This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

infected with "xp security" please help

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i have an old pc and it normally works ok but my girl was messing around on here and now its popping up an fake anti virus telling me its a trial version listing all kinds of "viruses and malware " it has detected and wanting me to remove them by clicking here obviously i havent but i used they OTL as in the guide i will post the two files when prompted . thank you in advance.
Hi hotzie, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Post the logs.

Thanks
OTL logfile created on: 3/27/2011 4:00:39 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

223.00 Mb Total Physical Memory | 40.00 Mb Available Physical Memory | 18.00% Memory free
547.00 Mb Paging File | 333.00 Mb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.40 Gb Total Space | 22.71 Gb Free Space | 68.00% Space Free | Partition Type: NTFS
Drive D: | 3.89 Gb Total Space | 0.74 Gb Free Space | 18.99% Space Free | Partition Type: FAT32

Computer Name: MARKS | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe (Valve Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (WSWNA1100) – C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe ()
SRV - (jswpsapi) – C:\Program Files\NETGEAR\WNA1100\jswpsapi.exe (Atheros Communications, Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (navapsvc) – c:\Program Files\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
SRV - (ccPwdSvc) – c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (tmrkb) – C:\WINDOWS\system32\drivers\tmrkb.sys (trend_company_name)
DRV - (AR9271) – C:\WINDOWS\system32\drivers\athuw.sys (Atheros Communications, Inc.)
DRV - (WSIMD) – C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (JSWSCIMD) – C:\WINDOWS\system32\drivers\jswscimd.sys (Atheros Communications, Inc.)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (wltwo51b) – C:\WINDOWS\system32\drivers\wltwo51b.sys (2wire)
DRV - (SAVRTPEL) – C:\WINDOWS\system32\drivers\SAVRTPEL.SYS (Symantec Corporation)
DRV - (SAVRT) – C:\WINDOWS\system32\drivers\SAVRT.SYS (Symantec Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20021202.005\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20021202.005\NAVENG.SYS (Symantec Corporation)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (nv_agp) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Search-Results"
FF - prefs.js..browser.search.defaultenginename: "Search-Results"
FF - prefs.js..browser.search.order.1: "Search-Results"
FF - prefs.js..browser.search.selectedEngine: "Search-Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.search-results.com?o=41647951&l=dis"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..keyword.URL: "http://websearch.search-results.com/redirect?client=ff&src=kw&tb=BBY2-SRS&o=41647948&locale=en_US&apn_uid=1576782B-2AE3-4CDB-AB53-2250635C5BD0&apn_ptnrs=7S&apn_sauid=5F1E14BD-165A-4A6E-BA31-74EB4082FCBE&apn_dtid=YYYYYYYYUS&q="

FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 19:30:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/02/23 04:30:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/03/27 15:06:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\y1sv4l9w.default\extensions
[2011/03/26 21:18:59 | 000,003,368 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\y1sv4l9w.default\searchplugins\search-results.xml
[2011/03/27 15:03:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Y1SV4L9W.DEFAULT\EXTENSIONS\[removed]
[2011/03/18 11:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 02:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2002/08/29 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.4.0/jinstall-…indows-i586.cab (Java Plug-in 1.4.0_01)
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jinstall-…indows-i586.cab (Java Plug-in 1.4.0_01)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 [removed] [removed]
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/01/24 08:07:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 04:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{e0a3a000-0a1d-11da-9871-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{e0a3a000-0a1d-11da-9871-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e0a3a000-0a1d-11da-9871-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 22:54:58 | 000,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe" -a "%1" %* (Valve Corporation)
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe" -a "%1" %* (Valve Corporation)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/27 15:35:11 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/03/27 15:35:11 | 000,056,400 | —- | C] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/03/27 15:35:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\log
[2011/03/27 15:21:41 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/03/27 15:21:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\HiJackThis
[2011/03/26 21:49:11 | 000,335,872 | -HS- | C] (Valve Corporation) – C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe
[2011/03/26 20:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2011/03/26 20:41:11 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/03/26 12:21:01 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/03/26 12:20:26 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/03/26 11:49:18 | 000,000,000 | —D | C] – C:\Program Files\James River Software
[2011/03/25 19:07:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/03/25 19:06:34 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/25 19:06:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/25 19:06:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/03/25 19:06:29 | 000,019,288 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/25 19:06:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/25 17:41:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2011/03/15 16:51:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Identities
[2011/03/13 00:36:50 | 000,000,000 | –SD | C] – C:\Documents and Settings\Owner\UserData
[2011/03/11 16:32:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/03/10 20:02:26 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data\Atheros
[2011/03/10 20:01:02 | 000,058,208 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\drivers\wsimd.sys
[2011/03/10 20:00:53 | 001,269,854 | —- | C] (Devicescape) – C:\WINDOWS\System32\dsa.dll
[2011/03/10 20:00:53 | 000,426,074 | —- | C] (Atheros) – C:\WINDOWS\System32\wgapi.dll
[2011/03/10 20:00:53 | 000,405,504 | —- | C] (Atheros) – C:\WINDOWS\System32\wcapi.dll
[2011/03/10 20:00:53 | 000,356,443 | —- | C] (Atheros) – C:\WINDOWS\System32\wcapiU.dll
[2011/03/10 20:00:53 | 000,311,390 | —- | C] (Atheros) – C:\WINDOWS\System32\athcfg20U.dll
[2011/03/10 20:00:53 | 000,254,022 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\wsfwDS.dll
[2011/03/10 20:00:53 | 000,249,924 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\wsimd.dll
[2011/03/10 20:00:53 | 000,237,568 | —- | C] (Atheros) – C:\WINDOWS\System32\athcfg20.dll
[2011/03/10 20:00:53 | 000,127,079 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\athcfg20resU.dll
[2011/03/10 20:00:53 | 000,127,053 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\athcfg20res.dll
[2011/03/10 20:00:53 | 000,082,017 | —- | C] (Devicescape, Inc.) – C:\WINDOWS\System32\dsaNac.dll
[2011/03/10 20:00:52 | 001,723,840 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\drivers\athuw.sys
[2011/03/10 20:00:52 | 000,495,700 | —- | C] (Atheros) – C:\WINDOWS\System32\acs.exe
[2011/03/10 20:00:52 | 000,058,208 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\wsimd.sys
[2011/03/10 20:00:52 | 000,057,440 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\jswscimd.sys
[2011/03/10 20:00:52 | 000,057,440 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\drivers\jswscimd.sys
[2011/03/10 20:00:48 | 000,405,582 | —- | C] (Atheros Communications, Inc.) – C:\WINDOWS\System32\jswscsup.dll
[2011/03/10 20:00:48 | 000,073,800 | —- | C] (Atheros) – C:\WINDOWS\System32\athgina.dll
[2011/03/10 20:00:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NETGEAR WNA1100 Smart Wizard
[2011/03/10 20:00:44 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2011/03/10 19:45:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\InstallShield
[2011/02/28 13:46:05 | 000,000,000 | —D | C] – C:\$WIN_NT$.~BT
[2011/02/28 13:45:53 | 000,000,000 | —D | C] – C:\WINDOWS\setupupd
[2011/02/28 04:48:33 | 000,000,000 | —D | C] – C:\WINDOWS\setup.pss
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/27 15:47:46 | 000,013,950 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uu7a0286ok431ntm7blec27
[2011/03/27 15:47:46 | 000,013,950 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\uu7a0286ok431ntm7blec27
[2011/03/27 15:37:28 | 000,002,447 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2011/03/27 15:37:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/27 15:37:00 | 234,409,984 | -HS- | M] () – C:\hiberfil.sys
[2011/03/27 15:35:11 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/03/27 15:35:11 | 000,056,400 | —- | M] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/03/27 15:14:05 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/03/27 14:39:54 | 000,000,246 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/03/26 21:49:11 | 000,335,872 | -HS- | M] (Valve Corporation) – C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe
[2011/03/26 11:52:30 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/25 20:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
[2011/03/25 19:30:59 | 000,000,750 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/25 19:30:59 | 000,000,732 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/25 19:06:34 | 000,000,792 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/25 15:35:09 | 000,005,120 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/12 23:20:55 | 000,000,252 | RHS- | M] () – C:\boot.ini
[2011/03/11 18:48:04 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/03/10 20:03:24 | 000,394,078 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/10 20:03:24 | 000,059,326 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/10 20:00:47 | 000,000,583 | —- | M] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WNA1100 Smart Wizard.lnk
[2011/03/10 19:54:58 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/08 18:16:59 | 000,018,541 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Y1EMgpFs.htm.part
[2011/03/08 14:04:40 | 000,003,344 | —- | M] () – C:\Documents and Settings\Owner\Desktop\General Experience and Reputation.html
[2011/03/07 03:11:58 | 000,117,661 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Rugger10-22TigerMaple.jpg
[2011/03/06 17:14:54 | 000,000,152 | —- | M] () – C:\logfile
[2011/03/06 17:12:19 | 000,140,440 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/06 00:59:42 | 000,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2011/03/06 00:54:35 | 000,000,608 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/03/05 23:58:54 | 000,000,907 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Kodak Pictures.lnk
[2011/02/28 04:48:48 | 000,000,237 | RHS- | M] () – C:\BOOT.BAK
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/27 15:21:41 | 000,002,447 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2011/03/26 21:49:18 | 000,013,950 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uu7a0286ok431ntm7blec27
[2011/03/26 21:49:18 | 000,013,950 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\uu7a0286ok431ntm7blec27
[2011/03/25 19:30:59 | 000,000,732 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/25 19:30:58 | 000,000,738 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/03/25 19:06:34 | 000,000,792 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/11 18:48:04 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/03/11 18:48:04 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/03/11 16:22:55 | 000,024,672 | —- | C] () – C:\WINDOWS\System32\javaw.exe
[2011/03/11 16:22:54 | 000,024,670 | —- | C] () – C:\WINDOWS\System32\java.exe
[2011/03/10 20:00:52 | 000,039,471 | —- | C] () – C:\WINDOWS\System32\wsimdp.cat
[2011/03/10 20:00:52 | 000,039,469 | —- | C] () – C:\WINDOWS\System32\wsimd.cat
[2011/03/10 20:00:52 | 000,035,967 | —- | C] () – C:\WINDOWS\System32\jswscimdp.cat
[2011/03/10 20:00:52 | 000,035,538 | —- | C] () – C:\WINDOWS\System32\jswscimd.cat
[2011/03/10 20:00:52 | 000,005,529 | —- | C] () – C:\WINDOWS\System32\jswscimdp.inf
[2011/03/10 20:00:52 | 000,005,363 | —- | C] () – C:\WINDOWS\System32\wsimdp.inf
[2011/03/10 20:00:52 | 000,002,231 | —- | C] () – C:\WINDOWS\System32\jswscimd.inf
[2011/03/10 20:00:52 | 000,002,179 | —- | C] () – C:\WINDOWS\System32\wsimd.inf
[2011/03/10 20:00:48 | 000,262,216 | —- | C] () – C:\WINDOWS\System32\IPTests.dll
[2011/03/10 20:00:47 | 000,000,583 | —- | C] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WNA1100 Smart Wizard.lnk
[2011/03/08 18:16:56 | 000,018,541 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Y1EMgpFs.htm.part
[2011/03/08 14:04:37 | 000,003,344 | —- | C] () – C:\Documents and Settings\Owner\Desktop\General Experience and Reputation.html
[2011/03/07 03:11:49 | 000,117,661 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Rugger10-22TigerMaple.jpg
[2011/03/06 17:14:43 | 000,000,152 | —- | C] () – C:\logfile
[2011/03/06 00:59:42 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/03/05 23:58:54 | 000,000,907 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Kodak Pictures.lnk
[2011/02/28 04:48:48 | 000,000,237 | RHS- | C] () – C:\BOOT.BAK
[2009/10/04 11:35:14 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2007/11/01 16:03:04 | 000,000,049 | —- | C] () – C:\WINDOWS\VistaEmail.ini
[2007/09/25 17:10:53 | 000,086,082 | —- | C] () – C:\WINDOWS\System32\ftdiunin.exe
[2007/09/25 17:10:53 | 000,000,110 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2007/03/08 15:10:39 | 000,000,312 | —- | C] () – C:\WINDOWS\EReg515.dat
[2005/08/24 13:11:59 | 000,561,152 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2005/07/25 17:03:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\eraseme_32050.exe
[2005/07/01 15:54:02 | 000,005,120 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/06/26 12:19:54 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\winsusrm.dll
[2005/05/14 15:43:49 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/05/05 20:58:12 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\shawn_1.dll
[2005/05/05 20:58:10 | 000,067,511 | —- | C] () – C:\WINDOWS\System32\a_i_037.exe
[2005/05/05 20:57:37 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\a_i_037.dll
[2005/04/30 18:33:33 | 000,000,400 | —- | C] () – C:\WINDOWS\System32\im64.dll
[2005/03/02 21:55:08 | 000,000,625 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/11/06 16:35:50 | 000,000,182 | —- | C] () – C:\WINDOWS\eomaha.ini
[2004/11/06 16:27:17 | 000,000,062 | —- | C] () – C:\WINDOWS\draw.ini
[2004/11/06 16:09:13 | 000,000,181 | —- | C] () – C:\WINDOWS\eholdem.ini
[2004/08/08 16:56:01 | 001,404,204 | —- | C] () – C:\WINDOWS\jawa32v.bin
[2004/08/08 16:56:01 | 000,188,416 | —- | C] () – C:\WINDOWS\jawa32.exe
[2004/08/08 16:56:01 | 000,106,324 | —- | C] () – C:\WINDOWS\jawa32u.bin
[2004/08/08 16:56:01 | 000,002,668 | —- | C] () – C:\WINDOWS\jawa32.dat
[2004/08/08 16:56:01 | 000,000,032 | —- | C] () – C:\WINDOWS\jawa32e.bin
[2004/08/08 16:56:00 | 000,034,068 | —- | C] () – C:\WINDOWS\jawa32.bin
[2004/07/14 14:40:34 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\msmc.exe
[2004/07/13 20:41:38 | 000,249,856 | —- | C] () – C:\WINDOWS\aqadcup.exe
[2004/07/13 20:41:17 | 000,024,576 | —- | C] () – C:\WINDOWS\wsem300.dll
[2004/06/25 10:20:43 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\istinstall_adlogix.exe
[2004/06/15 21:10:13 | 000,054,528 | —- | C] () – C:\WINDOWS\wsem218.dll
[2004/06/15 21:10:05 | 000,034,560 | —- | C] () – C:\WINDOWS\nem219.dll_
[2004/06/15 20:13:03 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\cdsm32.dll
[2004/06/11 17:10:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\automove.exe_
[2004/05/20 00:52:49 | 000,155,648 | —- | C] () – C:\WINDOWS\fash.exe
[2004/05/20 00:51:19 | 000,042,328 | —- | C] () – C:\WINDOWS\PreProcess.data
[2004/05/18 19:31:59 | 000,187,314 | —- | C] () – C:\WINDOWS\System32\silent.exe
[2004/05/15 18:44:14 | 000,167,936 | —- | C] () – C:\WINDOWS\mwsvm.exe
[2004/05/15 18:42:26 | 001,404,204 | —- | C] () – C:\WINDOWS\vurls.bin
[2004/05/15 18:42:26 | 000,160,400 | —- | C] () – C:\WINDOWS\mwsvm.bin
[2004/05/15 18:42:26 | 000,106,324 | —- | C] () – C:\WINDOWS\urls.bin
[2004/05/15 18:42:26 | 000,002,623 | —- | C] () – C:\WINDOWS\mwsvm.dat
[2004/05/12 18:09:04 | 000,073,728 | —- | C] () – C:\WINDOWS\ieasst.dll
[2004/05/12 18:07:53 | 000,202,527 | —- | C] () – C:\Documents and Settings\Owner\Application Data\tvmknwrd.dll
[2004/05/12 18:07:13 | 000,000,357 | —- | C] () – C:\WINDOWS\whInstaller.ini
[2004/05/12 18:00:04 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\IdleUI.dll
[2004/05/12 17:59:40 | 000,067,584 | —- | C] () – C:\WINDOWS\System32\2ndsrch.dll
[2004/05/12 17:59:27 | 000,229,793 | —- | C] () – C:\WINDOWS\twaintec.ini
[2004/05/12 17:58:26 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\stcloader.exe
[2004/05/12 17:57:18 | 000,000,060 | —- | C] () – C:\WINDOWS\wininit.ini_
[2004/05/12 17:57:03 | 000,032,768 | —- | C] () – C:\WINDOWS\preInsTT.exe_
[2004/05/12 17:54:48 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\bridge.dll_
[2004/05/12 17:54:48 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\jao.dll
[2004/05/12 17:54:20 | 000,251,829 | —- | C] () – C:\WINDOWS\System32\0021-bdl94126.EXE
[2004/05/12 17:54:05 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\infamous_downloader.exe
[2004/05/12 17:53:02 | 000,213,012 | —- | C] () – C:\WINDOWS\infamous.exe
[2003/08/23 15:16:24 | 000,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2003/08/23 15:16:24 | 000,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2003/07/30 22:42:07 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlsz.INI
[2003/07/28 21:09:34 | 000,000,037 | —- | C] () – C:\WINDOWS\Acroread.ini
[2003/06/07 18:50:19 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2003/02/07 06:49:22 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2003/02/07 06:49:22 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2003/02/07 06:47:42 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2003/02/07 06:47:38 | 000,001,740 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2003/02/07 06:24:42 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/02/07 06:24:31 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/02/07 06:24:31 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/02/07 06:24:29 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2003/02/07 06:24:25 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2003/02/07 06:24:20 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/01/25 04:43:47 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/01/25 04:43:16 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\iAlmcoin.dll
[2003/01/25 04:30:01 | 000,000,032 | -HS- | C] () – C:\WINDOWS\System32\{7A423CBA-2B8A-4A0B-AE91-B7E63A03AA63}.dat
[2003/01/25 04:30:01 | 000,000,032 | -HS- | C] () – C:\WINDOWS\{432DC6F6-968D-4F5B-A15F-5FECE3F263AD}.dat
[2003/01/25 04:29:51 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\SR2.dat
[2003/01/24 09:36:27 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\IntroReg.dll
[2003/01/24 09:36:25 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/01/24 09:36:24 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/01/24 09:27:03 | 000,008,822 | —- | C] () – C:\WINDOWS\mozver.dat
[2003/01/24 09:18:55 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/01/24 09:18:40 | 000,000,608 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/01/24 08:52:52 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/01/24 08:41:30 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\shpshftr.dll
[2003/01/24 08:30:21 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/01/24 08:30:21 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/01/24 08:29:52 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/01/24 08:11:36 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/01/24 08:09:48 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2003/01/24 08:04:56 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2003/01/24 06:55:28 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/24 06:54:59 | 000,004,573 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/24 06:54:56 | 000,394,078 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/01/24 06:54:56 | 000,059,326 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/01/24 00:00:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/01/23 23:59:01 | 000,140,440 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2001/08/22 18:00:00 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\cfg.dat
[2001/08/19 05:30:44 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\elitesiy32.exe
[1999/01/22 12:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2005/06/30 12:35:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/08/23 18:53:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2003/01/24 09:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterTrust
[2004/05/20 01:09:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2003/01/24 09:24:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2009/01/24 16:37:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/14 15:03:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2003/01/24 09:09:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/17 15:00:49 | 000,000,450 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration RunOnce Task.job
[2003/09/10 20:17:22 | 000,000,342 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1055195529.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2003/01/24 08:07:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/28 04:48:48 | 000,000,237 | RHS- | M] () – C:\BOOT.BAK
[2011/03/12 23:20:55 | 000,000,252 | RHS- | M] () – C:\boot.ini
[2003/01/24 08:07:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/27 15:37:00 | 234,409,984 | -HS- | M] () – C:\hiberfil.sys
[2003/01/24 08:07:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/08/10 22:28:54 | 000,000,586 | -H– | M] () – C:\IPH.PH
[2011/03/06 17:14:54 | 000,000,152 | —- | M] () – C:\logfile
[2003/01/24 08:07:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 06:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/03/06 17:12:37 | 000,000,000 | —- | M] () – C:\nvlog.txt
[2011/03/27 15:36:59 | 352,321,536 | -HS- | M] () – C:\pagefile.sys
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/01/24 08:07:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2007/06/07 12:53:02 | 000,031,744 | —- | M] () – C:\Program Files\Megan's Resume.doc

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/01/23 23:58:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2003/01/23 23:58:14 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2003/01/23 23:58:14 | 000,385,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2003/01/24 08:07:39 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2003/12/09 23:44:20 | 000,063,074 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\.plugin140_01.trace
[2002/02/21 04:05:54 | 000,000,173 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\oobecmt.ini

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2003/01/24 08:11:24 | 000,000,139 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2003/01/24 08:11:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/02/23 04:29:01 | 008,582,536 | —- | M] (Mozilla) – C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.6.13.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
OTL Extras logfile created on: 3/27/2011 4:00:39 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

223.00 Mb Total Physical Memory | 40.00 Mb Available Physical Memory | 18.00% Memory free
547.00 Mb Paging File | 333.00 Mb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.40 Gb Total Space | 22.71 Gb Free Space | 68.00% Space Free | Partition Type: NTFS
Drive D: | 3.89 Gb Total Space | 0.74 Gb Free Space | 18.99% Space Free | Partition Type: FAT32

Computer Name: MARKS | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL %1,%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe (Valve Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL %1,%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{01F9D88C-3C86-4E82-840A-101A3221F67A}" = Microsoft Money 2003
"{02B42D23-10F2-4862-ADA4-3DF1EA0021B2}" = Microsoft Money 2003 System Pack
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{7CF31609-270B-11D6-9445-000102308676}" = Java 2 Runtime Environment, SE v1.4.0_01
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver Software
"{8D5D99B8-DFA2-4018-ADE9-A6B83E655C65}" =
"{A2AE9709-283B-4B48-AA34-729C070A62FB}" = NETGEAR WNA1100 wireless USB 2.0 adapter
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English) v1.0.3705
"{EDCD4CE3-DE92-49A9-87F9-FE09B2FBA16C}" = Norton AntiVirus 2003
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"America Online us" = America Online
"AolCoach" = AOL Coach Version 1.0(Build:20011028.1)
"FTDICOMM" = FTDI USB Serial Converter Drivers
"Inactive HP Printer Drivers (Remove only)" = Inactive HP Printer Drivers (Remove only)
"Java Web Start" = Java Web Start
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PS2" = PS2
"Q327979" = Windows XP Hotfix (SP2) Q327979
"q330638" = Windows XP Hotfix (SP2) [See q330638 for more information]
"Q331958" = Windows XP Hotfix (SP2) Q331958
"QuickTime" = QuickTime
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/27/2011 4:42:32 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca

Error - 3/27/2011 4:52:23 PM | Computer Name = MARKS | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 3/27/2011 4:52:39 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff

Error - 3/27/2011 4:52:39 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca

Error - 3/27/2011 5:02:47 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff

Error - 3/27/2011 5:02:47 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca

Error - 3/27/2011 5:30:45 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff

Error - 3/27/2011 5:30:46 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca

Error - 3/27/2011 5:30:55 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x2eff

Error - 3/27/2011 5:30:55 PM | Computer Name = MARKS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 0x8ca

[ System Events ]
Error - 3/27/2011 5:08:51 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:08:51 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:08:52 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:08:53 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/27/2011 5:37:17 PM | Computer Name = MARKS | Source = System Error | ID = 1003
Description = Error code 10000050, parameter1 80636000, parameter2 00000000, parameter3
ec73bf97, parameter4 00000000.

Error - 3/27/2011 5:38:40 PM | Computer Name = MARKS | Source = Service Control Manager | ID = 7003
Description = The tmrkb service depends on the following nonexistent service: tmcomm


< End of report >
Hi hotzie,


I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

copy and paste the following into the upload a file box (one at a time if more than one file is listed)

D:\Info.exe


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O37 - HKCU\…exe [@ = exefile] – "C:\Documents and Settings\Owner\Local Settings\Application Data\hsn.exe" -a "%1" %* (Valve Corporation)
2011/03/27 15:47:46 | 000,013,950 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uu7a0286ok431ntm7blec27
[2011/03/27 15:47:46 | 000,013,950 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\uu7a0286ok431ntm7blec27


:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan

[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply

Please post back with
  • OTL fix log
  • aswmbr log
How is the computer?

Thanks
it totally screwed up while i was tryin to do what u asked in the last post. i did the first step of it(virustotals) and it said it had seen it before in 2009. then it wouldnt let me on any site kept saying firefox had blocked it and gave me three choices none worked except to use the xp security and i couldnt get anything to work so i had to do a system restore. it hasnt popped up yet but i dont know what to do know though?? i really appreciate your help because im so p!ssed off i want to smash this tower.
Hi hotzie, That's probably a combination of the infection and using system restore. Use IE to finish the instructions. You should also rerun the OTL fix. If VirusTotal says the file has been scanned before click rescan. Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI