This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rootkit Infected Boot Sector

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair: A friend has 2 computers that were run with expired anti-virus programs. This one was "protected" with avg2011 that is infected. Malwarebytes showed over 140 infections to start with including Trojan.Downloads, Trojan.Qhost, Spyware.Passwords.Xgen, My Web Search, Broken.Open command, Security.Hijack, Trojan.Agent, Adware.iwon, Pup.funweb, Trojan.Fakelaert, Trojan.zbotR.gen. I installed Avast so she would have some protection while we work on this. Avast finds and tries unsuccessfully to remove an infection in the master boot record. I think it may be Win95:Dupator in C:\hiberfil.sys.

Unfortunately, this computer has Windows XP Service Pack 2. Service Pack 3 has been downloaded and is ready to install. Is this safe to do with an infected MBR?

I would really appreciate your assistance. -Jcatsmom

Here are my scans.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:21:59 PM, on 3/25/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Ed\Desktop\Computer stuff\HJThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Charter Communications
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Charter Toolbar - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Charter Toolbar - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} (iWon Progressive Counter) - http://cc.iwon.com/ct/pm3/iWonPMSetup_12_1,0,2,5.exe
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 7481 bytes

OTL logfile created on: 3/25/2011 4:30:01 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Ed\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 712.00 Mb Available Physical Memory | 70.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.07 Gb Total Space | 10.92 Gb Free Space | 57.25% Space Free | Partition Type: FAT32

Computer Name: ED-7480603707F7 | User Name: Ed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ed\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Walgreens\Walgreens PhotoShow\data\Xtras\mssysmgr.exe (Simple Star, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Program Files\AOL Companion\companion.exe ()
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Ed\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (TermService) – C:\WINDOWS\system32\termsrv.dll ()
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (gameenum) Crystal SoundFusion™ – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (NtApm) – C:\WINDOWS\system32\drivers\NtApm.sys (Microsoft Corporation)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (MidiSyn) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (USRpdA) – C:\WINDOWS\system32\drivers\USRpdA.sys (U.S. Robotics Corporation)
DRV - (cwcwdm) Crystal SoundFusion™ – C:\WINDOWS\system32\drivers\cwcwdm.sys (Crystal Semiconductor Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\1.bin
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/25 15:31:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2006/05/21 00:26:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2006/05/21 00:26:12 | 000,000,000 | —D | M]

[2009/01/25 14:14:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ed\Application Data\Mozilla\Extensions
[2006/06/04 00:58:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\8boq2fdr.default\extensions
[2006/06/04 00:59:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2004/02/20 13:14:10 | 000,176,177 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2006/01/18 12:50:00 | 000,319,488 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll

O1 HOSTS File: ([2011/02/18 15:40:12 | 000,001,003 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 thepiratebay.org
O1 - Hosts: 127.0.0.1 www.thepiratebay.org
O1 - Hosts: 127.0.0.1 mininova.org
O1 - Hosts: 127.0.0.1 www.mininova.org
O1 - Hosts: 127.0.0.1 forum.mininova.org
O1 - Hosts: 127.0.0.1 blog.mininova.org
O1 - Hosts: 127.0.0.1 suprbay.org
O1 - Hosts: 127.0.0.1 www.suprbay.org
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [USRpdA] File not found
O4 - HKCU..\Run: [PhotoShow Deluxe Media Manager] C:\Program Files\Walgreens\Walgreens PhotoShow\data\Xtras\mssysmgr.exe (Simple Star, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AOL; Toolbar Search - c:\Program Files\AOL\AOL Toolbar 2.0\resources\en-us\local\search.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} http://cc.iwon.com/ct/pm3/iWonPMSetup_12_1,0,2,5.exe (iWon Progressive Counter)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Ed\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ed\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/10 10:31:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{aa64bbc2-379a-11db-b3c9-00038a000015}\Shell\AutoRun\command - "" = F:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/25 16:28:08 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Ed\Desktop\OTL.exe
[2011/03/25 16:08:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2011/03/25 15:32:13 | 000,019,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/03/25 15:32:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/03/25 15:32:12 | 000,301,528 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/03/25 15:32:03 | 000,025,432 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/03/25 15:32:02 | 000,049,240 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/03/25 15:32:01 | 000,371,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/03/25 15:32:00 | 000,102,232 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/03/25 15:32:00 | 000,096,344 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/03/25 15:31:59 | 000,030,680 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/03/25 15:31:42 | 000,190,016 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/03/25 15:31:42 | 000,040,648 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/03/25 15:31:35 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/03/25 15:31:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/25 14:52:36 | 000,000,000 | -HSD | C] – C:\FOUND.012
[2011/03/25 14:32:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Ed\Application Data\Malwarebytes
[2011/03/25 14:32:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/25 14:32:09 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/25 14:32:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/03/25 14:32:05 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/25 14:32:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/25 14:30:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Ed\Desktop\Computer stuff
[2011/03/25 14:12:40 | 000,000,000 | -HSD | C] – C:\FOUND.011
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/25 16:28:12 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ed\Desktop\OTL.exe
[2011/03/25 16:15:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/25 16:13:42 | 1072,943,104 | -HS- | M] () – C:\hiberfil.sys
[2011/03/25 15:32:14 | 000,001,593 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/03/25 15:32:02 | 000,002,625 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/03/25 15:31:04 | 062,623,864 | —- | M] () – C:\Documents and Settings\Ed\Desktop\setup_av_free.exe
[2011/03/25 15:13:40 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpFB8D6.FOT
[2011/03/25 15:13:40 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpD09D6.FOT
[2011/03/25 15:13:40 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpB69D6.FOT
[2011/03/25 15:13:40 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp9B9D6.FOT
[2011/03/25 15:13:40 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp61AD6.FOT
[2011/03/25 15:13:40 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp158D6.FOT
[2011/03/25 15:10:34 | 000,104,609 | —- | M] () – C:\VETlog.dmp
[2011/03/25 15:08:14 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/03/25 14:32:12 | 000,000,688 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/25 14:22:00 | 000,000,214 | —- | M] () – C:\BOOT.INI
[2011/03/25 14:13:00 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/25 15:32:13 | 000,001,593 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/03/25 15:30:30 | 062,623,864 | —- | C] () – C:\Documents and Settings\Ed\Desktop\setup_av_free.exe
[2011/03/25 15:13:38 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpFB8D6.FOT
[2011/03/25 15:13:38 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpD09D6.FOT
[2011/03/25 15:13:38 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpB69D6.FOT
[2011/03/25 15:13:38 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp9B9D6.FOT
[2011/03/25 15:13:38 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp61AD6.FOT
[2011/03/25 15:13:38 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp158D6.FOT
[2011/03/25 14:32:10 | 000,000,688 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/03 12:29:34 | 000,166,928 | —- | C] () – C:\WINDOWS\MAMLPRE.DLL
[2009/03/03 12:29:34 | 000,027,936 | —- | C] () – C:\WINDOWS\MDBA.DLL
[2009/03/03 12:29:34 | 000,008,144 | —- | C] () – C:\WINDOWS\MYBC.INI
[2009/03/03 12:29:31 | 000,000,360 | —- | C] () – C:\WINDOWS\label.ini
[2009/03/03 12:29:27 | 000,000,052 | —- | C] () – C:\WINDOWS\odbcddp.ini
[2008/06/02 20:22:06 | 000,147,588 | —- | C] () – C:\WINDOWS\hpoins21.dat
[2008/06/02 20:22:06 | 000,008,138 | —- | C] () – C:\WINDOWS\hpomdl21.dat
[2008/01/07 18:33:07 | 000,141,260 | —- | C] () – C:\WINDOWS\hpoins14.dat
[2008/01/07 18:33:07 | 000,002,000 | —- | C] () – C:\WINDOWS\hpomdl14.dat
[2007/05/30 18:38:57 | 000,100,724 | —- | C] () – C:\WINDOWS\cpeins04.dat
[2007/05/30 18:38:57 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2007/05/30 18:35:41 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/10/17 11:50:08 | 000,000,309 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/10/17 10:45:12 | 000,003,584 | —- | C] () – C:\Documents and Settings\Ed\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/26 00:15:40 | 000,000,125 | —- | C] () – C:\Documents and Settings\Ed\Local Settings\Application Data\fusioncache.dat
[2006/09/25 21:54:36 | 000,104,182 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2006/09/25 21:54:36 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2006/06/10 09:11:23 | 000,000,619 | —- | C] () – C:\WINDOWS\aolback.exe.lnk
[2006/06/10 08:31:31 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/06/09 20:38:19 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2006/06/04 03:55:41 | 000,000,035 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2006/06/04 00:58:58 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/05/22 00:26:57 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/05/22 00:26:55 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/05/21 00:30:17 | 000,001,181 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/21 00:27:06 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2006/05/21 00:26:13 | 000,004,126 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/05/20 23:23:44 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2006/05/20 23:23:44 | 000,004,962 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2006/05/20 23:23:42 | 000,005,120 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2006/05/20 23:23:42 | 000,003,328 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2006/05/20 23:22:16 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2006/05/20 23:18:48 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/05/20 23:18:46 | 000,003,699 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/05/20 23:18:45 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/05/10 10:57:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/05/10 10:20:48 | 000,022,720 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/05/10 10:17:55 | 000,215,552 | —- | C] () – C:\WINDOWS\System32\termsrv.dll
[2006/05/10 09:57:49 | 000,005,466 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/05/10 09:55:16 | 000,132,480 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/09/01 12:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/09/01 12:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/09/01 12:00:00 | 000,380,680 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/09/01 12:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/09/01 12:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/09/01 12:00:00 | 000,052,968 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/09/01 12:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/09/01 12:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/09/01 12:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/09/01 12:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/09/01 12:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/09/01 12:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/09/01 12:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2006/06/10 07:26:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/01/14 12:25:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2011/03/25 15:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2006/06/19 23:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\Snapfish
[2006/06/23 17:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\Walgreens
[2006/06/23 17:31:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\Simple Star
[2007/02/24 20:28:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\acccore
[2007/02/26 12:58:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\Aim
[2007/02/28 14:55:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\Viewpoint
[2011/02/03 13:02:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\CHARTERTOOLBAR
[2011/02/18 15:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\Ulel
[2011/02/18 15:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Ed\Application Data\Foyxd

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[1999/04/23 22:22:00 | 000,222,390 | RHS- | M] () – C:\IO.SYS
[1999/04/23 22:22:00 | 000,000,009 | RHS- | M] () – C:\MSDOS.SYS
[1999/04/23 22:22:00 | 000,093,890 | -HS- | M] () – C:\COMMAND.COM
[1999/04/23 22:22:00 | 000,068,871 | RHS- | M] () – C:\DRVSPACE.BIN
[2006/05/20 23:42:06 | 000,000,000 | -H– | M] () – C:\BOOTLOG.TXT
[1995/07/11 09:50:00 | 000,069,886 | —- | M] () – C:\EDIT.COM
[2011/03/25 14:22:00 | 000,000,214 | —- | M] () – C:\BOOT.INI
[2006/05/10 09:53:46 | 000,000,512 | -HS- | M] () – C:\bootsect.dos
[2006/05/10 10:31:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/05/10 10:31:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/05/20 22:38:32 | 000,000,000 | -HS- | M] () – C:\BOOTLOG.PRV
[2011/03/25 16:13:42 | 1072,943,104 | -HS- | M] () – C:\hiberfil.sys
[2011/03/25 16:15:36 | 1610,612,736 | -HS- | M] () – C:\PAGEFILE.SYS
[2004/09/01 12:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2004/09/01 12:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/03/25 15:10:34 | 000,104,609 | —- | M] () – C:\VETlog.dmp
[2011/03/25 15:10:34 | 000,062,687 | —- | M] () – C:\VETlog.txt
[2006/05/22 00:27:06 | 008,659,788 | —- | M] () – C:\BellSouthIW.re~
[2006/06/10 07:39:50 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2006/06/10 07:39:50 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2003/12/08 13:15:56 | 000,028,672 | R— | M] ( ) – C:\hpqimgrc.resources.dll

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/05/20 23:12:10 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/03/28 13:57:34 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[1 C:\WINDOWS\system32\spool\prtprocs\w32x86\*.tmp files -> C:\WINDOWS\system32\spool\prtprocs\w32x86\*.tmp -> ]

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/23 10:04:22 | 000,040,648 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2005/05/19 15:10:22 | 000,294,912 | —- | M] (Simple Star, Inc.) – C:\WINDOWS\Walgreens PhotoShow.scr
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/05/20 23:04:04 | 003,670,016 | —- | M] () – C:\WINDOWS\system32\config\system.sav
[2006/05/20 23:04:04 | 008,912,896 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/05/20 23:04:04 | 000,262,144 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/05/13 12:33:28 | 000,262,144 | —- | M] () – C:\WINDOWS\system32\config\security.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2006/05/20 23:12:38 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/05/20 23:17:40 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Ed\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/05/20 23:17:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\Ed\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2007/02/26 12:57:04 | 008,506,408 | —- | M] () – C:\Documents and Settings\Ed\Desktop\Install_AIM59.exe
[2011/02/03 13:34:40 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Ed\Desktop\IE8-WindowsXP-x86-ENU.exe
[2011/03/25 15:31:04 | 062,623,864 | —- | M] () – C:\Documents and Settings\Ed\Desktop\setup_av_free.exe
[2011/03/25 16:28:12 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ed\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

OTL Extras logfile created on: 3/25/2011 4:30:01 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Ed\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 712.00 Mb Available Physical Memory | 70.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.07 Gb Total Space | 10.92 Gb Free Space | 57.25% Space Free | Partition Type: FAT32

Computer Name: ED-7480603707F7 | User Name: Ed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed
"C:\Program Files\Common Files\AOL\1149949539\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1149949539\EE\AOLServiceHost.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL
"C:\Program Files\Real\RealPlayer\REALPLAY.EXE" = C:\Program Files\Real\RealPlayer\REALPLAY.EXE:*:Disabled:RealPlayer – (RealNetworks, Inc.)
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger
"C:\Program Files\AIM6\AIM6.EXE" = C:\Program Files\AIM6\AIM6.EXE:*:Enabled:AIM
"C:\Program Files\Yahoo! Games\Cubis Gold 2\cubis2.exe" = C:\Program Files\Yahoo! Games\Cubis Gold 2\cubis2.exe:*:Enabled:cubis2
"C:\Program Files\HP\Digital Imaging\BIN\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\BIN\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hposid01.exe" = C:\Program Files\HP\Digital Imaging\BIN\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqcopy.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqcopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\BIN\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\WINDOWS\EXPLORER.EXE" = C:\WINDOWS\EXPLORER.EXE:*:Disabled:Windows Explorer – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{2F71F2BA-B513-4113-969C-18A84D238E27}" = 1310
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{706BB40A-4102-4c89-8107-DC68C4EBD19B}" = HP Deskjet All-In-One Software 9.0
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{80413011-029C-4D6B-B3AD-725DDE60B81C}" = 1310Trb
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A3FD0CA9-884F-4525-97B8-0AE6179302E6}" = F2100
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A73ACE08-4CA7-4d08-912E-EFE4DF521B39}" = c7200_Help
"{A9C365A3-06C0-43b4-A2DB-EDF0A6079AA9}" = DJ_AIO_Software
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B4B1F18B-5CED-4f8f-8A8F-1BD0503C222E}" = DJ_AIO_ProductContext
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{B7FB6B99-C93C-4818-825B-37EF4B64C80C}" = PS_AIO_02_Software
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C4A978A3-CAE4-4856-89D5-696498A7B8F7}" = HPODiscovery
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDC7BEC8-D631-4e36-81D7-FC3689209AA6}" = F2100_Help
"{CE325D55-FCAF-4273-BB79-069BB8747270}" = TomTom HOME
"{CE4888DB-CE49-485b-AA3A-A9E0F361B277}" = C7200
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D25BDCF5-19F6-4d9e-B9C9-273FE81446C4}" = PS_AIO_02_ProductContext
"{D64BC2CF-0F12-47d7-B412-B4F3FD684253}" = HP Photosmart All-In-One Software 9.0
"{E21658D0-8C83-4ADD-937B-6ED07F335ABA}" = 1310Tour
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E90BEB5B-CFA0-418E-9ABB-4C4A7B0D9483}" = 1310_Help
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EB48851B-96A4-489f-9F95-29F3731E9764}" = F2100_doccd
"{EF0D2E55-6FE2-4e35-BE22-A742E85D84E3}" = PS_AIO_02_Software_min
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F56D6F46-1D62-4734-BF12-6457A1ED17BD}" = DJ_AIO_Software_min
"{F619E2AF-677D-49bc-9618-D60BDFB925DB}" = C7200_doccd
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Toolbar" = AOL Toolbar 2.0
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach" = AOL Coach Version 1.0(Build:20030807.3)
"ASIO4ALL" = ASIO4ALL
"avast" = avast! Free Antivirus
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"chartertoolbar" = Charter Toolbar
"Collab" = Collab
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photo & Imaging" = HP Image Zone 4.2
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"ie8" = Windows Internet Explorer 8
"IL Download Manager" = IL Download Manager
"Insaniquarium Deluxe 1.0" = Insaniquarium Deluxe 1.0
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"MSNINST" = MSN
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"StreetPlugin" = Learn2 Player (Uninstall Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VUInstRhine" = VIA Rhine Family Fast Ethernet Adapter
"Walgreens PhotoShow Express" = Walgreens PhotoShow Express

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/10/2011 4:48:27 PM | Computer Name = ED-7480603707F7 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdo…authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 1/10/2011 4:48:27 PM | Computer Name = ED-7480603707F7 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdo…authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 1/11/2011 5:16:17 PM | Computer Name = ED-7480603707F7 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/3/2011 1:42:25 PM | Computer Name = ED-7480603707F7 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/18/2011 4:28:42 PM | Computer Name = ED-7480603707F7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/18/2011 4:28:43 PM | Computer Name = ED-7480603707F7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This network connection does not exist.

Error - 2/18/2011 4:38:25 PM | Computer Name = ED-7480603707F7 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00021260.

Error - 2/18/2011 6:23:33 PM | Computer Name = ED-7480603707F7 | Source = Application Error | ID = 1001
Description = Fault bucket 188608198.

Error - 3/25/2011 3:36:51 PM | Computer Name = ED-7480603707F7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 3/25/2011 3:36:51 PM | Computer Name = ED-7480603707F7 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 3/25/2011 4:44:24 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7001
Description = The Fast User Switching Compatibility service depends on the Terminal
Services service which failed to start because of the following error: %%193

Error - 3/25/2011 4:44:24 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%193

Error - 3/25/2011 5:04:39 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7001
Description = The Fast User Switching Compatibility service depends on the Terminal
Services service which failed to start because of the following error: %%193

Error - 3/25/2011 5:04:39 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%193

Error - 3/25/2011 5:04:39 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%193

Error - 3/25/2011 5:13:00 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7001
Description = The Fast User Switching Compatibility service depends on the Terminal
Services service which failed to start because of the following error: %%193

Error - 3/25/2011 5:13:00 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%193

Error - 3/25/2011 5:18:04 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7001
Description = The Fast User Switching Compatibility service depends on the Terminal
Services service which failed to start because of the following error: %%193

Error - 3/25/2011 5:18:04 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%193

Error - 3/25/2011 5:18:04 PM | Computer Name = ED-7480603707F7 | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%193


< End of report >
Hi Jcatsmom,


My name is Blottedisk and I will be helping you with your malware issues. Before we delve into this, please take a look at the following notes:

  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
  • The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.

Let's wait until the machine is clean to update to SP3. The update procedure can conflict with the infections. Please follow these steps:


Step 1 | Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it


Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure all options are checked except:
  • IAT/EAT
  • Drives/Partition other than Systemdrive, which is typically C:\
  • Show All (This is important, so do not miss it.)

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.


Step 3 | Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Blottedisk, Thank you for your lightning fast reply. All 3 scans showed rootkit infection. I am sending GMER log in 2 parts because it is too large for one report.

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000001d

Kernel Drivers (total 124):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806CE000 \WINDOWS\system32\hal.dll
0x86783000 \WINDOWS\system32\KDCOM.DLL
0xF79F0000 \WINDOWS\system32\BOOTVID.dll
0xF74AD000 ACPI.sys
0xF7ADC000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF749C000 pci.sys
0xF75DC000 isapnp.sys
0xF7ADE000 viaide.sys
0xF785C000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7AE0000 aliide.sys
0xF75EC000 MountMgr.sys
0xF747D000 ftdisk.sys
0xF7AE2000 dmload.sys
0xF7457000 dmio.sys
0xF7864000 PartMgr.sys
0xF75FC000 VolSnap.sys
0xF743F000 atapi.sys
0xF760C000 disk.sys
0xF761C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7420000 fltMgr.sys
0xF740E000 sr.sys
0xF73EB000 Fastfat.sys
0xF73D4000 KSecDD.sys
0xF73A7000 NDIS.sys
0xF738C000 Mup.sys
0xF762C000 alim1541.sys
0xF763C000 gagp30kx.sys
0xF2F70000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xF2F5C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF48CB000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF48BB000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF48AB000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF2F39000 \SystemRoot\system32\DRIVERS\ks.sys
0xF4AE1000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF2F16000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF4AD9000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF3B7D000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF3CB0000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF3CA8000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF7B48000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0xF3B6D000 \SystemRoot\system32\DRIVERS\serial.sys
0xF54B9000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF2E12000 \SystemRoot\system32\DRIVERS\parport.sys
0xF2DD0000 \SystemRoot\system32\drivers\smwdm.sys
0xF2DAC000 \SystemRoot\system32\drivers\portcls.sys
0xF3B5D000 \SystemRoot\system32\drivers\drmk.sys
0xF2D90000 \SystemRoot\system32\drivers\aeaudio.sys
0xF2D32000 \SystemRoot\system32\drivers\senfilt.sys
0xF3B4D000 \SystemRoot\system32\DRIVERS\fetnd5b.sys
0xF3B3D000 \SystemRoot\system32\DRIVERS\AmdK8.sys
0xF34F9000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF3B2D000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF54B5000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF2D1B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF3B1D000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF3B0D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF3CA0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF2D0A000 \SystemRoot\system32\DRIVERS\psched.sys
0xF3AFD000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF3C98000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF3C90000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF3C88000 \SystemRoot\system32\DRIVERS\wanatw4.sys
0xF2CD9000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF3AED000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF3C80000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7B4A000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF2CA5000 \SystemRoot\system32\DRIVERS\update.sys
0xF4EC9000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF77EC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF77FC000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7AF8000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF78DC000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xF7AFA000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xEF7A4000 \SystemRoot\System32\Drivers\Null.SYS
0xF7B2C000 \SystemRoot\System32\Drivers\Beep.SYS
0xF78FC000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF7904000 \SystemRoot\System32\drivers\vga.sys
0xF7B26000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7AFC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF790C000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7914000 \SystemRoot\System32\Drivers\Npfs.SYS
0xEFD51000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xEF5F4000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xEF59C000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF781C000 \SystemRoot\System32\Drivers\aswTdi.SYS
0xEF574000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF791C000 \SystemRoot\System32\Drivers\aswRdr.SYS
0xEF552000 \SystemRoot\System32\drivers\afd.sys
0xF782C000 \SystemRoot\system32\DRIVERS\netbios.sys
0xEF526000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xEF4B7000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF784C000 \SystemRoot\System32\Drivers\Fips.SYS
0xEF496000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF766C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xEF44E000 \SystemRoot\System32\Drivers\aswSP.SYS
0xEF3F0000 \SystemRoot\System32\Drivers\aswSnx.SYS
0xF7AFE000 \SystemRoot\system32\drivers\AsIO.sys
0xF794C000 \SystemRoot\System32\Drivers\Aavmker4.SYS
0xF7974000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xEF63F000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF768C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xEF637000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xF48EB000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEF3D8000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7B28000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xEFE59000 \SystemRoot\System32\drivers\Dxapi.sys
0xF79BC000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7C99000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xF7A80000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0xEDD14000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xEDC79000 \SystemRoot\System32\Drivers\aswMon2.SYS
0xED4AE000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xED471000 \SystemRoot\system32\drivers\wdmaud.sys
0xED573000 \SystemRoot\system32\drivers\sysaudio.sys
0xF7B18000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xED3F5000 \SystemRoot\system32\drivers\kmixer.sys
0xF7B1C000 \SystemRoot\System32\Drivers\ASCTRM.SYS
0xECFB4000 \SystemRoot\system32\DRIVERS\srv.sys
0xEB50D000 \??\C:\DOCUME~1\Ed\LOCALS~1\Temp\fwedrkog.sys
0x7C900000 \WINDOWS\System32\ntdll.dll

Processes (total 41):
0 System Idle Process
4 System
584 C:\WINDOWS\system32\SMSS.EXE
656 csrss.exe
680 C:\WINDOWS\system32\winlogon.exe
724 C:\WINDOWS\system32\services.exe
744 C:\WINDOWS\system32\lsass.exe
888 C:\WINDOWS\system32\SVCHOST.EXE
984 SVCHOST.EXE
1024 C:\WINDOWS\system32\SVCHOST.EXE
1116 SVCHOST.EXE
1164 SVCHOST.EXE
1340 C:\WINDOWS\EXPLORER.EXE
1404 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1556 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
1564 C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
1572 C:\Program Files\Real\RealPlayer\REALPLAY.EXE
1596 C:\Program Files\QuickTime\QTTASK.EXE
1604 C:\Program Files\HP\hpcoretech\HPCMPMGR.EXE
1624 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
1632 C:\Program Files\AVAST Software\Avast\AvastUI.exe
1656 C:\Program Files\Walgreens\Walgreens PhotoShow\DATA\Xtras\MSSYSMGR.EXE
1664 C:\WINDOWS\system32\CTFMON.EXE
1680 C:\Program Files\Messenger\MSMSGS.EXE
1788 C:\Program Files\HP\Digital Imaging\BIN\hpqtra08.exe
2036 C:\Program Files\HP\Digital Imaging\BIN\hpqgalry.exe
488 C:\WINDOWS\system32\spoolsv.exe
632 C:\Program Files\Common Files\AOL\ACS\acsd.exe
1224 C:\WINDOWS\system32\SVCHOST.EXE
1252 C:\WINDOWS\system32\SVCHOST.EXE
1272 C:\WINDOWS\system32\SVCHOST.EXE
1220 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
1072 C:\WINDOWS\system32\SVCHOST.EXE
1524 C:\WINDOWS\wanmpsvc.exe
2476 alg.exe
2832 C:\Program Files\HP\Digital Imaging\BIN\hpqSTE08.exe
3364 C:\Program Files\AOL Companion\companion.exe
2884 C:\WINDOWS\system32\wuauclt.exe
660 C:\WINDOWS\system32\wuauclt.exe
812 C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\update\update.exe
1520 C:\Documents and Settings\Ed\Desktop\Computer stuff\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32)

PhysicalDrive0 Model Number: Maxtor2B020H1, Rev: WAH21PB0

Size Device Name MBR Status
——————————————–
19 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!
============================================================

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000001d

Kernel Drivers (total 124):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806CE000 \WINDOWS\system32\hal.dll
0x86783000 \WINDOWS\system32\KDCOM.DLL
0xF79F0000 \WINDOWS\system32\BOOTVID.dll
0xF74AD000 ACPI.sys
0xF7ADC000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF749C000 pci.sys
0xF75DC000 isapnp.sys
0xF7ADE000 viaide.sys
0xF785C000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7AE0000 aliide.sys
0xF75EC000 MountMgr.sys
0xF747D000 ftdisk.sys
0xF7AE2000 dmload.sys
0xF7457000 dmio.sys
0xF7864000 PartMgr.sys
0xF75FC000 VolSnap.sys
0xF743F000 atapi.sys
0xF760C000 disk.sys
0xF761C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7420000 fltMgr.sys
0xF740E000 sr.sys
0xF73EB000 Fastfat.sys
0xF73D4000 KSecDD.sys
0xF73A7000 NDIS.sys
0xF738C000 Mup.sys
0xF762C000 alim1541.sys
0xF763C000 gagp30kx.sys
0xF2F70000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xF2F5C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF48CB000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF48BB000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF48AB000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF2F39000 \SystemRoot\system32\DRIVERS\ks.sys
0xF4AE1000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF2F16000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF4AD9000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF3B7D000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF3CB0000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF3CA8000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF7B48000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0xF3B6D000 \SystemRoot\system32\DRIVERS\serial.sys
0xF54B9000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF2E12000 \SystemRoot\system32\DRIVERS\parport.sys
0xF2DD0000 \SystemRoot\system32\drivers\smwdm.sys
0xF2DAC000 \SystemRoot\system32\drivers\portcls.sys
0xF3B5D000 \SystemRoot\system32\drivers\drmk.sys
0xF2D90000 \SystemRoot\system32\drivers\aeaudio.sys
0xF2D32000 \SystemRoot\system32\drivers\senfilt.sys
0xF3B4D000 \SystemRoot\system32\DRIVERS\fetnd5b.sys
0xF3B3D000 \SystemRoot\system32\DRIVERS\AmdK8.sys
0xF34F9000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF3B2D000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF54B5000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF2D1B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF3B1D000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF3B0D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF3CA0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF2D0A000 \SystemRoot\system32\DRIVERS\psched.sys
0xF3AFD000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF3C98000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF3C90000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF3C88000 \SystemRoot\system32\DRIVERS\wanatw4.sys
0xF2CD9000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF3AED000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF3C80000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7B4A000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF2CA5000 \SystemRoot\system32\DRIVERS\update.sys
0xF4EC9000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF77EC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF77FC000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7AF8000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF78DC000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xF7AFA000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xEF7A4000 \SystemRoot\System32\Drivers\Null.SYS
0xF7B2C000 \SystemRoot\System32\Drivers\Beep.SYS
0xF78FC000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF7904000 \SystemRoot\System32\drivers\vga.sys
0xF7B26000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7AFC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF790C000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7914000 \SystemRoot\System32\Drivers\Npfs.SYS
0xEFD51000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xEF5F4000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xEF59C000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF781C000 \SystemRoot\System32\Drivers\aswTdi.SYS
0xEF574000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF791C000 \SystemRoot\System32\Drivers\aswRdr.SYS
0xEF552000 \SystemRoot\System32\drivers\afd.sys
0xF782C000 \SystemRoot\system32\DRIVERS\netbios.sys
0xEF526000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xEF4B7000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF784C000 \SystemRoot\System32\Drivers\Fips.SYS
0xEF496000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF766C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xEF44E000 \SystemRoot\System32\Drivers\aswSP.SYS
0xEF3F0000 \SystemRoot\System32\Drivers\aswSnx.SYS
0xF7AFE000 \SystemRoot\system32\drivers\AsIO.sys
0xF794C000 \SystemRoot\System32\Drivers\Aavmker4.SYS
0xF7974000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xEF63F000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF768C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xEF637000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xF48EB000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEF3D8000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7B28000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xEFE59000 \SystemRoot\System32\drivers\Dxapi.sys
0xF79BC000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7C99000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xF7A80000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0xEDD14000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xEDC79000 \SystemRoot\System32\Drivers\aswMon2.SYS
0xED4AE000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xED471000 \SystemRoot\system32\drivers\wdmaud.sys
0xED573000 \SystemRoot\system32\drivers\sysaudio.sys
0xF7B18000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xED3F5000 \SystemRoot\system32\drivers\kmixer.sys
0xF7B1C000 \SystemRoot\System32\Drivers\ASCTRM.SYS
0xECFB4000 \SystemRoot\system32\DRIVERS\srv.sys
0xEB50D000 \??\C:\DOCUME~1\Ed\LOCALS~1\Temp\fwedrkog.sys
0x7C900000 \WINDOWS\System32\ntdll.dll

Processes (total 41):
0 System Idle Process
4 System
584 C:\WINDOWS\system32\SMSS.EXE
656 csrss.exe
680 C:\WINDOWS\system32\winlogon.exe
724 C:\WINDOWS\system32\services.exe
744 C:\WINDOWS\system32\lsass.exe
888 C:\WINDOWS\system32\SVCHOST.EXE
984 SVCHOST.EXE
1024 C:\WINDOWS\system32\SVCHOST.EXE
1116 SVCHOST.EXE
1164 SVCHOST.EXE
1340 C:\WINDOWS\EXPLORER.EXE
1404 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1556 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
1564 C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
1572 C:\Program Files\Real\RealPlayer\REALPLAY.EXE
1596 C:\Program Files\QuickTime\QTTASK.EXE
1604 C:\Program Files\HP\hpcoretech\HPCMPMGR.EXE
1624 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
1632 C:\Program Files\AVAST Software\Avast\AvastUI.exe
1656 C:\Program Files\Walgreens\Walgreens PhotoShow\DATA\Xtras\MSSYSMGR.EXE
1664 C:\WINDOWS\system32\CTFMON.EXE
1680 C:\Program Files\Messenger\MSMSGS.EXE
1788 C:\Program Files\HP\Digital Imaging\BIN\hpqtra08.exe
2036 C:\Program Files\HP\Digital Imaging\BIN\hpqgalry.exe
488 C:\WINDOWS\system32\spoolsv.exe
632 C:\Program Files\Common Files\AOL\ACS\acsd.exe
1224 C:\WINDOWS\system32\SVCHOST.EXE
1252 C:\WINDOWS\system32\SVCHOST.EXE
1272 C:\WINDOWS\system32\SVCHOST.EXE
1220 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
1072 C:\WINDOWS\system32\SVCHOST.EXE
1524 C:\WINDOWS\wanmpsvc.exe
2476 alg.exe
2832 C:\Program Files\HP\Digital Imaging\BIN\hpqSTE08.exe
3364 C:\Program Files\AOL Companion\companion.exe
2884 C:\WINDOWS\system32\wuauclt.exe
660 C:\WINDOWS\system32\wuauclt.exe
812 C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\update\update.exe
1520 C:\Documents and Settings\Ed\Desktop\Computer stuff\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32)

PhysicalDrive0 Model Number: Maxtor2B020H1, Rev: WAH21PB0

Size Device Name MBR Status
——————————————–
19 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!
aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-03-27 13:42:38
—————————–
13:42:38.984 OS Version: Windows 5.1.2600 Service Pack 2
13:42:38.984 Number of processors: 1 586 0x1C00
13:42:38.984AC ComputerName: ED-7480603707F7 UserName: Ed
13:42:49.765 Initialize success
13:43:55.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
13:43:55.000 Disk 0 Vendor: Maxtor_2B020H1 WAH21PB0 Size: 19541MB BusType: 3
13:43:55.000 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskMaxtor_2B020H1__________________________WAH21PB0#31425637484e455220
2020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
13:43:55.000 Device \Driver\atapi -> DriverStartIo 8671c27f
13:43:57.062 Disk 0 MBR read successfully
13:43:57.062 Disk 0 MBR scan
13:43:57.062 Disk 0 TDL4@MBR code has been found
13:43:57.062 Disk 0 MBR hidden
13:43:57.062 Disk 0 MBR [TDL4] **ROOTKIT**
13:43:57.062 Disk 0 trace - called modules:
13:43:57.062 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8671c439]<<
13:43:57.062 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x867c8ab8]
13:43:57.062 3 CLASSPNP.SYS[f761d05b] -> nt!IofCallDriver -> \Device\00000067[0x8677af18]
13:43:57.062 5 ACPI.sys[f74b3620] -> nt!IofCallDriver -> [0x8678e940]
13:43:57.562 \Driver\atapi[0x867737d0] -> IRP_MJ_CREATE -> 0x8671c439
13:43:57.562 Scan finished successfully
Hi Jcatsmom,


Thanks for the logs. Unfortunately your machine appears to have been infected by the TDSS rootkit/backdoor infection. This kind of malware is very dangerous. Backdoor Trojans provide a means of accessing a computer system that bypasses security mechanisms and steal sensitive information like passwords, personal and financial data which they send back to the hacker. Rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge.


If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:

  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks,
    paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or
    credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps

Please read the following for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
What Should I Do If I've Become A Victim Of Identity Theft?
Identity Theft Victims Guide - What to do



Although the TDSS infection can be identified and removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that if this type of malware has been removed the computer is now secure. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:

When should I re-format? How should I reinstall?
Where to draw the line? When to recommend a format and reinstall?

Note: Attempting to reinstall Windows (repair install) without first wiping the entire hard drive with a repartition/reformat will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system causing problems will still be there afterwards and a Repair will NOT help.


Should you have any questions, please feel free to ask. Please let me know what you have decided to do in your next post. If you decide you want to try and clean your PC then please continue with the following instructions:


  • Please double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When scan finishes, press the Fix Button. Once the Fix is done, press the Save Log button and save the log to your desktop. You need to reboot your computer when its done before you do anything else, then post the log that will be on your desktop.

[external image: Posted Image]
Click the image to enlarge it
Blottedisk, my friend was all in favor of wiping her hard drive and reinstalling the op system. Unfortunately, she has Win XP Professional and I only have the disk for Home Edition. This was a put together computer by someone where she used to live and there's no Microsoft license label on it. Seems like we're kind of stuck on not reinstalling. I successfully cleaned the MBR with aswMBR. Is there anything quick we could do that would give us an idea of the remaining infection level? Thanks! By the way, I'm turning off System Restore to make sure to get rid of any remnants there. -Jcatsmom aswMBR version 0.9.4 Copyright© 2011 AVAST Software Run date: 2011-03-27 18:28:58 —————————– 18:28:58.781 OS Version: Windows 5.1.2600 Service Pack 2 18:28:58.781 Number of processors: 1 586 0x1C00 18:28:58.781 ComputerName: ED-7480603707F7 UserName: Ed 18:28:59.609 Initialize success 18:29:01.937 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 18:29:01.937 Disk 0 Vendor: Maxtor_2B020H1 WAH21PB0 Size: 19541MB BusType: 3 18:29:03.953 Disk 0 MBR read successfully 18:29:03.953 Disk 0 MBR scan 18:29:05.968 Disk 0 scanning sectors +40017915 18:29:05.984 Disk 0 scanning C:\WINDOWS\system32\drivers 18:29:08.687 Service scanning 18:29:10.203 Disk 0 trace - called modules: 18:29:10.218 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys PCIIDEX.SYS 18:29:10.218 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86779ab8] 18:29:10.218 3 CLASSPNP.SYS[f761d05b] -> nt!IofCallDriver -> \Device\00000067[0x8677b0d8] 18:29:10.218 5 ACPI.sys[f74b3620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86719940] 18:29:10.218 Scan finished successfully
Hi Jcatsmom,


Cleaning restore points is always my last step during malware removal process. Shall something go wrong and render your machine unbootable while cleaning it, a system restore point could be of use, even if it's infected.


But it's ok, let's go on. We Need to Diagnose a Possible Problem with WGA.

  • Please download MGADiag.exe and save it to your desktop.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.
Hi Blottedisk, We're stuck between a rock and a hard place. WGA reports that the computer does not have a valid license. Is it possible that repairing the mbr caused it, or is it more likely that a pirated copy was installed to start with? I guess we need to contact the guy who built the machine and see if he will make good on it and loan a system disk to reinstall. Do you have any suggestions? Thanks! :pullhair: Jcatsmom
Hi Jcatsmom,

I suggest you contact Microsoft to get a legitimate operating system. Due to the issues your machine seems to be having, a format and reinstall with a legal OS would be in order.

How to Tell

Unless your operating system and software have been fully validated I am unable to continue helping you.
Blottedisk, Thank you for helping me as much as you could. I was able to recover the license using "third party" software and Microsoft tells me it is not a valid license. :angry: -Jcatsmom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI