This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected: "Warning you are in danger your computer is infected wi

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Thanks in advance for your assistance. Appreciate it.

My dell laptop was infected on 3/2/2011 and my desktop has the following message "warning you are in danger your computer is infected with spyware…." I keep getting notifications about several .exe files being infected'

I run ZoneAlarm anti-virus, anti-spyware and a firewall.

Since being infected I did a system restore, ran Malawarebytes and Spydot. Malawarebytes found 5 objects and removed them but the issue started back up yesterday (3/4/2011).

I then checked this forum and I've run HijackThis to get the log file. I have not run 'analyse this' or attempted to fix anything as per the instructions. The log file is below:

——————————————————————————————-
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:31:51 AM, on 3/5/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Users\Manjula\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files (x86)\ooVoo\ooVoo.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Java\jre6\bin\jucheck.exe
C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\mswinext.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Users\Manjula\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Manjula\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Manjula\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Manjula\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Manjula\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Manjula\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [googletalk] C:\Users\Manjula\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe /minimized
O4 - HKCU\..\Run: [Spyware Doctor] C:\Users\Manjula\Desktop\sdsetup.exe -min
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [kFpNiJj06300] C:\ProgramData\kFpNiJj06300\kFpNiJj06300.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} (DellSystemLite.Scanner) - http://support.dell.com/systemprofiler/DellSystemLite.CAB
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://seomozevents.webex.com/client/T27LB/nbr/ieatgpc1.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Amazon Download Agent - Amazon.com - C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 13765 bytes

———————————————————————
Thank you again,

Saicool
Hi saicool171, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKCU\..\RunOnce: [kFpNiJj06300] C:\ProgramData\kFpNiJj06300\kFpNiJj06300.exe

Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.

Reboot your computer.

Next

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

Next

Download OTL to your desktop.
  • Right click on OTL.exe and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop
    C:\ProgramData\kFpNiJj06300\*.* /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • MBRCheck log
  • both OTL logs
Thanks
Hi oldman960, Thank you for your assistance with this.

Between when I posted this morning and running these scans - Windows rebooted to auto apply an update. Don't know if this is relevant - I didn't install it but when I started my laptop this evening I had a notification stating updates had been applied.

The log files are below.

Saicool.



MBRcheck log:

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Inspiron 1545
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 194):
0x02A0E000 \SystemRoot\system32\ntoskrnl.exe
0x02FEB000 \SystemRoot\system32\hal.dll
0x00BBF000 \SystemRoot\system32\kdcom.dll
0x00C14000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00C58000 \SystemRoot\system32\PSHED.dll
0x00C6C000 \SystemRoot\system32\CLFS.SYS
0x00CCA000 \SystemRoot\system32\CI.dll
0x00E87000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F2B000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00F3A000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00F91000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00F9A000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00FA4000 \SystemRoot\system32\DRIVERS\pci.sys
0x00FD7000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00FE4000 \SystemRoot\System32\drivers\partmgr.sys
0x00E00000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00E09000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00E15000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00E2A000 \SystemRoot\System32\drivers\volmgrx.sys
0x00D8A000 \SystemRoot\System32\drivers\mountmgr.sys
0x010A9000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x011C5000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x01000000 \SystemRoot\system32\drivers\fltmgr.sys
0x0104C000 \SystemRoot\system32\drivers\fileinfo.sys
0x01060000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x01259000 \SystemRoot\System32\Drivers\Ntfs.sys
0x014FB000 \SystemRoot\System32\Drivers\msrpc.sys
0x01559000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01573000 \SystemRoot\System32\Drivers\cng.sys
0x015E6000 \SystemRoot\System32\drivers\pcw.sys
0x01400000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x0162A000 \SystemRoot\system32\drivers\ndis.sys
0x0171C000 \SystemRoot\system32\drivers\NETIO.SYS
0x0177C000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01803000 \SystemRoot\System32\drivers\tcpip.sys
0x017A7000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0140A000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x017F1000 \SystemRoot\System32\Drivers\spldr.sys
0x01456000 \SystemRoot\System32\drivers\rdyboost.sys
0x01600000 \SystemRoot\System32\Drivers\mup.sys
0x01612000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01490000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x014CA000 \SystemRoot\system32\DRIVERS\disk.sys
0x01200000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x02D40000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02D6A000 \SystemRoot\system32\DRIVERS\klif.sys
0x02DC6000 \SystemRoot\System32\Drivers\Null.SYS
0x02DCF000 \SystemRoot\System32\Drivers\Beep.SYS
0x02DD6000 \SystemRoot\System32\drivers\vga.sys
0x01230000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x02DE4000 \SystemRoot\System32\drivers\watchdog.sys
0x02DF4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x02C00000 \SystemRoot\system32\drivers\rdpencdd.sys
0x014E0000 \SystemRoot\system32\drivers\rdprefmp.sys
0x014E9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x0106C000 \SystemRoot\System32\Drivers\Npfs.SYS
0x0107D000 \SystemRoot\system32\DRIVERS\tdx.sys
0x0109B000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x03A70000 \SystemRoot\system32\DRIVERS\kl1.sys
0x040DC000 \SystemRoot\system32\drivers\afd.sys
0x04166000 \SystemRoot\System32\DRIVERS\netbt.sys
0x04000000 \SystemRoot\system32\DRIVERS\vsdatant.sys
0x04093000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x0409C000 \SystemRoot\system32\DRIVERS\pacer.sys
0x040C2000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x041AB000 \SystemRoot\system32\DRIVERS\netbios.sys
0x041BA000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x041D5000 \SystemRoot\system32\DRIVERS\termdd.sys
0x03F99000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x041E9000 \SystemRoot\system32\drivers\nsiproxy.sys
0x041F5000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x03FEA000 \SystemRoot\System32\drivers\discache.sys
0x03A00000 \SystemRoot\System32\Drivers\dfsc.sys
0x03A1E000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x0489D000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x04281000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04375000 \SystemRoot\System32\drivers\dxgmms1.sys
0x043BB000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x04200000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04256000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x043C8000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x05047000 \SystemRoot\system32\DRIVERS\bcmwl664.sys
0x052EF000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x052FC000 \SystemRoot\system32\DRIVERS\yk62x64.sys
0x05360000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x0537E000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
0x053BA000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x053C9000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x053D8000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x053DD000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x053E6000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x05000000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x05010000 \SystemRoot\system32\DRIVERS\lmimirr.sys
0x05017000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x04F9C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x0502D000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04FC0000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04800000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x0481B000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04267000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x05039000 \SystemRoot\system32\DRIVERS\swenum.sys
0x0483C000 \SystemRoot\system32\DRIVERS\ks.sys
0x043EC000 \SystemRoot\system32\DRIVERS\umbus.sys
0x00DA4000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x0487F000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x05EA8000 \SystemRoot\system32\DRIVERS\stwrt64.sys
0x05F23000 \SystemRoot\system32\DRIVERS\portcls.sys
0x05F60000 \SystemRoot\system32\DRIVERS\drmk.sys
0x05F82000 \SystemRoot\system32\drivers\ksthunk.sys
0x000E0000 \SystemRoot\System32\win32k.sys
0x05F88000 \SystemRoot\System32\drivers\Dxapi.sys
0x05F94000 \SystemRoot\System32\Drivers\RtsUStor.sys
0x05FCE000 \SystemRoot\System32\Drivers\USBD.SYS
0x05FD0000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x05FED000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x05E00000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x05E19000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x05E22000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x05E2F000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x05E3B000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x05E56000 \SystemRoot\System32\Drivers\usbvideo.sys
0x03A2F000 \SystemRoot\system32\DRIVERS\CtClsFlt.sys
0x05E84000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00570000 \SystemRoot\System32\TSDDD.dll
0x00650000 \SystemRoot\System32\cdd.dll
0x02C09000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x02C26000 \SystemRoot\system32\drivers\luafv.sys
0x02C49000 \SystemRoot\system32\drivers\WudfPf.sys
0x05E92000 \SystemRoot\System32\Drivers\crashdmp.sys
0x02494000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x025B0000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x025C3000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x02400000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x02453000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x02466000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0247E000 \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
0x02C6A000 \SystemRoot\system32\drivers\HTTP.sys
0x025D8000 \SystemRoot\system32\DRIVERS\bowser.sys
0x011D0000 \SystemRoot\System32\drivers\mpsdrv.sys
0x0541D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x0544A000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x05498000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x054BB000 \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
0x054C2000 \??\C:\Windows\system32\drivers\LMIRfsDriver.sys
0x054D5000 \SystemRoot\system32\drivers\peauth.sys
0x0557B000 \SystemRoot\System32\Drivers\secdrv.SYS
0x05586000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x055B3000 \SystemRoot\System32\drivers\tcpipreg.sys
0x08007000 \SystemRoot\System32\DRIVERS\srv2.sys
0x0806E000 \SystemRoot\System32\DRIVERS\srv.sys
0x08104000 \SystemRoot\system32\drivers\BCM42RLY.sys
0x0810D000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x0813E000 \SystemRoot\System32\Drivers\fastfat.SYS
0x08174000 \SystemRoot\system32\drivers\spsys.sys
0x76F50000 \Windows\System32\ntdll.dll
0x480A0000 \Windows\System32\smss.exe
0xFF270000 \Windows\System32\apisetschema.dll
0xFF460000 \Windows\System32\autochk.exe
0xFF000000 \Windows\System32\iertutil.dll
0xFEFF0000 \Windows\System32\lpk.dll
0xFEF20000 \Windows\System32\usp10.dll
0xFED10000 \Windows\System32\ole32.dll
0xFEBE0000 \Windows\System32\wininet.dll
0xFEB90000 \Windows\System32\Wldap32.dll
0x77120000 \Windows\System32\psapi.dll
0xFEA10000 \Windows\System32\urlmon.dll
0xFE990000 \Windows\System32\shlwapi.dll
0xFE960000 \Windows\System32\imm32.dll
0xFE8E0000 \Windows\System32\difxapi.dll
0xFE8C0000 \Windows\System32\imagehlp.dll
0xFE870000 \Windows\System32\ws2_32.dll
0xFE7D0000 \Windows\System32\msvcrt.dll
0x76E30000 \Windows\System32\kernel32.dll
0xFE7C0000 \Windows\System32\nsi.dll
0xFE690000 \Windows\System32\rpcrt4.dll
0xFE5F0000 \Windows\System32\clbcatq.dll
0xFE4E0000 \Windows\System32\msctf.dll
0xFD750000 \Windows\System32\shell32.dll
0xFD730000 \Windows\System32\sechost.dll
0x76D30000 \Windows\System32\user32.dll
0x77110000 \Windows\System32\normaliz.dll
0xFD690000 \Windows\System32\comdlg32.dll
0xFD5B0000 \Windows\System32\oleaut32.dll
0xFD3D0000 \Windows\System32\setupapi.dll
0xFD2F0000 \Windows\System32\advapi32.dll
0xFD280000 \Windows\System32\gdi32.dll
0xFD260000 \Windows\System32\devobj.dll
0xFD1F0000 \Windows\System32\KernelBase.dll
0xFD080000 \Windows\System32\crypt32.dll
0xFCFE0000 \Windows\System32\comctl32.dll
0xFCFA0000 \Windows\System32\cfgmgr32.dll
0xFCF60000 \Windows\System32\wintrust.dll
0xFCF50000 \Windows\System32\msasn1.dll
0x77100000 \Windows\SysWOW64\normaliz.dll

Processes (total 95):
0 System Idle Process
4 System
316 C:\Windows\System32\smss.exe
412 csrss.exe
488 C:\Windows\System32\wininit.exe
504 csrss.exe
556 C:\Windows\System32\winlogon.exe
580 C:\Windows\System32\services.exe
608 C:\Windows\System32\lsass.exe
620 C:\Windows\System32\lsm.exe
716 C:\Windows\System32\svchost.exe
796 C:\Windows\System32\svchost.exe
872 C:\Windows\System32\svchost.exe
916 C:\Windows\System32\svchost.exe
944 C:\Windows\System32\svchost.exe
1000 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe
352 C:\Windows\System32\audiodg.exe
1120 C:\Windows\System32\svchost.exe
1168 C:\Program Files\Dell\DellDock\DockLogin.exe
1268 C:\Windows\System32\svchost.exe
1336 C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
1424 C:\Windows\System32\wlanext.exe
1432 C:\Windows\System32\conhost.exe
1680 C:\Windows\System32\dwm.exe
1704 C:\Windows\explorer.exe
1928 C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
1960 C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
2020 C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
1720 C:\Windows\System32\spoolsv.exe
1580 C:\Windows\System32\taskhost.exe
1804 C:\Windows\System32\svchost.exe
1688 C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
992 C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
2160 C:\Program Files (x86)\LogMeIn\x64\ramaint.exe
2228 C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
2344 C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
2424 C:\Program Files\DellTPad\Apoint.exe
2664 C:\Program Files\IDT\WDM\sttray64.exe
2680 C:\Windows\System32\igfxtray.exe
2716 C:\Windows\System32\hkcmd.exe
2740 C:\Windows\System32\igfxpers.exe
2804 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2836 C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
2900 C:\Windows\System32\igfxsrvc.exe
2912 C:\Program Files\Dell\QuickSet\quickset.exe
2992 C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
3028 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
1096 C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
996 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2616 C:\Users\Manjula\AppData\Local\Google\Chrome\Application\chrome.exe
2924 C:\Windows\System32\svchost.exe
2944 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
2500 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
3132 C:\Users\Manjula\AppData\Local\Google\Update\GoogleUpdate.exe
3208 C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
3280 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
3452 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
3492 C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
3568 C:\Users\Manjula\AppData\Roaming\Google\Google Talk\googletalk.exe
3604 C:\Program Files (x86)\ooVoo\ooVoo.exe
3644 WmiPrvSE.exe
4496 C:\Windows\System32\SearchIndexer.exe
4548 C:\Users\Manjula\AppData\Local\Google\Chrome\Application\chrome.exe
4604 C:\Windows\System32\svchost.exe
4900 C:\Windows\System32\svchost.exe
5068 WUDFHost.exe
4888 C:\Program Files (x86)\Yahoo!\Messenger\Ymsgr_tray.exe
4700 C:\Program Files\Windows Media Player\wmpnetwk.exe
4804 C:\Program Files\DellTPad\ApMsgFwd.exe
3336 C:\Users\Manjula\AppData\Local\Google\Chrome\Application\chrome.exe
4792 C:\Program Files\DellTPad\hidfind.exe
4492 C:\Program Files\DellTPad\ApntEx.exe
4896 C:\Windows\System32\conhost.exe
4612 C:\Windows\System32\SearchProtocolHost.exe
2248 C:\Windows\System32\sppsvc.exe
3380 C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
4776 C:\Windows\System32\svchost.exe
4312 C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
4772 C:\Program Files\Dell\DellDock\DellDock.exe
3868 C:\Program Files (x86)\Java\jre6\bin\jusched.exe
2384 C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
2436 C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
4348 C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
3156 C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
4664 C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
4960 C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
2456 C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
5148 C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
5760 C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
5220 C:\Windows\System32\wuauclt.exe
4200 C:\Windows\System32\SearchFilterHost.exe
5144 dllhost.exe
5036 dllhost.exe
5956 C:\Users\Manjula\Desktop\MBRCheck.exe
5904 C:\Windows\System32\conhost.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000004`cab00000 (NTFS)

PhysicalDrive0 Model Number: ST9320325AS, Rev: 0003DEM1

Size Device Name MBR Status
——————————————–
298 GB \\.\PhysicalDrive0 Dell Inspiron MBR code detected
SHA1: AE3E0A945D44C8EA304A19A8F50F69065C34344B


Done!

—————————————————————————————————
OTL.txt


OTL logfile created on: 3/5/2011 7:39:02 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\Manjula\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 278.92 Gb Total Space | 229.87 Gb Free Space | 82.41% Space Free | Partition Type: NTFS
Drive D: | 1.04 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DELL-LAPTOP | User Name: Manjula | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Manjula\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
PRC - C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
PRC - C:\Program Files (x86)\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe ()
PRC - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Users\Manjula\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)


========== Modules (SafeList) ==========

MOD - C:\Users\Manjula\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CheckPoint\ZAForceField\WOW64\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\wintrust.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcp80.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (vsmon) – C:\Windows\SysWOW64\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (Amazon Download Agent) – C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV:64bit: - (Vsdatant) – C:\Windows\SysNative\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (Vsdatant) – C:\Windows\SysWOW64\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=DLCDF8&PC=WLEM&q="
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.5.0
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.80
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2
FF - prefs.js..extensions.enabledItems: {75CEEE46-9B64-46f8-94BF-54012DE155F0}:0.3.92
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20091209.4
FF - prefs.js..extensions.enabledItems: [removed]:0.42
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.152.14
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=DLCDF8&PC=WLEM&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2011/03/04 08:09:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/08/09 17:14:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\Firefox [2010/08/09 17:15:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/03/04 07:49:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/03/04 07:49:58 | 000,000,000 | —D | M]

[2010/01/30 17:26:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Manjula\AppData\Roaming\Mozilla\Extensions
[2011/03/04 08:56:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions
[2010/02/02 20:16:18 | 000,000,000 | —D | M] (FireShot) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2011/01/20 10:56:53 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/01/30 19:53:47 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/02/02 20:14:41 | 000,000,000 | —D | M] (ColorZilla) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/02/02 20:13:53 | 000,000,000 | —D | M] (MeasureIt) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}
[2010/02/02 20:20:47 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/01/30 18:28:59 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/02/02 20:43:29 | 000,000,000 | —D | M] (Firebug) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\[removed]
[2010/09/26 12:43:08 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\[removed]
[2010/02/03 07:37:13 | 000,000,000 | —D | M] ("Inline Code Finder for Firebug") – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\[removed]
[2010/02/09 19:48:34 | 000,000,000 | —D | M] (Mozbar) – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\extensions\[removed]
[2010/08/13 11:01:34 | 000,001,832 | —- | M] () – C:\Users\Manjula\AppData\Roaming\Mozilla\Firefox\Profiles\47mll4aj.default\searchplugins\bing.xml
[2010/03/12 08:54:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/03/04 08:09:10 | 000,000,000 | —D | M] (ZoneAlarm Toolbar) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\WOW64\TRUSTCHECKER

O1 HOSTS File: ([2011/03/04 20:49:34 | 000,430,706 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14824 more lines…
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [googletalk] C:\Users\Manjula\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Spyware Doctor] C:\Users\Manjula\Desktop\sdsetup.exe ()
O4 - Startup: C:\Users\Manjula\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://seomozevents.webex.com/client/T27LB/nbr/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 12:40:43 | 000,000,093 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{31e3efac-adab-11de-adab-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{31e3efac-adab-11de-adab-806e6f6e6963}\Shell\AutoRun\command - "" = D:\HoyleCasinoGames2011.exe – [2010/08/10 07:27:00 | 1111,265,438 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/03/05 19:35:09 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Users\Manjula\Desktop\OTL.exe
[2011/03/05 19:17:18 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{2DFBAF16-D87E-4BB4-917F-9CC5698A22FB}
[2011/03/04 19:43:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/03/04 19:43:21 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/03/04 19:43:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2011/03/04 19:41:32 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2011/03/04 19:37:22 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011/03/04 19:10:56 | 000,000,000 | —D | C] – C:\ProgramData\kFpNiJj06300
[2011/03/04 08:08:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZoneAlarm
[2011/03/04 08:08:47 | 000,157,712 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\kl1.sys
[2011/03/04 08:08:45 | 000,351,248 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2011/03/04 08:08:16 | 000,374,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2011/03/04 08:07:51 | 000,110,080 | —- | C] (Check Point Software Technologies LTD) – C:\Windows\SysWow64\vsxml.dll
[2011/03/04 08:07:50 | 000,456,280 | —- | C] (Check Point Software Technologies LTD) – C:\Windows\SysWow64\drivers\vsdatant.sys
[2011/03/04 08:07:50 | 000,000,000 | —D | C] – C:\Windows\SysNative\ZoneLabs
[2011/03/03 10:38:13 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{7B645DC7-CD2A-4D3C-AF75-18B0C302D4E8}
[2011/03/02 22:45:18 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Roaming\Malwarebytes
[2011/03/02 22:45:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/03/02 22:45:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/02 22:45:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/03/02 22:45:05 | 000,024,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/03/02 22:45:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/03/02 22:37:50 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{1AC59F79-E40B-47CA-8212-42BFC348B300}
[2011/03/02 22:20:50 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/03/02 22:13:54 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2011/03/02 21:25:08 | 000,000,000 | —D | C] – C:\ProgramData\cMdLoBg06300
[2011/03/01 07:52:17 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{746BD617-67AD-45B8-926D-8962849A3164}
[2011/02/26 15:31:52 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{75EA055D-6291-4D38-8651-418395DF34E3}
[2011/02/26 15:18:15 | 000,000,000 | —D | C] – C:\Users\Manjula\Documents\Dell WebCam Central
[2011/02/26 15:18:15 | 000,000,000 | —D | C] – C:\ProgramData\Creative
[2011/02/26 15:18:14 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Roaming\Creative
[2011/02/24 10:12:54 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{826C21ED-8CE3-459C-84F1-55B69D21852D}
[2011/02/23 07:07:54 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/02/23 07:07:54 | 000,475,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/02/23 07:07:54 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/02/23 07:07:54 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/02/23 06:55:50 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{5C012C4D-EA9E-4E01-8CFF-F8E59CB10E1F}
[2011/02/22 13:40:07 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{2069C49D-C48B-4856-A19E-6FF82EEA424E}
[2011/02/19 17:49:02 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\{098EE9C9-DC1E-44B6-88F6-E53B62894E0A}
[2011/02/19 17:43:03 | 000,000,000 | —D | C] – C:\Windows\en
[2011/02/19 17:42:37 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/02/19 17:40:10 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/02/19 17:39:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/02/19 17:37:29 | 003,860,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbon.dll
[2011/02/19 17:37:29 | 002,983,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbon.dll
[2011/02/19 17:37:29 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbonRes.dll
[2011/02/19 17:37:29 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbonRes.dll
[2011/02/19 17:23:10 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Roaming\Windows Live Writer
[2011/02/19 17:23:10 | 000,000,000 | —D | C] – C:\Users\Manjula\AppData\Local\Windows Live Writer
[2011/02/19 17:23:10 | 000,000,000 | —D | C] – C:\Users\Manjula\Documents\My Weblog Posts
[2011/02/12 21:35:55 | 000,000,000 | –SD | C] – C:\Users\Manjula\Documents\My Data Sources
[2011/02/09 07:19:25 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/02/09 07:19:24 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/02/09 07:19:24 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/02/09 07:19:24 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/02/09 07:19:24 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/02/09 07:19:24 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/02/09 07:19:24 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/02/09 07:19:24 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/02/09 07:19:24 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/02/09 07:19:24 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/02/09 07:19:23 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/02/09 07:19:23 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/02/09 07:18:51 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/02/09 07:18:51 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/02/09 07:18:49 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/02/09 07:18:48 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/02/09 07:18:48 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/02/09 07:18:48 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/02/09 07:18:48 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/02/09 07:18:48 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/02/09 07:18:29 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/02/09 07:18:28 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/02/09 07:18:28 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/02/09 07:18:25 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/02/09 07:18:24 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/02/09 07:18:24 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/02/09 07:18:23 | 005,510,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/02/09 07:18:22 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/02/09 07:18:22 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/02/09 07:18:22 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/02/09 07:18:21 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/02/09 07:18:21 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/02/09 07:18:20 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/02/09 07:18:20 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010/12/26 10:07:28 | 000,099,840 | —- | C] ( ) – C:\Windows\SysWow64\Zipdll.dll
[2010/12/26 10:07:23 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\Unzdll.dll
[2 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/05 19:36:35 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/05 19:36:35 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/05 19:35:09 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Users\Manjula\Desktop\OTL.exe
[2011/03/05 19:30:58 | 000,080,384 | —- | M] () – C:\Users\Manjula\Desktop\MBRCheck.exe
[2011/03/05 19:28:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/03/05 19:28:17 | 3190,050,816 | -HS- | M] () – C:\hiberfil.sys
[2011/03/05 19:23:29 | 000,883,802 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/03/05 19:23:29 | 000,734,324 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/03/05 19:23:29 | 000,149,568 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/03/05 18:53:00 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2941801158-3006526266-1162735378-1000UA.job
[2011/03/05 08:53:01 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2941801158-3006526266-1162735378-1000Core.job
[2011/03/04 20:49:34 | 000,430,706 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/03/04 19:36:59 | 000,512,992 | —- | M] () – C:\Users\Manjula\Desktop\sdsetup.exe
[2011/03/04 08:58:37 | 000,420,619 | —- | M] () – C:\Windows\SysNative\drivers\vsconfig.xml
[2011/03/02 22:45:11 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/28 07:39:29 | 000,002,038 | -H– | M] () – C:\Users\Manjula\Documents\Default.rdp
[2011/02/12 20:51:35 | 000,001,017 | —- | M] () – C:\Users\Manjula\Desktop\charttest.csv
[2011/02/12 08:42:58 | 001,222,775 | —- | M] () – C:\Users\Manjula\Desktop\There is an Ocean.jpg
[2011/02/10 03:19:10 | 000,352,360 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/05 19:30:58 | 000,080,384 | —- | C] () – C:\Users\Manjula\Desktop\MBRCheck.exe
[2011/03/04 19:37:22 | 000,512,992 | —- | C] () – C:\Users\Manjula\Desktop\sdsetup.exe
[2011/03/02 22:45:11 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/19 17:42:28 | 000,001,307 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/02/19 17:42:12 | 000,001,376 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/02/19 17:41:41 | 000,001,460 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/02/19 17:41:06 | 000,002,488 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/02/12 20:22:03 | 000,001,017 | —- | C] () – C:\Users\Manjula\Desktop\charttest.csv
[2011/01/20 17:06:17 | 000,000,095 | —- | C] () – C:\Users\Manjula\AppData\Local\fusioncache.dat
[2010/12/26 10:07:30 | 000,230,912 | —- | C] () – C:\Windows\SysWow64\Zipit.dll
[2010/12/26 10:07:18 | 000,314,880 | —- | C] () – C:\Windows\SysWow64\Tx32.dll
[2010/12/23 11:10:09 | 000,000,016 | —- | C] () – C:\Users\Manjula\AppData\Roaming\vedsadsat
[2010/10/08 20:28:57 | 000,900,374 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/09/10 19:17:38 | 000,819,200 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/09/10 19:17:38 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/07/07 06:10:51 | 000,000,013 | -H– | C] () – C:\ProgramData\1ÌØ13.sys
[2010/02/16 19:15:11 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/09/30 05:08:15 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/09/30 05:08:13 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/09/30 05:08:13 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/09/30 05:08:12 | 000,433,024 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/09/30 02:44:21 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2010/10/17 10:37:48 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\Blender Foundation
[2010/03/02 19:44:42 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\CheckPoint
[2010/03/30 21:16:31 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\com.desktopreporting.flex.polaris.D45E9FAD25C0AD532F3E3C235E51131DC132F796.
1
[2010/12/23 13:21:43 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\FileZilla
[2011/02/27 19:29:34 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\Hoyle
[2010/12/31 09:27:53 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\Hoyle FaceCreator
[2010/06/01 19:49:58 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\ICAClient
[2010/12/26 07:54:01 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\mypanchang.com
[2010/08/29 08:04:01 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\ooVoo Details
[2010/06/01 19:49:18 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\Runaware
[2011/02/22 19:49:44 | 000,000,000 | —D | M] – C:\Users\Manjula\AppData\Roaming\Windows Live Writer
[2011/02/05 07:56:32 | 000,032,630 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/12/01 17:11:14 | 000,001,024 | —- | M] () – C:\.rnd
[2009/08/18 22:17:02 | 000,106,427 | —- | M] () – C:\Build.Log
[2009/09/30 05:14:47 | 000,003,261 | RH– | M] () – C:\dell.sdr
[2011/03/05 19:28:17 | 3190,050,816 | -HS- | M] () – C:\hiberfil.sys
[2006/12/01 22:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/03/05 19:28:29 | 4253,405,184 | -HS- | M] () – C:\pagefile.sys
[2010/03/19 17:55:52 | 002,073,703 | —- | M] () – C:\VS_EXPBSLN_x64_enu.CAB
[2010/03/19 17:58:20 | 000,551,424 | —- | M] () – C:\VS_EXPBSLN_x64_enu.MSI

< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >


< MD5 for: EXPLORER.ADML >
[2009/07/13 20:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 14:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2009/07/13 19:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/10/30 23:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\SysWOW64\explorer.exe
[2009/10/30 23:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2009/08/03 00:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2009/10/31 00:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\explorer.exe
[2009/10/31 00:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 23:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/31 00:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 23:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 19:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 00:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009/08/03 00:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2008/04/29 09:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 20:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 20:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 20:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 20:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE.WINDOWS EXPLORER.MICROSOFT CORPORATION.6.1.7600.16450.ICO >
[2010/09/21 19:57:19 | 000,187,373 | —- | M] () MD5=59EF532FA50E1EC27DC50D43DA386BFB – C:\Users\Manjula\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\explorer.exe.Windows Explorer.Microsoft Corporation.6.1.7600.16450.ico

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2011/03/05 19:16:53 | 000,031,804 | —- | M] () MD5=A70A8BCF717BA7B7BDB1CB1D8B7A4E95 – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: IEXPLORE.EXE >
[2010/09/07 22:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2009/07/13 19:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2010/09/07 23:37:57 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2010/09/07 23:49:01 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2010/11/03 23:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_1a0bc510729d1f54\iexplore.exe
[2010/09/07 22:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2010/11/03 23:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1a75f2618bd22c48\iexplore.exe
[2010/12/18 00:17:48 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Program Files\Internet Explorer\iexplore.exe
[2010/12/18 00:17:48 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2010/12/18 00:11:10 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2010/12/17 23:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2010/12/17 23:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2010/12/17 23:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2010/11/04 00:37:41 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D8E00EA671A1EFE95C69C7566C505AD4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_0fb71abe3e3c5d59\iexplore.exe
[2010/11/04 00:42:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E220FB009F54AAF649C6A278A5156764 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1021480f57716a4d\iexplore.exe
[2009/07/13 19:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2008/04/29 09:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\iexplore.exe

< MD5 for: IEXPLORE.EXE.INTERNET EXPLORER.MICROSOFT CORPORATION.8.0.7600.16385.ICO >
[2010/09/12 10:32:21 | 000,097,527 | —- | M] () MD5=66BA3CA5EFAEC697C374EBCCE61061CF – C:\Users\Manjula\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\iexplore.exe.Internet Explorer.Microsoft Corporation.8.0.7600.16385.ico

< MD5 for: IEXPLORE.EXE.INTERNET EXPLORER.MICROSOFT CORPORATION.8.0.7600.16671.ICO >
[2010/12/01 18:47:52 | 000,097,527 | —- | M] () MD5=66BA3CA5EFAEC697C374EBCCE61061CF – C:\Users\Manjula\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\iexplore.exe.Internet Explorer.Microsoft Corporation.8.0.7600.16671.ico

< MD5 for: IEXPLORE.EXE.MUI >
[2009/07/13 20:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 20:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 20:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 20:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2011/03/04 19:18:37 | 000,217,676 | —- | M] () MD5=622F468BF2EB1BB50B31EAD8923B7993 – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf

< MD5 for: WINLOGON.ADML >
[2009/07/13 20:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 15:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/07/13 19:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 01:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 00:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\SysNative\winlogon.exe
[2009/10/28 00:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
[2008/07/01 07:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2009/07/13 20:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2009/07/13 20:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 20:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 20:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 14:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 14:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< C:\ProgramData\kFpNiJj06300\*.* /s >
[2011/03/05 19:17:50 | 000,000,098 | —- | M] () – C:\ProgramData\kFpNiJj06300\kFpNiJj06300
[2011/03/04 19:10:56 | 000,425,984 | —- | M] () – C:\ProgramData\kFpNiJj06300\kFpNiJj06300.exe

< End of report >
———————————————————————————————————————————–
Extras.txt

OTL Extras logfile created on: 3/5/2011 7:39:02 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\Manjula\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 278.92 Gb Total Space | 229.87 Gb Free Space | 82.41% Space Free | Partition Type: NTFS
Drive D: | 1.04 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DELL-LAPTOP | User Name: Manjula | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{59996900-0E6C-45B7-8C39-C64CB98462E4}" = Microsoft Web Platform Installer 2.0
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}" = Microsoft SQL Server 2008 Native Client
"{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{005F78AF-110D-398A-8430-BE98950A1E22}" = Google Talk Plugin
"{04F3038E-4120-44CC-B330-E05F737246A5}" = Roxio Update Manager
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07766F89-EFAA-4635-86B7-636B89EA2C0D}" = Bing Bar Platform
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{36C9E08A-BE2B-40A0-83C5-576748F7B777}" = TestDrive Client
"{4A47E0EC-6DE5-416C-AD38-25EB7BA1F115}" = Advanced Web Ranking 7.2
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{597E70FF-7C46-4EED-8092-91B7C2E0529D}" = Google SketchUp 7
"{5BDFAB82-060E-438B-AB4F-A2331B2294C0}" = Microsoft ASP.NET MVC 2 - VWD Express 2010 Tools
"{5C47C8B6-77FF-4FC7-A388-66FCF9CFC24C}" = Snagit 9.1.3
"{5D112C61-C8D0-4718-8DD7-B9115EB9AF90}" = LogMeIn
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85076DFF-7A17-3566-9CC0-488E6E6D4494}" = Microsoft Visual Web Developer 2010 Express - ENU
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B87C6F3B-E650-4722-9682-941F077B6AB9}" = Nakshatra Astrology Software for Windows by mypanchang.com
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{CB2094F9-F8DA-CC88-DF1D-6BAE7E20A915}" = Desktop Reporting - Polaris
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D65F8E34-C050-4E6C-86DB-D2B9075749A0}" = Windows Live Sync ActiveX Control for Remote Connections
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Amazon Games & Software Downloader_is1" = Amazon Games & Software Downloader
"Blender" = Blender (remove only)
"CoffeeCup Flash FireStarter" = CoffeeCup Flash FireStarter
"CoffeeCup Free Zip Wizard" = CoffeeCup Free Zip Wizard
"com.desktopreporting.flex.polaris.D45E9FAD25C0AD532F3E3C235E51131DC132F796.
1" = Desktop Reporting - Polaris
"Dell Webcam Central" = Dell Webcam Central
"FileZilla Client" = FileZilla Client 3.3.5.1
"GoToAssist" = GoToAssist 8.0.0.514
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Hoyle Casino Games 2011" = Hoyle Casino Games 2011 (remove only)
"Jagannatha Hora_is1" = Jagannatha Hora 7.4
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft Visual Web Developer 2010 Express - ENU" = Microsoft Visual Web Developer 2010 Express - ENU
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"ShipWorks_is1" = ShipWorks® 2.9.65
"Super Bounce Out_is1" = Super Bounce Out
"TR-2.2.1" = ThinkingRock-2.2.1
"WinLiveSuite" = Windows Live Essentials
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"ZoneAlarm Anti-virus" = ZoneAlarm Anti-virus

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 4.5.0.456
"Shapeways Editor" = Shapeways Editor

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/3/2011 12:16:22 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:16:22 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:16:22 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:16:22 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:16:22 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:16:22 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:16:22 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:25:40 AM | Computer Name = Dell-Laptop | Source = EventSystem | ID = 4622
Description =

Error - 3/3/2011 12:34:41 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 3/3/2011 12:34:41 AM | Computer Name = Dell-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ OSession Events ]
Error - 5/2/2010 11:45:09 AM | Computer Name = Dell-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 41
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/2/2010 6:37:02 PM | Computer Name = Dell-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 704
seconds with 120 seconds of active time. This session ended with a crash.

Error - 5/2/2010 6:37:12 PM | Computer Name = Dell-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/3/2010 8:34:40 AM | Computer Name = Dell-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 120
seconds with 60 seconds of active time. This session ended with a crash.

Error - 5/3/2010 8:34:50 AM | Computer Name = Dell-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/8/2010 9:03:42 PM | Computer Name = Dell-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 131864
seconds with 4620 seconds of active time. This session ended with a crash.

Error - 5/8/2010 9:05:16 PM | Computer Name = Dell-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 35
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/1/2011 12:54:17 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/1/2011 12:54:47 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/1/2011 12:55:17 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/1/2011 12:55:47 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/1/2011 12:56:17 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/1/2011 12:56:47 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/1/2011 12:57:17 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/1/2011 12:57:48 PM | Computer Name = Dell-Laptop | Source = Service Control Manager | ID = 7023
Description = The LogMeIn service terminated with the following error: %%10013

Error - 1/10/2011 10:50:46 AM | Computer Name = Dell-Laptop | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 1/10/2011 10:50:49 AM | Computer Name = Dell-Laptop | Source = volsnap | ID = 393230
Description = The shadow copies of volume C: were aborted because of an IO failure
on volume C:.


< End of report >
—————————————————————————————-
Hi saicool171,

Are you still receiving the infected warning messages?

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\ProgramData\kFpNiJj06300

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Please open OTL if it is not opened after the reboot.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following

    C:\Users\Manjula\AppData\Local\{2DFBAF16-D87E-4BB4-917F-9CC5698A22FB}\*.* /s
    C:\Users\Manjula\AppData\Local\{7B645DC7-CD2A-4D3C-AF75-18B0C302D4E8}\*.* /s
    C:\Users\Manjula\AppData\Local\{5C012C4D-EA9E-4E01-8CFF-F8E59CB10E1F}\*.* /s
    C:\Users\Manjula\AppData\Local\{2069C49D-C48B-4856-A19E-6FF82EEA424E}\*.* /s
    C:\Users\Manjula\AppData\Local\{098EE9C9-DC1E-44B6-88F6-E53B62894E0A}\*.* /s
    C:\Users\Manjula\AppData\Local\{1AC59F79-E40B-47CA-8212-42BFC348B300}\*.* /s
    C:\Users\Manjula\AppData\Local\{746BD617-67AD-45B8-926D-8962849A3164}\*.* /s
    C:\Users\Manjula\AppData\Local\{75EA055D-6291-4D38-8651-418395DF34E3}\*.* /s
    C:\Users\Manjula\AppData\Local\{826C21ED-8CE3-459C-84F1-55B69D21852D}\*.* /s
    C:\ProgramData\cMdLoBg06300\*.* /s


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Please post back with
  • OTL fix log
  • OTL.txt
How's the computer?

Thanks
Hi oldman960,

The computer is running well and I'm not getting any messages, desktop has reverted back to normal - everything looks great - but I'll let your expert eyes review the logs and let me know if we are all clear or there are additional steps to take.

Again, thank you so much,

Saicool

OTL Fix Log:
—————–


All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
C:\ProgramData\kFpNiJj06300 folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Manjula
->Temp folder emptied: 64614854 bytes
->Temporary Internet Files folder emptied: 119331703 bytes
->Java cache emptied: 54292239 bytes
->FireFox cache emptied: 58981491 bytes
->Google Chrome cache emptied: 436237098 bytes
->Flash cache emptied: 203199 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 48350124 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67630 bytes
RecycleBin emptied: 1659105762 bytes

Total Files Cleaned = 2,328.00 mb


OTL by OldTimer - Version 3.2.22.2 log created on 03062011_082003

Files\Folders moved on Reboot…
C:\Users\Manjula\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Manjula\AppData\Local\Temp\~DFA306C94858969C97.TMP moved successfully.
File\Folder C:\Windows\temp\av16F5.tmp not found!
C:\Windows\temp\iswift.dat moved successfully.
C:\Windows\temp\sfdb.dat moved successfully.
C:\Windows\temp\ZLT06a8a.TMP moved successfully.

Registry entries deleted on Reboot…

——————————————————————————-


OTL.txt
———-

OTL logfile created on: 3/6/2011 8:41:18 AM - Run 2
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\Manjula\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 278.92 Gb Total Space | 235.07 Gb Free Space | 84.28% Space Free | Partition Type: NTFS
Drive D: | 1.04 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DELL-LAPTOP | User Name: Manjula | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< C:\Users\Manjula\AppData\Local\{2DFBAF16-D87E-4BB4-917F-9CC5698A22FB}\*.* /s >

< C:\Users\Manjula\AppData\Local\{7B645DC7-CD2A-4D3C-AF75-18B0C302D4E8}\*.* /s >

< C:\Users\Manjula\AppData\Local\{5C012C4D-EA9E-4E01-8CFF-F8E59CB10E1F}\*.* /s >

< C:\Users\Manjula\AppData\Local\{2069C49D-C48B-4856-A19E-6FF82EEA424E}\*.* /s >

< C:\Users\Manjula\AppData\Local\{098EE9C9-DC1E-44B6-88F6-E53B62894E0A}\*.* /s >

< C:\Users\Manjula\AppData\Local\{1AC59F79-E40B-47CA-8212-42BFC348B300}\*.* /s >

< C:\Users\Manjula\AppData\Local\{746BD617-67AD-45B8-926D-8962849A3164}\*.* /s >

< C:\Users\Manjula\AppData\Local\{75EA055D-6291-4D38-8651-418395DF34E3}\*.* /s >

< C:\Users\Manjula\AppData\Local\{826C21ED-8CE3-459C-84F1-55B69D21852D}\*.* /s >

< C:\ProgramData\cMdLoBg06300\*.* /s >
[2011/03/02 21:35:56 | 000,000,098 | —- | M] () – C:\ProgramData\cMdLoBg06300\cMdLoBg06300

< End of report >
Hi saicool171,

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Users\Manjula\AppData\Local\{2DFBAF16-D87E-4BB4-917F-9CC5698A22FB}
C:\Users\Manjula\AppData\Local\{7B645DC7-CD2A-4D3C-AF75-18B0C302D4E8}
C:\Users\Manjula\AppData\Local\{5C012C4D-EA9E-4E01-8CFF-F8E59CB10E1F}
C:\Users\Manjula\AppData\Local\{2069C49D-C48B-4856-A19E-6FF82EEA424E}
C:\Users\Manjula\AppData\Local\{098EE9C9-DC1E-44B6-88F6-E53B62894E0A}
C:\Users\Manjula\AppData\Local\{1AC59F79-E40B-47CA-8212-42BFC348B300}
C:\Users\Manjula\AppData\Local\{746BD617-67AD-45B8-926D-8962849A3164}
C:\Users\Manjula\AppData\Local\{75EA055D-6291-4D38-8651-418395DF34E3}
C:\Users\Manjula\AppData\Local\{826C21ED-8CE3-459C-84F1-55B69D21852D}
C:\ProgramData\cMdLoBg06300

:Commands
[createrestorepoint]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTL fix log
  • MBAM log
Thanks
Hi oldman960, I ran the OTL Fix as per the instructions but didn't see the OTL Fix Log. I got a message that a reboot was needed so I clicked ok to reboot. After reboot OTL didn't open automatically. I opened it manually but couldn't find a log. I then ran mbam - it said no infections found so there was nothing to select and remove. The log is below. Please let me know if I'm missing something on the OTL Fix log and how I can get that information over to you. Thanks, Saicool. MBAM- log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5975 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 3/6/2011 1:54:10 PM mbam-log-2011-03-06 (13-54-10).txt Scan type: Quick scan Objects scanned: 162797 Time elapsed: 4 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) —————————————————————————-
Hi saicool171,

The OTL fix log can be found at C:\_OTL\MovedFiles It will have a file name consisting of numbers that reflect the date and time stamp the fix was ran. It will be something similar to 03062011_111009.log . Please copy and paste the contents into your next reply.

One more scan just to check our handiwork,

As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

Please post back with the ESET log.

Thanks
Hi oldman960, Thanks for the pointer on the OTL log file. Below are both the logs (OTL and ESET). I'll wait to hear back from you on next steps or if we are all clean. Again, thanks much for your time and help, Saicool. OTL Log from 3/6: ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Users\Manjula\AppData\Local\{2DFBAF16-D87E-4BB4-917F-9CC5698A22FB} folder moved successfully. C:\Users\Manjula\AppData\Local\{7B645DC7-CD2A-4D3C-AF75-18B0C302D4E8} folder moved successfully. C:\Users\Manjula\AppData\Local\{5C012C4D-EA9E-4E01-8CFF-F8E59CB10E1F} folder moved successfully. C:\Users\Manjula\AppData\Local\{2069C49D-C48B-4856-A19E-6FF82EEA424E} folder moved successfully. C:\Users\Manjula\AppData\Local\{098EE9C9-DC1E-44B6-88F6-E53B62894E0A} folder moved successfully. C:\Users\Manjula\AppData\Local\{1AC59F79-E40B-47CA-8212-42BFC348B300} folder moved successfully. C:\Users\Manjula\AppData\Local\{746BD617-67AD-45B8-926D-8962849A3164} folder moved successfully. C:\Users\Manjula\AppData\Local\{75EA055D-6291-4D38-8651-418395DF34E3} folder moved successfully. C:\Users\Manjula\AppData\Local\{826C21ED-8CE3-459C-84F1-55B69D21852D} folder moved successfully. C:\ProgramData\cMdLoBg06300 folder moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.22.2 log created on 03062011_133820 —————————————————————————————————————————————- ESET Log: ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255) # OnlineScanner.ocx=1.0.0.6425 # api_version=3.0.2 # EOSSerial=9557e05288cf5e4c80e0800ad0e928ff # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-03-07 02:51:23 # local_time=2011-03-07 08:51:23 (-0600, Central Standard Time) # country="United States" # lang=9 # osver=6.1.7600 NT # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776573 100 94 0 51049939 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16776893 100 77 0 15514567 0 0 # scanned=88184 # found=0 # cleaned=0 # scan_time=2994 ———————————————————————————————————————————–
Hi saicool171,


Everthing looks good from here.

We'll clean up the tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • MBRCheck

Next

*Create a new Restore point*

  • Click on the Start button to open your Start Menu.
  • Click on the Control Panel menu option.
  • Click on the System and Maintenance menu option.
  • Click on the System menu option.
  • Click on System Protection in the left-hand task list.
  • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
  • Type in a title for the manual restore point and press the Create button.
  • Close the System window after you have been advised that the procedure has been successfully completed.

    *Clear out the old Restore points*
  • Next, go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Choose the option to clean up system restore and Ok it
This will remove all restore points except the most recent one.

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep MBAM updated and use it regularly.

ESET can be uninstalled via add/remove programs.


Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You seem well on your way to building a secure system.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Hi oldman960, Thank you for your help. I've followed all of the steps provided in your post and completed the process. I have one question: I missed deleting 3 MBRCheck text/log files. I realized it only much later. Can I just delete those or do I need to go thru additional steps after deleting those. My apologies about the mess up there and taking up your time with this. Thanks again, Saicool

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI