.bmp
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\CashBack.bmp
c:\program files\SelectRebates\Toolbar\Coupons.bmp
c:\program files\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\ImageCache\alert-red.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\Scissors.bmp
c:\program files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
c:\windows\system32\6178.dll
c:\windows\system32\f3PSSavr.scr

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_KWANZY_SERVICE
——-\Legacy_MYWEBSEARCHSERVICE
——-\Service_Kwanzy Service
——-\Service_MyWebSearchService


((((((((((((((((((((((((( Files Created from 2011-02-01 to 2011-03-01 )))))))))))))))))))))))))))))))
.

2011-03-01 19:34 . 2011-03-01 19:34 ——– d—–w- c:\documents and settings\Maritza\Local Settings\Application Data\PackageAware
2011-02-01 23:24 . 2011-02-01 23:24 ——– d—–w- c:\program files\iPod
2011-02-01 23:24 . 2011-02-01 23:25 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-02-01 23:22 . 2011-02-01 23:23 ——– d—–w- c:\program files\QuickTime
2011-02-01 23:22 . 2011-02-01 23:22 ——– d—–w- c:\program files\Apple Software Update
2011-02-01 23:20 . 2010-12-15 00:51 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-01 23:20 . 2011-02-01 23:20 ——– d—–w- c:\program files\Bonjour

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2008-04-14 12:00 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2008-04-14 12:00 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2008-04-14 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:08 . 2009-08-12 00:34 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-12-20 23:08 . 2008-04-14 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:08 . 2008-04-14 12:00 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:08 . 2008-04-14 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-12-20 17:26 . 2008-04-14 12:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2008-04-14 12:00 389120 —-a-w- c:\windows\system32\html.iec
2010-12-15 00:51 . 2009-01-28 22:01 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-12-13 17:51 . 2010-12-13 17:51 37376 —-a-w- c:\windows\system32\libusb0.dll
2010-12-13 17:51 . 2010-12-13 17:51 21504 —-a-w- c:\windows\system32\drivers\libusb0.sys
2010-12-09 15:15 . 2008-04-14 12:00 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2008-04-14 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42 . 2008-04-14 12:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2008-04-14 00:01 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
2009-12-20 09:51 87480 —-a-w- c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2010-10-19 12:53 585136 —-a-w- c:\progra~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0974BA1E-64EC-11DE-B2A5-E43756D89593}"= "c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll" [2009-12-20 87480]

[HKEY_CLASSES_ROOT\clsid\{0974ba1e-64ec-11de-b2a5-e43756d89593}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-01-28 19:47 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 20:57 948672 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 06:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-20 00:20 57344 —-a-w- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Conime]
2008-04-14 12:00 27648 —-a-w- c:\windows\system32\conime.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-08-15 23:06 178712 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-08-15 23:06 150040 —-a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 21:08 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MegaPanel]
2006-05-11 18:30 2064384 —-a-w- c:\program files\ACNielsen\Homescan Internet Transporter\HSTrans.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 13:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2008-05-23 19:06 128296 ——w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-08-15 23:06 150040 —-a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 23:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-07-31 23:05 16806912 —-a-w- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Kodak\\AiO\\Center\\AiOHomeCenter.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\Kodak.Statistics.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\NetworkPrinterDiscovery.exe"=
"c:\\Program Files\\Kodak\\AiO\\Firmware\\KodakAiOUpdater.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kodak\\Installer\\Setup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\ekdiscovery.exe [8/5/2009 11:49 AM 284016]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [1/28/2009 1:51 PM 110080]
S0 cerc6;cerc6; [x]
.
Contents of the 'Scheduled Tasks' folder

2011-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 17:50]

2011-03-01 c:\windows\Tasks\User_Feed_Synchronization-{67D1CDF4-3E96-49F0-98F5-AC94118F6F89}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]

2011-03-01 c:\windows\Tasks\User_Feed_Synchronization-{AC7889A6-366B-4ADC-ADDE-9728E4376C8E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.mywebsearch.com/mywebsearch/default.jhtml?ptnrS=ZCman000&ptb=_QjR7K1CxXj.IeiX5Jx.zQ
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{74AAE0C4-991F-4000-8D00-1B4B5A8A9A81} - c:\windows\system32\6178.dll
WebBrowser-{74AAE0C4-991F-4000-8D00-1B4B5A8A9A81} - c:\windows\system32\6178.dll
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-xgpyfdxcnkus - c:\documents and settings\rocio\local settings\application data\oybwyx\cfqsyml.exe
HKLM-Run-lvmrealgnwg - c:\documents and settings\carlos\local settings\application data\terlsa\mbdsxiy.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-EKIJ5000StatusMonitor - c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
MSConfigStartUp-Microsoft Default Manager - c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe
MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
MSConfigStartUp-osCheck - c:\program files\Norton Internet Security\osCheck.exe
MSConfigStartUp-SelectRebates - c:\program files\SelectRebates\SelectRebates.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-01 14:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

- - - - - - - > 'explorer.exe'(2536)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-03-01 14:16:36 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-01 20:16

Pre-Run: 220,461,420,544 bytes free
Post-Run: 222,672,916,480 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 30AC2AED1B71AC197FB83E6A21BDFF90
Hello lamar

Thank you for the log.

could u give me some good advise after we fix the pc, on which free AV or internet security is good to get?

No problem :)


  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I see you have BearShare. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • A list of currently installed programs will be displayed.
    • Find the "BearShare" program, click on it once and then click on the "Remove" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      DirLook::
      c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

      DDS::
      uStart Page = hxxp://search.mywebsearch.com/mywebsearch/default.jhtml?ptnrS=ZCman000&ptb=_QjR7K1CxXj.IeiX5Jx.zQ

      Driver::
      cerc6

      RegLock::
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.

    Please post the ComboFix log in your next reply.
Back again jontom… i erased the bearshare p2p and norton since it was expired (now ill need to find a free one untill i get the money to pay for kaspersky), could u reccomend me a good antivirus (free)?


next is the log fro the script on the combo fix




ComboFix 11-02-28.07 - Maritza 03/01/2011 16:26:18.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1624 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Maritza\Desktop\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_cerc6


((((((((((((((((((((((((( Files Created from 2011-02-01 to 2011-03-01 )))))))))))))))))))))))))))))))
.

2011-03-01 22:20 . 2011-03-01 22:20 ——– d—–w- c:\program files\Common Files\Java
2011-03-01 22:19 . 2011-03-01 22:19 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2011-03-01 22:16 . 2011-03-01 22:16 ——– d—–w- c:\documents and settings\Maritza\Local Settings\Application Data\Borders Desktop
2011-03-01 19:34 . 2011-03-01 19:34 ——– d—–w- c:\documents and settings\Maritza\Local Settings\Application Data\PackageAware
2011-02-01 23:24 . 2011-02-01 23:24 ——– d—–w- c:\program files\iPod
2011-02-01 23:24 . 2011-02-01 23:25 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-02-01 23:23 . 2011-02-01 23:23 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-02-01 23:22 . 2011-02-01 23:23 ——– d—–w- c:\program files\QuickTime
2011-02-01 23:22 . 2011-02-01 23:22 ——– d—–w- c:\program files\Apple Software Update
2011-02-01 23:20 . 2010-12-15 00:51 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-01 23:20 . 2011-02-01 23:20 ——– d—–w- c:\program files\Bonjour

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 03:40 . 2010-07-22 16:56 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-03 01:19 . 2009-10-30 16:22 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-01-21 14:44 . 2008-04-14 12:00 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2008-04-14 12:00 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2008-04-14 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:08 . 2009-08-12 00:34 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-12-20 23:08 . 2008-04-14 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:08 . 2008-04-14 12:00 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:08 . 2008-04-14 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-12-20 17:26 . 2008-04-14 12:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2008-04-14 12:00 389120 —-a-w- c:\windows\system32\html.iec
2010-12-15 00:51 . 2009-01-28 22:01 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-12-13 17:51 . 2010-12-13 17:51 37376 —-a-w- c:\windows\system32\libusb0.dll
2010-12-13 17:51 . 2010-12-13 17:51 21504 —-a-w- c:\windows\system32\drivers\libusb0.sys
2010-12-09 15:15 . 2008-04-14 12:00 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2008-04-14 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42 . 2008-04-14 12:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2008-04-14 00:01 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} —-

2011-02-01 23:25 . 2011-02-01 23:25 3578 —-a-w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\DIFxInstallLog.txt
2009-06-03 15:32 . 2009-06-03 15:32 7994 —-a-w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\gearaspiwdmx86.cat
2009-05-18 19:48 . 2009-05-18 19:48 2763 —-a-w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\GEARAspiWDM.inf
2009-05-18 19:17 . 2009-05-18 19:17 26600 —-a-w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86\GEARAspiWDM.sys
2009-02-04 19:56 . 2009-02-04 19:56 75112 —-a-w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\DifXInstall32.exe
2008-04-17 18:12 . 2008-04-17 18:12 107368 —-a-w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86\GEARAspi.dll
2006-11-02 12:21 . 2006-11-02 12:21 319456 —-a-w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\DIFxAPI.dll


((((((((((((((((((((((((((((( SnapShot@2011-03-01_20.13.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-01 22:31 . 2011-03-01 22:31 16384 c:\windows\Temp\Perflib_Perfdata_724.dat
+ 2010-07-22 16:56 . 2011-02-03 03:40 157472 c:\windows\system32\javaws.exe
+ 2010-07-22 16:56 . 2011-02-03 03:40 145184 c:\windows\system32\javaw.exe
- 2010-07-22 16:56 . 2010-04-12 22:29 145184 c:\windows\system32\javaw.exe
+ 2010-07-22 16:56 . 2011-02-03 03:40 145184 c:\windows\system32\java.exe
- 2010-07-22 16:56 . 2010-04-12 22:29 145184 c:\windows\system32\java.exe
+ 2011-03-01 22:20 . 2011-03-01 22:20 180224 c:\windows\Installer\2496a.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2010-10-19 12:53 585136 —-a-w- c:\progra~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-01-28 19:47 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 20:57 948672 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 06:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-20 00:20 57344 —-a-w- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Conime]
2008-04-14 12:00 27648 —-a-w- c:\windows\system32\conime.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-08-15 23:06 178712 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-08-15 23:06 150040 —-a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 21:08 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MegaPanel]
2006-05-11 18:30 2064384 —-a-w- c:\program files\ACNielsen\Homescan Internet Transporter\HSTrans.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 13:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2008-05-23 19:06 128296 ——w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-08-15 23:06 150040 —-a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 23:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-07-31 23:05 16806912 —-a-w- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Kodak\\AiO\\Center\\AiOHomeCenter.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\Kodak.Statistics.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\NetworkPrinterDiscovery.exe"=
"c:\\Program Files\\Kodak\\AiO\\Firmware\\KodakAiOUpdater.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kodak\\Installer\\Setup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\ekdiscovery.exe [8/5/2009 11:49 AM 284016]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [1/28/2009 1:51 PM 110080]
.
Contents of the 'Scheduled Tasks' folder

2011-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 17:50]

2011-03-01 c:\windows\Tasks\User_Feed_Synchronization-{67D1CDF4-3E96-49F0-98F5-AC94118F6F89}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]

2011-03-01 c:\windows\Tasks\User_Feed_Synchronization-{AC7889A6-366B-4ADC-ADDE-9728E4376C8E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

BHO-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll
Toolbar-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-01 16:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

- - - - - - - > 'explorer.exe'(3572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-03-01 16:34:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-01 22:34
ComboFix2.txt 2011-03-01 20:16

Pre-Run: 222,619,279,360 bytes free
Post-Run: 222,618,767,360 bytes free

- - End Of File - - 2B096AD1DEA14690F9C4DDCCCFCB8790
Hello lamar

Thank you for the log.

I will provide links to some free AV's and Firewalls once we have cleaned your machine. For the time being, please do not use the net except to download tools and to post replies back here.


  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.

    • Double click on the mbam-setup.exe icon to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the MBAM log and the ESET log in your next reply :)
back again

malware bytes scan and fix:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5925

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

3/1/2011 9:40:41 PM
mbam-log-2011-03-01 (21-40-41).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 174601
Time elapsed: 26 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 76

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B7D3E479-CC68-42B5-A338-938ECE35F419} (Adware.Softomate) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files\msn messenger\msimg32.dll (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\program files\msn messenger\riched20.dll (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\1.bin\npmywebs.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3cjpeg.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3dtactl.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3histsw.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3hkstub.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3htmlmu.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3httpct.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3popswt.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3pssavr.scr.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3reghk.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3reprox.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3restub.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3schmon.exe.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3scrctr.dll.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\f3wphook.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3auxstb.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3dlghk.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3highin.exe.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3html.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3idle.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3impipe.exe.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3medint.exe.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3msg.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3outlcn.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3plugin.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3skin.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3skplay.exe.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3slsrch.exe.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\m3srchmn.exe.vir.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\mwsbar.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\mwsoemon.exe.vir.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\mwsoeplg.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\mwsoestb.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\mwssrcas.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\2.bin\mwssvc.exe.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\mywebsearch\bar\firefox\npmywebs.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\6178.dll.vir (Adware.Mirar) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\f3pssavr.scr.vir (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262731.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262767.dll (Adware.Mirar) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262716.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262717.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262718.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262719.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262720.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262721.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262722.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262723.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262724.SCR (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262725.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262726.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262727.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262728.EXE (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262729.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262730.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262732.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262733.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262734.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262735.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262736.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262737.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262738.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262739.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262740.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262741.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262742.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262743.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262744.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262745.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262746.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262747.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262748.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262751.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{7f82d479-adbf-4520-8989-e05c58505293}\RP688\A0262768.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.



ESET scan findings after malwarebytes:




C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-3870556-12 meses gallego disipulos CD quality.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-3877633-y vas caminado zion lenoxx.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-39456-Don Omar - Dile.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-4820647-kapone al this 2k10 rock nba live.snd a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5088466-el verano del 96 si senor(192k 44100 stereo).snd a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5183725-rockstart rhiana top #1 hit.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5847706-down jat sean ft.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5875343-alive p o d.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5966561-kapone al this 2k10 rock nba (new album).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-4820647-kapone al this 2k10 rock nba live.snd a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5088466-el verano del 96 si senor(192k 44100 stereo).snd a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5106484-10 rock this al kapone.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5183725-rockstart rhiana top #1 hit.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5847706-down jat sean ft.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5855389-hasta bajo rmx daddy yankee ft.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5875343-alive p o d.au a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\12 meses gallego disipulos CD quality.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\cuando siente el boom rmx CD quality.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\kapone al this 2k10 rock nba (new album).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\manolo cabeza de huevo.mpg a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\senora mia menudo.wma a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR.vir Win32/Toolbar.MyWebSearch application
C:\WINDOWS\system32\drivers\etc\hosts.msn Win32/Qhost trojan
Hello lamar

Looks like you received infected files through Limewire. If you still have the Limewire program, make sure you uninstall it then do the following:


  • Please create a new System Restore point


    • Click on "Start" > "All Programs" > "Accessories" > "System tools" > "System Restore".
    • In the dialogue box that appears select "Create a Restore Point".
    • Click "Next".
    • Enter a name
    • e.g. Todays date.
    • Click "Create".

  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      
      :Files
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-3870556-12 meses gallego disipulos CD quality.mp3
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-3877633-y vas caminado zion lenoxx.mp3
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-39456-Don Omar - Dile.mp3
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-4820647-kapone al this 2k10 rock nba live.snd
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5088466-el verano del 96 si senor(192k 44100 stereo).snd
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5183725-rockstart rhiana top #1 hit.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5847706-down jat sean ft.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5875343-alive p o d.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5966561-kapone al this 2k10 rock nba (new album).mp3
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-4820647-kapone al this 2k10 rock nba live.snd
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5088466-el verano del 96 si senor(192k 44100 stereo).snd
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5106484-10 rock this al kapone.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5183725-rockstart rhiana top #1 hit.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5847706-down jat sean ft.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5855389-hasta bajo rmx daddy yankee ft.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5875343-alive p o d.au
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\12 meses gallego disipulos CD quality.mp3
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\cuando siente el boom rmx CD quality.mp3
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\kapone al this 2k10 rock nba (new album).mp3
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\manolo cabeza de huevo.mpg
      C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\senora mia menudo.wma
      C:\WINDOWS\system32\drivers\etc\hosts.msn
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

  • Security programs


    • I have provided links to three trusted programs (just choose one).




    • For a free Firewall try one of the following:
    • Comodo Personal Firewall
    • NOTE: If you use a Third Party AnitiVirus, make sure you uncheck the option to install Comodo AntiVirus when you install Comodo Firewall.



    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

    Please post the OTL log in your next reply, along with both of the DDS logs and let me know how the machine is running now.
back again jontom :D appreciate ur fast replies and help, i noticed most of the files that were infected was infact due to a P2P program…. (this is actually my sisters pc and had a lot of user accounts made for family members, but i guess she will learn the lesson this time) i took the liberty to erase all the extra user accounts since its easier to monitor one account rather than 5…. anyways the pc after the fixes has been a lil bit faster :D and has not freezed so far, i dunno if it still infected (u will check once i post the next logs) but seems a lot better as for now ….
thnx


one more question…. if i add the antivirus and the comodo firewall… can i add SPYBOT search and destroy as well?? i like that program due to the fact that it warns you everytime a change on the registry is about to be made and it gives you the option to accept the change or decline it… let me know if its possible


OTL FIX


All processes killed
========== OTL ==========
No active process named explorer.exe was found!
========== FILES ==========
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-3870556-12 meses gallego disipulos CD quality.mp3 moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-3877633-y vas caminado zion lenoxx.mp3 moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-39456-Don Omar - Dile.mp3 moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-4820647-kapone al this 2k10 rock nba live.snd moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5088466-el verano del 96 si senor(192k 44100 stereo).snd moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5183725-rockstart rhiana top #1 hit.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5847706-down jat sean ft.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5875343-alive p o d.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\Preview-T-5966561-kapone al this 2k10 rock nba (new album).mp3 moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-4820647-kapone al this 2k10 rock nba live.snd moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5088466-el verano del 96 si senor(192k 44100 stereo).snd moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5106484-10 rock this al kapone.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5183725-rockstart rhiana top #1 hit.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5847706-down jat sean ft.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5855389-hasta bajo rmx daddy yankee ft.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Incomplete\T-5875343-alive p o d.au moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\12 meses gallego disipulos CD quality.mp3 moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\cuando siente el boom rmx CD quality.mp3 moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\kapone al this 2k10 rock nba (new album).mp3 moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\manolo cabeza de huevo.mpg moved successfully.
C:\Documents and Settings\Maritza\Desktop\Carlos\My Documents\LimeWire\Saved\senora mia menudo.wma moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.msn moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41044 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Maritza
->Temp folder emptied: 2876900 bytes
->Temporary Internet Files folder emptied: 21358856 bytes
->Java cache emptied: 49803087 bytes
->Flash cache emptied: 17352 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2402044 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 571 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32902 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 73.00 mb


[EMPTYFLASH]

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: Maritza
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.22.2 log created on 03022011_024923

Files\Folders moved on Reboot…
C:\Documents and Settings\Maritza\Local Settings\Temporary Internet Files\Content.IE5\SMJAMWEW\index[1].htm moved successfully.
C:\Documents and Settings\Maritza\Local Settings\Temporary Internet Files\Content.IE5\OZJXUP2L\like[1].htm moved successfully.
C:\Documents and Settings\Maritza\Local Settings\Temporary Internet Files\Content.IE5\9QY2HR6W\iframe[1].htm moved successfully.
C:\Documents and Settings\Maritza\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.

Registry entries deleted on Reboot…






DDS SCAN





DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 2:57:25.20 on Wed 03/02/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1651 [GMT -6:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Maritza\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: UrlHelper Class: {74322bf9-df26-493f-b0da-6d2fc5e6429e} - c:\progra~1\bearsh~1\mediabar\datamngr\IEBHO.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Inbox Toolbar: {d3d233d5-9f6d-436c-b6c7-e63f77503b30} - c:\progra~1\inboxt~1\Inbox.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: &Inbox; Toolbar: {d7e97865-918f-41e4-9cd0-25ab1c574ce8} - c:\progra~1\inboxt~1\Inbox.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Conime] %windir%\system32\conime.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\inboxt~1\Inbox.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll

============= SERVICES / DRIVERS ===============

R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\ekdiscovery.exe [2009-8-5 284016]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-1-28 110080]

=============== Created Last 30 ================

2011-03-02 08:49:23 ——– d—–w- C:\_OTL
2011-03-02 04:35:37 ——– d—–w- c:\program files\ESET
2011-03-02 02:57:34 ——– d—–w- c:\docume~1\maritza\applic~1\Malwarebytes
2011-03-02 02:57:27 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-02 02:57:27 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-03-02 02:57:24 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-03-02 02:57:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-03-01 22:16:23 ——– d—–w- c:\docume~1\maritza\locals~1\applic~1\Borders Desktop
2011-03-01 20:02:08 ——– d-sha-r- C:\cmdcons
2011-03-01 19:54:05 98816 —-a-w- c:\windows\sed.exe
2011-03-01 19:54:05 89088 —-a-w- c:\windows\MBR.exe
2011-03-01 19:54:05 256512 —-a-w- c:\windows\PEV.exe
2011-03-01 19:54:05 161792 —-a-w- c:\windows\SWREG.exe
2011-03-01 19:34:35 ——– d—–w- c:\docume~1\maritza\locals~1\applic~1\PackageAware
2011-02-01 23:24:55 ——– d—–w- c:\program files\iPod
2011-02-01 23:24:51 ——– d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-02-01 23:23:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-02-01 23:23:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-02-01 23:23:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-02-01 23:23:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-02-01 23:23:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-02-01 23:23:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-02-01 23:23:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-02-01 23:20:30 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-01 23:20:07 ——– d—–w- c:\program files\Bonjour

==================== Find3M ====================

2011-02-03 03:40:23 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-03 01:19:39 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34:28 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:08:45 832512 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:08:45 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-12-20 23:08:45 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:08:45 17408 —-a-w- c:\windows\system32\corpol.dll
2010-12-20 17:26:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55:25 389120 —-a-w- c:\windows\system32\html.iec
2010-12-13 17:51:52 37376 —-a-w- c:\windows\system32\libusb0.dll
2010-12-09 15:15:09 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30:22 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42:26 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07:07 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe

============= FINISH: 2:58:00.60 ===============

Attachments:

Hello lamar

Thank you for the log.

can i add SPYBOT search and destroy as well??

I would think so. Give it a try and see how they all run together. If you are not happy with the combination there are other options (WinPatrol for example).

Your logs appear to be clean :thumbup:

Go ahead and install an AV, Firewall and Spybot. Update the AV and run a full system scan.

Once the scan is complete let me know how the machine is running :)
scan went good… :D pc aint freezing anymore and internet is not kicking us out anymore… lesson of the day to anyone reading this: DO NOT USE P2P LOL thnx for your time and help, its greatly appreciated it :D
Hello lamar

Glad to hear things are running well for you.

lesson of the day to anyone reading this: DO NOT USE P2P

Yes. P2P is a major source of malware infection. "Free files" are never free (they may actually end up costing you more than you think - in some cases it might be the price of a new computer).

Lets remove the tools we used during your fix:

  • Please Uninstall Combofix


    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • Please perform the following cleanup procedure


    • Double click on the OTL.exe icon on your desktop to run the program.
    • Once OTL has opened, click on the "CleanUp!" button.
    • Follow any prompts that you receive.

  • Your Adobe is out of date


    • You can obtain the latest version of Adobe Reader from here, and the latest version of Flash Player from here.
    • For more information and links to Adobe updates and downloads click here.


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 3.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI