This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Turned on my computer one day, loaded with viruses

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I've been a long time member of what the tech(tom coyote hehe) and you guys have helped me immensely. Though I have hit something that I just cant shake. I have no idea what gave me this, but I was on my computer one day when I noticed the internet was very VERY slow. Then, when I went to certain websites (such as the hijack this website) it would redirect me to some shady site like word-contribution.com or some other ones. Then, my background turned blue and I completely lost internet. Luckily I had malwarebytes. I used that, restored my desktop (i have windows 7 64 bit btw) and gained access to the internet. It detected several trojans and removed them. Then I downloaded adaware, made a few scans found 45 items and removed them. Yet I still have slow internet and the redirect issue. One more thing, when I had the blue background, I would also get several popups on my screen telling me I had multiple viruses and to have it scan my system(obviously this was part of the virus). I had a friend flash drive me a copy of hijack this, and that is how I'm posting the log right now. and dds told me it doesnt support my operating system.

Thanks!

OTL logfile created on: 3/30/2011 12:29:21 AM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Blake Foster\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.7930.16406)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 39.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.49 Gb Total Space | 58.04 Gb Free Space | 12.91% Space Free | Partition Type: NTFS
Drive D: | 15.98 Gb Total Space | 2.31 Gb Free Space | 14.43% Space Free | Partition Type: NTFS
Drive G: | 199.00 Mb Total Space | 166.84 Mb Free Space | 83.84% Space Free | Partition Type: NTFS

Computer Name: BLAKEFOSTER-PC | User Name: Blake Foster | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Blake Foster\Downloads\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe (Trend Micro Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe (Pharos Systems International)
PRC - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)


========== Modules (SafeList) ==========

MOD - C:\Users\Blake Foster\Downloads\OTL(1).exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\certSTAT.dll ()
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\xolehlp.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\imagehlp.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (dlea_device) – C:\Windows\SysNative\dleacoms.exe ( )
SRV:64bit: - (dleaCATSCustConnectService) – C:\Windows\SysNative\spool\DRIVERS\x64\3\\dleaserv.exe ()
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (dlea_device) – C:\Windows\SysWow64\dleacoms.exe ( )
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Pharos Systems ComTaskMaster) – C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe (Pharos Systems International)
SRV - (pgsql-8.3) – C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (NETw5s64) Intel® – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asearch.babylon.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 48 57 4E A3 BA 60 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {9565115d-c7d6-46d3-bd63-b67b481a4368} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "PageRage Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23


FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/03/23 13:15:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/03/23 13:15:45 | 000,000,000 | —D | M]

[2010/10/15 09:41:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Blake Foster\AppData\Roaming\Mozilla\Extensions
[2011/03/24 12:14:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Blake Foster\AppData\Roaming\Mozilla\Firefox\Profiles\trihwblg.default\extensions
[2010/11/23 13:02:06 | 000,000,919 | —- | M] () – C:\Users\Blake Foster\AppData\Roaming\Mozilla\Firefox\Profiles\trihwblg.default\searchplugins\conduit.xml
[2011/03/23 13:15:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/21 19:13:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\USERS\BLAKE FOSTER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TRIHWBLG.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7b4a5c2a-0eae-11e0-b0b5-70f395608001}\Shell - "" = AutoRun
O33 - MountPoints2\{7b4a5c2a-0eae-11e0-b0b5-70f395608001}\Shell\AutoRun\command - "" = E:\setup\rsrc\Autorun.exe
O33 - MountPoints2\{7b4a5c2a-0eae-11e0-b0b5-70f395608001}\Shell\dinstall\command - "" = E:\Directx\dxsetup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: setuInit - (C:\Windows\system32\certSTAT.dll) - C:\Windows\SysWOW64\certSTAT.dll ()
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/30 00:19:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/03/30 00:19:27 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/03/30 00:05:41 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/03/29 01:00:13 | 000,069,376 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/03/29 01:00:09 | 000,049,752 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/03/29 00:58:31 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\Sunbelt Software
[2011/03/29 00:56:27 | 000,000,000 | -H-D | C] – C:\ProgramData\{8790345A-AF70-4319-B9E7-AAA25C6DCD42}
[2011/03/29 00:56:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/03/29 00:42:50 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2011/03/29 00:42:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2011/03/28 23:51:06 | 000,000,000 | —D | C] – C:\ProgramData\oPoJdOoJpMo05200
[2011/03/24 11:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III
[2011/03/24 11:57:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Warcraft III
[2011/03/24 10:47:07 | 000,000,000 | —D | C] – C:\Users\Blake Foster\Warcraft III 1.21b TFT Installer enUS
[2011/03/24 10:46:37 | 000,000,000 | —D | C] – C:\Users\Blake Foster\Warcraft III 1.21b ROC Installer enUS
[2011/03/23 18:22:20 | 000,000,000 | —D | C] – C:\Users\Blake Foster\Desktop\gameboy emu
[2011/03/17 21:59:02 | 000,000,000 | —D | C] – C:\Users\Blake Foster\Desktop\Pcsx2
[2011/03/14 21:57:48 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\Logitech
[2011/03/14 21:48:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2011/03/14 21:48:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Logitech
[2011/03/14 21:48:01 | 000,000,000 | —D | C] – C:\Program Files\Logitech
[2011/03/11 23:52:29 | 000,000,000 | —D | C] – C:\Users\Blake Foster\Desktop\XBCD
[2011/03/11 17:23:04 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\project64 1.6
[2011/03/11 17:23:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Project64 1.6
[2011/03/08 22:16:52 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/03/08 22:16:51 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/03/08 22:16:51 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/03/08 22:16:51 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/03/08 22:16:51 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/03/08 22:16:51 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/03/08 22:16:51 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/03/08 22:16:51 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/03/08 22:16:50 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/03/08 22:16:50 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/03/08 22:16:49 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/03/08 22:16:49 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/03/04 17:42:32 | 000,000,000 | —D | C] – C:\Users\Blake Foster\Desktop\New World
[2011/03/02 12:46:46 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\{380F0058-05E6-4DCB-A4F4-FD4FCFFF032D}
[2011/03/01 23:13:37 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\{2C5FD68D-DA01-455E-A914-E659936FC665}
[2011/03/01 23:13:37 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\{1D654A13-7219-4F14-B22B-3D2DA6097361}
[2011/03/01 08:32:43 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\{A4D35726-B017-41D0-99CE-64E06B0AB670}
[2011/03/01 02:50:44 | 000,000,000 | —D | C] – C:\Users\Blake Foster\Documents\My Received Files
[2011/03/01 00:52:03 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStove
[2011/03/01 00:52:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerStove
[2011/02/28 17:08:37 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\{CD0811E0-7822-4ABE-AA9F-892C7A7446CB}
[2011/02/28 03:09:42 | 000,000,000 | —D | C] – C:\Users\Blake Foster\AppData\Local\{E93471BA-E70B-496D-BBB5-8799BFE400C2}
[2010/10/22 09:42:49 | 001,048,576 | —- | C] ( ) – C:\Windows\SysWow64\dleaserv.dll
[2010/10/22 09:42:49 | 000,847,872 | —- | C] ( ) – C:\Windows\SysWow64\dleausb1.dll
[2010/10/22 09:42:49 | 000,802,816 | —- | C] ( ) – C:\Windows\SysWow64\dleacomc.dll
[2010/10/22 09:42:49 | 000,688,128 | —- | C] ( ) – C:\Windows\SysWow64\dleahbn3.dll
[2010/10/22 09:42:49 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\dleapmui.dll
[2010/10/22 09:42:49 | 000,598,696 | —- | C] ( ) – C:\Windows\SysWow64\dleacoms.exe
[2010/10/22 09:42:49 | 000,577,536 | —- | C] ( ) – C:\Windows\SysWow64\dlealmpm.dll
[2010/10/22 09:42:49 | 000,373,416 | —- | C] ( ) – C:\Windows\SysWow64\dleacfg.exe
[2010/10/22 09:42:49 | 000,372,736 | —- | C] ( ) – C:\Windows\SysWow64\dleacomm.dll
[2010/10/22 09:42:49 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\dleainpa.dll
[2010/10/22 09:42:49 | 000,344,064 | —- | C] ( ) – C:\Windows\SysWow64\dleaiesc.dll
[2010/10/22 09:42:49 | 000,324,264 | —- | C] ( ) – C:\Windows\SysWow64\dleaih.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/30 00:21:41 | 000,727,362 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/03/30 00:21:41 | 000,624,128 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/03/30 00:21:41 | 000,107,728 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/03/30 00:19:27 | 000,003,007 | —- | M] () – C:\Users\Blake Foster\Desktop\HiJackThis.lnk
[2011/03/30 00:17:20 | 001,402,880 | —- | M] () – C:\Users\Blake Foster\Desktop\HijackThis.msi
[2011/03/30 00:00:00 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2008147149-1644845097-2794928718-1001UA.job
[2011/03/29 23:49:43 | 000,019,520 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/29 23:49:43 | 000,019,520 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/29 23:48:00 | 000,000,924 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2008147149-1644845097-2794928718-1000UA.job
[2011/03/29 23:41:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/03/29 23:41:40 | 3062,059,008 | -HS- | M] () – C:\hiberfil.sys
[2011/03/29 22:42:28 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2008147149-1644845097-2794928718-1001Core.job
[2011/03/29 18:49:38 | 000,018,258 | —- | M] () – C:\Users\Blake Foster\Documents\ra class.odt
[2011/03/29 18:23:55 | 000,000,872 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2008147149-1644845097-2794928718-1000Core.job
[2011/03/29 08:38:58 | 000,017,220 | —- | M] () – C:\Users\Blake Foster\Documents\music notes.odt
[2011/03/29 02:27:11 | 000,008,704 | —- | M] () – C:\Users\Blake Foster\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/29 01:00:09 | 000,049,752 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/03/29 00:56:26 | 000,001,166 | —- | M] () – C:\Users\Blake Foster\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/03/29 00:56:26 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/03/28 23:51:28 | 000,060,416 | -H– | M] () – C:\Windows\SysWow64\certSTAT.dll
[2011/03/28 12:18:45 | 000,014,873 | —- | M] () – C:\Users\Blake Foster\Documents\music take home test.odt
[2011/03/25 04:03:19 | 000,069,376 | —- | M] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/03/25 04:03:18 | 000,016,432 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2011/03/24 11:59:06 | 000,001,098 | —- | M] () – C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk
[2011/03/24 11:58:03 | 000,001,053 | —- | M] () – C:\Users\Public\Desktop\Warcraft III.lnk
[2011/03/23 16:25:40 | 000,018,128 | —- | M] () – C:\Users\Blake Foster\Documents\tab le.ods
[2011/03/23 16:25:40 | 000,000,138 | -H– | M] () – C:\Users\Blake Foster\Documents\.~lock.tab le.ods#
[2011/03/23 13:16:48 | 000,002,052 | —- | M] () – C:\Users\Blake Foster\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/23 13:15:02 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/22 18:00:35 | 000,022,274 | —- | M] () – C:\Users\Blake Foster\Documents\journal entry 5.odt
[2011/03/22 15:18:51 | 000,007,560 | —- | M] () – C:\Users\Blake Foster\Documents\physics las tables.ods
[2011/03/20 23:48:50 | 000,507,273 | —- | M] () – C:\Users\Blake Foster\Desktop\2305857170011.pdf
[2011/03/20 23:48:45 | 000,480,240 | —- | M] () – C:\Users\Blake Foster\Desktop\2305857168011.pdf
[2011/03/20 21:39:22 | 004,454,569 | —- | M] () – C:\Users\Blake Foster\Documents\chem session.wma
[2011/03/20 19:19:06 | 000,009,821 | —- | M] () – C:\Users\Blake Foster\Documents\chemreviewsession2.odt
[2011/03/19 02:32:27 | 000,417,021 | —- | M] () – C:\Users\Blake Foster\Documents\nukefromorbit.png
[2011/03/15 15:19:10 | 000,007,292 | —- | M] () – C:\Users\Blake Foster\Desktop\chess-langley2.jpg
[2011/03/13 22:56:26 | 000,085,932 | —- | M] () – C:\Users\Blake Foster\Documents\ragecomic.png
[2011/03/11 17:23:05 | 000,002,097 | —- | M] () – C:\Users\Blake Foster\Desktop\Project64 1.6.lnk
[2011/03/09 19:04:01 | 000,018,483 | —- | M] () – C:\Users\Blake Foster\Documents\lab3.cmbl
[2011/03/09 17:43:59 | 000,019,355 | —- | M] () – C:\Users\Blake Foster\Documents\physics 151labrep3.odt
[2011/03/08 18:14:58 | 000,337,094 | —- | M] () – C:\Users\Blake Foster\Documents\fitness bb.odp
[2011/03/08 18:00:43 | 000,020,322 | —- | M] () – C:\Users\Blake Foster\Documents\bulletin board reflection.odt
[2011/03/08 17:42:39 | 000,019,177 | —- | M] () – C:\Users\Blake Foster\Documents\report 4.odt
[2011/03/07 18:49:38 | 000,245,054 | —- | M] () – C:\Users\Blake Foster\Documents\clicker.png
[2011/03/01 18:11:05 | 000,341,755 | —- | M] () – C:\Users\Blake Foster\Documents\fitnessbb.odp
[2011/03/01 11:21:20 | 000,018,714 | —- | M] () – C:\Users\Blake Foster\Documents\bulletin board.odt
[2011/03/01 01:51:54 | 000,124,231 | —- | M] () – C:\Users\Blake Foster\Documents\ragecomci.png
[2011/03/01 01:40:23 | 000,264,143 | —- | M] () – C:\Users\Blake Foster\Documents\willprofile.png
[2011/03/01 00:52:03 | 000,000,991 | —- | M] () – C:\Users\Blake Foster\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStove.lnk
[2011/03/01 00:52:03 | 000,000,967 | —- | M] () – C:\Users\Blake Foster\Desktop\PokerStove.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/30 00:19:27 | 000,003,007 | —- | C] () – C:\Users\Blake Foster\Desktop\HiJackThis.lnk
[2011/03/30 00:18:55 | 001,402,880 | —- | C] () – C:\Users\Blake Foster\Desktop\HijackThis.msi
[2011/03/29 22:56:49 | 000,016,432 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2011/03/29 18:49:35 | 000,018,258 | —- | C] () – C:\Users\Blake Foster\Documents\ra class.odt
[2011/03/29 00:56:26 | 000,001,166 | —- | C] () – C:\Users\Blake Foster\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/03/29 00:56:26 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/03/28 23:51:28 | 000,060,416 | -H– | C] () – C:\Windows\SysWow64\certSTAT.dll
[2011/03/28 11:35:04 | 000,014,873 | —- | C] () – C:\Users\Blake Foster\Documents\music take home test.odt
[2011/03/24 11:58:34 | 000,001,098 | —- | C] () – C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk
[2011/03/24 11:57:44 | 000,001,053 | —- | C] () – C:\Users\Public\Desktop\Warcraft III.lnk
[2011/03/23 15:26:41 | 000,000,138 | -H– | C] () – C:\Users\Blake Foster\Documents\.~lock.tab le.ods#
[2011/03/23 15:26:40 | 000,018,128 | —- | C] () – C:\Users\Blake Foster\Documents\tab le.ods
[2011/03/23 13:15:01 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/03/22 17:48:03 | 000,022,274 | —- | C] () – C:\Users\Blake Foster\Documents\journal entry 5.odt
[2011/03/22 15:18:49 | 000,007,560 | —- | C] () – C:\Users\Blake Foster\Documents\physics las tables.ods
[2011/03/20 23:48:50 | 000,507,273 | —- | C] () – C:\Users\Blake Foster\Desktop\2305857170011.pdf
[2011/03/20 23:48:45 | 000,480,240 | —- | C] () – C:\Users\Blake Foster\Desktop\2305857168011.pdf
[2011/03/20 21:39:22 | 004,454,569 | —- | C] () – C:\Users\Blake Foster\Documents\chem session.wma
[2011/03/20 19:19:04 | 000,009,821 | —- | C] () – C:\Users\Blake Foster\Documents\chemreviewsession2.odt
[2011/03/19 02:32:26 | 000,417,021 | —- | C] () – C:\Users\Blake Foster\Documents\nukefromorbit.png
[2011/03/15 15:19:09 | 000,007,292 | —- | C] () – C:\Users\Blake Foster\Desktop\chess-langley2.jpg
[2011/03/13 22:55:33 | 000,085,932 | —- | C] () – C:\Users\Blake Foster\Documents\ragecomic.png
[2011/03/11 18:45:28 | 000,000,730 | —- | C] () – C:\Users\Blake Foster\Desktop\readme.html
[2011/03/11 18:45:27 | 033,554,432 | —- | C] () – C:\Users\Blake Foster\Desktop\Zelda - Majora's Mask.z64
[2011/03/11 17:23:04 | 000,002,097 | —- | C] () – C:\Users\Blake Foster\Desktop\Project64 1.6.lnk
[2011/03/09 17:04:10 | 000,018,483 | —- | C] () – C:\Users\Blake Foster\Documents\lab3.cmbl
[2011/03/09 01:32:44 | 000,019,355 | —- | C] () – C:\Users\Blake Foster\Documents\physics 151labrep3.odt
[2011/03/08 18:11:28 | 000,337,094 | —- | C] () – C:\Users\Blake Foster\Documents\fitness bb.odp
[2011/03/08 17:47:05 | 000,020,322 | —- | C] () – C:\Users\Blake Foster\Documents\bulletin board reflection.odt
[2011/03/08 17:37:34 | 000,019,177 | —- | C] () – C:\Users\Blake Foster\Documents\report 4.odt
[2011/03/07 18:49:38 | 000,245,054 | —- | C] () – C:\Users\Blake Foster\Documents\clicker.png
[2011/03/01 18:11:02 | 000,341,755 | —- | C] () – C:\Users\Blake Foster\Documents\fitnessbb.odp
[2011/03/01 11:17:39 | 000,018,714 | —- | C] () – C:\Users\Blake Foster\Documents\bulletin board.odt
[2011/03/01 09:00:03 | 000,017,220 | —- | C] () – C:\Users\Blake Foster\Documents\music notes.odt
[2011/03/01 01:51:54 | 000,124,231 | —- | C] () – C:\Users\Blake Foster\Documents\ragecomci.png
[2011/03/01 01:40:22 | 000,264,143 | —- | C] () – C:\Users\Blake Foster\Documents\willprofile.png
[2011/03/01 00:52:03 | 000,000,991 | —- | C] () – C:\Users\Blake Foster\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStove.lnk
[2011/03/01 00:52:03 | 000,000,967 | —- | C] () – C:\Users\Blake Foster\Desktop\PokerStove.lnk
[2011/02/27 03:15:33 | 000,004,997 | —- | C] () – C:\ProgramData\bltofzsb.qlf
[2011/01/30 01:55:08 | 000,000,693 | —- | C] () – C:\Users\Blake Foster\AppData\Roaming\MPQEditor.ini
[2011/01/13 12:40:20 | 000,000,254 | —- | C] () – C:\Windows\RomeTW.ini
[2011/01/10 14:16:36 | 000,743,594 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/16 19:26:22 | 000,066,856 | —- | C] () – C:\Windows\SysWow64\SynTPEnhPS.dll
[2010/12/07 13:18:39 | 000,002,351 | —- | C] () – C:\Windows\ChessMentor.ini
[2010/12/03 19:10:17 | 001,970,176 | —- | C] () – C:\Windows\SysWow64\d3dx9.dll
[2010/11/30 01:57:22 | 000,008,704 | —- | C] () – C:\Users\Blake Foster\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/22 09:42:49 | 000,344,064 | —- | C] () – C:\Windows\SysWow64\dleacomx.dll
[2010/10/22 09:42:49 | 000,331,776 | —- | C] () – C:\Windows\SysWow64\DLEAinst.dll
[2010/10/22 09:42:49 | 000,323,584 | —- | C] () – C:\Windows\SysWow64\dleains.dll
[2010/10/22 09:42:49 | 000,262,144 | —- | C] () – C:\Windows\SysWow64\dleainsb.dll
[2010/10/22 09:42:49 | 000,253,952 | —- | C] () – C:\Windows\SysWow64\dleacu.dll
[2010/10/22 09:42:49 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\dleainsr.dll
[2010/10/22 09:42:49 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\dleacub.dll
[2010/10/22 09:42:49 | 000,086,180 | —- | C] () – C:\Windows\SysWow64\DLEAcfg.dll
[2010/10/22 09:42:49 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\dleajswr.dll
[2010/10/22 09:42:49 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\dleacur.dll
[2010/10/22 09:42:32 | 000,299,008 | —- | C] () – C:\Windows\SysWow64\DLEAsm.dll
[2010/10/22 09:42:32 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\DLEAsmr.dll
[2010/10/15 09:41:18 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/09/23 22:30:50 | 000,000,016 | —- | C] () – C:\Windows\entpack.ini
[2010/09/05 00:33:51 | 000,129,024 | —- | C] () – C:\Windows\SysWow64\AVERM.dll
[2010/09/05 00:33:51 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\AVEQT.dll
[2010/08/10 17:43:59 | 000,007,602 | —- | C] () – C:\Users\Blake Foster\AppData\Local\Resmon.ResmonCfg
[2010/08/08 17:15:00 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/08/08 11:49:06 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/08/08 11:38:14 | 000,001,105 | —- | C] () – C:\Windows\SysWow64\atipblup.dat
[2010/08/07 08:18:24 | 003,265,024 | —- | C] () – C:\Windows\es.exe
[2010/07/28 03:41:26 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/28 03:41:26 | 000,104,636 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/28 03:41:24 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/09 15:00:32 | 000,041,872 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2010/06/09 18:35:06 | 000,002,189 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2010/03/09 22:44:58 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/03/09 22:44:58 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2004/02/20 16:36:34 | 000,416,256 | —- | C] () – C:\Windows\exchndl.dll

========== LOP Check ==========

[2011/02/22 18:49:02 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\.minecraft
[2010/11/09 11:07:45 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\acccore
[2010/11/27 00:32:37 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\BatteryBar
[2011/01/01 15:26:35 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\ChessBase
[2010/12/23 12:09:16 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\DAEMON Tools Lite
[2011/03/03 03:58:40 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\DNA
[2010/12/03 14:18:00 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\EVEMon
[2010/09/05 00:33:53 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\GetRightToGo
[2010/11/14 23:01:10 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\Guitar Pro 6
[2010/10/03 15:37:36 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\OnLive App
[2010/08/31 18:28:18 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\OpenOffice.org
[2010/09/03 13:47:31 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\Rainmeter
[2011/01/07 16:47:30 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\RIFT
[2010/12/03 14:54:32 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\TS3Client
[2011/03/18 16:55:14 | 000,000,000 | —D | M] – C:\Users\Blake Foster\AppData\Roaming\uTorrent
[2011/01/30 15:57:41 | 000,032,544 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\Blake Foster\Desktop\Step.Brothers[2008][Unrated.Edition]DvDrip-ColinWithaT.avi:TOC.WMV

< End of report >


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:19:59 AM, on 3/30/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Blake Foster\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asearch.babylon.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2008147149-1644845097-2794928718-1008\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'postgres')
O4 - HKUS\S-1-5-21-2008147149-1644845097-2794928718-1008\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'postgres')
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: dleaCATSCustConnectService - Unknown owner - C:\Windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe
O23 - Service: dlea_device - - C:\Windows\system32\dleacoms.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~2\PHAROS~1\Core\CTskMstr.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9160 bytes
Run OTL.exe by right-clicking and choosing Run as Administrator on the icon
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    [2011/02/27 03:15:33 | 000,004,997 | —- | C] () – C:\ProgramData\bltofzsb.qlf
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new the resulting OTL log here


Please let me know how your computer is running now, especially with regard to the redirects.
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\ProgramData\bltofzsb.qlf moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Blake Foster ->Temp folder emptied: 81279485 bytes ->Temporary Internet Files folder emptied: 21027520 bytes ->Java cache emptied: 99049839 bytes ->FireFox cache emptied: 461647954 bytes ->Google Chrome cache emptied: 94899606 bytes ->Flash cache emptied: 197599 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: postgres ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84726 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 723.00 mb [EMPTYFLASH] User: All Users User: Blake Foster ->Flash cache emptied: 0 bytes User: Default User: Default User User: postgres User: Public Total Flash Files Cleaned = 0.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.22.3 log created on 03302011_132503 Files\Folders moved on Reboot… C:\Users\Blake Foster\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot…
i checked my redirects after that, and I was able to access sites I wasn't able to access before (yamaha.com for instance), but then I tried some of the other ones I was having trouble with I got redirected again :( Even websites like steam.com are still being redirected
Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Right-Click and choose Run as Administrator on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now



Also, please tell me if you are using a router. If you are, are there multiple computers using it or is your computer the only one?
This is very frustrating. I am downloading it directly to the desktop, and starting as administrator. All windows/processes are closed. I have tried both download links, yet whenever I open combofix the green bar makes it almost to the end and then it stops working! Any ideas?
Can I confirm that you do not have any antivirus program on this machine? I don't think I see any entries in the log for one.

Download and Run RKill

Please download and run the following tool to help allow other programs to run. (Thanks to Grinler of BleepingComputer.com)
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin

You only need to get one of these to run, not all of them.
Rkill.exe
Rkill.com
Rkill.scr
Rkill.pif


Once it is downloaded, double-click on the rkill.com in order to automatically try to stop any processes associated with rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next steps.

If you get a message rkill is an infection, do not be concerned. The message is just a fake warning by some rogue programs when it terminates programs that may potentially remove it. The trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this should allow you to bypass the malware trying to protect itself so that rkill can terminate the rogue processes. Continue to try running Rkill until the malware is no longer running. You will then be able to proceed with the next steps.

Do not reboot your computer after running rkill as the malware programs will start again.



Then go ahead and follow the instructions for running Combofix.

If that does not please let me know.
Wow this is unbelievable. I don't know if this is the virus or my computer, but the first 3 links all did "this stopped working", and the fourth one 404'd. It seems to be happening with most exe programs, for instance a setup for avg that I tried to get going before I posted on this. I do have ad-aware but i made sure to turn it off and turn it off on the start up list as well as make sure the process is not running in the background.
I know this is frustrating, but stick with me. The malware is likely trying to block the tools we need to use to remove it.

Download Combofix from any of the links below but rename it to iexplore.exe before saving it to your desktop. (Leave the file type as Application.)

Link 1
Link 2

Right-click and choose Run as Administrator on the renamed ComboFix.exe (the icon should say iexpolore) & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.


If this still doesn't work then do the following:


Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account and try running Combofix again.
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.
I went into safe mode ( the iexplorer trick didnt work unfortunately), and whenever I opened combofix it would fill the bar all the way and then disspear and nothing would happen. This virus seems like it could be very serious, I'm considering reformatting. Do you have any other ideas to try to get combofix running? I really thought it would work in safe mode ;(
I know it seems like this thing has a hold on the computer - but it's doing just what it was designed to do. The malware is simply blocking the tools. Once we figure out how to stop that from happening we can remove it from your system. I'm not ready to give up yet. Let's try a scan with something different.

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan


[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply




If you have have access to another computer, I'd like you to also do the following:


Using another computer, please follow the instructions found on this page to download a portable copy of SuperAntiSpyware to a USB/flash drive.

The file will save with a random name (so that it is not recognized by malware). Please do not change the name to anything else.

Once you have it on the flash drive, I'd like you to run it from the flash drive on your machine and see if it will scan. You don't want to try to move the file to your computer or it may be blocked. It is designed to be launched from the flash drive.

Please post the results of any log file it generates.
Here is the log file from aswmbr, I can get the superantispyware done around 4 o'clock today. Though I have to say, I need my computer for the weekend to finish a project, and while I hate giving up too I may have to just reformat so I can get going on it :/ If we can't get it working tonight I don't think I have much of a choice aswMBR version 0.9.4 Copyright© 2011 AVAST Software Run date: 2011-04-01 12:10:36 —————————– 12:10:36.340 OS Version: Windows x64 6.1.7600 12:10:36.340 Number of processors: 4 586 0x2502 12:10:36.340 ComputerName: BLAKEFOSTER-PC UserName: Blake Foster 12:10:41.318 Initialize success 12:10:52.660 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 12:10:52.663 Disk 0 Vendor: ST950042 0006 Size: 476940MB BusType: 3 12:10:52.665 Disk 0 MBR read error 12:10:52.666 Disk 0 MBR scan 12:10:52.668 MBR BIOS signature not found 0 12:10:52.670 Service scanning 12:10:54.805 Disk 0 trace - called modules: 12:10:54.832 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys spgl.sys hal.dll 12:10:54.835 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800709f060] 12:10:54.838 3 CLASSPNP.SYS[fffff88001c7c43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004ff9050] 12:10:54.840 Scan finished successfully
Give SuperAntiSypware (SAS) a go when you can this afternoon. I'll keep an eye on this topic this evening so we can decide what the best course of action for you will be given your need to use the computer. I have also posted to see if my colleagues can offer any other ideas on cleaning the machine or how to get Combofix to run. Let me know how the scan goes….or doesn't.
combofix log ComboFix 11-04-01.01 - Blake Foster 04/01/2011 20:24:35.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3894.2702 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\windows\es.exe c:\windows\pthreadGC2.dll . . ((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 ))))))))))))))))))))))))))))))) . . 2011-04-02 00:33 . 2011-04-02 00:33 ——– d—–w- c:\users\postgres\AppData\Local\temp 2011-04-02 00:33 . 2011-04-02 00:33 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-04-01 23:25 . 2011-04-01 23:25 ——– d—–w- c:\users\Blake Foster\AppData\Roaming\SUPERAntiSpyware.com 2011-04-01 23:25 . 2011-04-01 23:25 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-04-01 17:43 . 2011-03-15 05:17 8424784 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{36F0A319-CB09-4276-BB93-DFE7409EE482}\mpengine.dll 2011-03-31 04:14 . 2011-03-31 04:14 12872 —-a-w- c:\windows\system32\bootdelete.exe 2011-03-31 04:04 . 2011-03-31 04:15 19528 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys 2011-03-31 04:03 . 2011-03-31 04:14 ——– d—–w- c:\programdata\Hitman Pro 2011-03-30 17:25 . 2011-03-30 17:25 ——– d—–w- C:\_OTL 2011-03-30 04:40 . 2011-03-30 05:59 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2011-03-30 04:40 . 2011-03-30 04:40 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2011-03-30 04:19 . 2011-03-30 04:19 388096 —-a-r- c:\users\Blake Foster\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-03-30 04:19 . 2011-03-30 04:19 ——– d—–w- c:\program files (x86)\Trend Micro 2011-03-30 04:05 . 2011-03-30 04:05 ——– d—–w- c:\programdata\MFAData 2011-03-30 02:56 . 2011-03-25 08:03 16432 —-a-w- c:\windows\system32\lsdelete.exe 2011-03-29 05:00 . 2011-03-25 08:03 69376 —-a-w- c:\windows\system32\drivers\Lbd.sys 2011-03-29 05:00 . 2011-03-29 05:00 49752 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-03-29 04:58 . 2011-03-29 04:58 ——– d—–w- c:\users\Blake Foster\AppData\Local\Sunbelt Software 2011-03-29 04:56 . 2011-03-29 04:56 ——– dc-h–w- c:\programdata\{8790345A-AF70-4319-B9E7-AAA25C6DCD42} 2011-03-29 04:42 . 2011-03-29 04:43 ——– d—–w- c:\programdata\Lavasoft 2011-03-29 04:42 . 2011-03-29 04:42 ——– d—–w- c:\program files (x86)\Lavasoft 2011-03-29 03:51 . 2011-03-29 04:46 ——– d—–w- c:\programdata\oPoJdOoJpMo05200 2011-03-24 15:57 . 2011-03-27 06:14 ——– d—–w- c:\program files (x86)\Warcraft III 2011-03-24 14:47 . 2011-03-24 15:52 ——– d—–w- c:\users\Blake Foster\Warcraft III 1.21b TFT Installer enUS 2011-03-24 14:46 . 2011-03-24 15:14 ——– d—–w- c:\users\Blake Foster\Warcraft III 1.21b ROC Installer enUS 2011-03-23 17:15 . 2011-03-18 17:53 142296 —-a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll 2011-03-23 17:15 . 2011-03-18 17:53 781272 —-a-w- c:\program files (x86)\Mozilla Firefox\mozsqlite3.dll 2011-03-23 17:15 . 2011-03-18 17:53 1874904 —-a-w- c:\program files (x86)\Mozilla Firefox\mozjs.dll 2011-03-23 17:15 . 2011-03-18 17:53 15832 —-a-w- c:\program files (x86)\Mozilla Firefox\mozalloc.dll 2011-03-23 17:15 . 2011-03-18 17:53 728024 —-a-w- c:\program files (x86)\Mozilla Firefox\libGLESv2.dll 2011-03-23 17:15 . 2011-03-18 17:53 142296 —-a-w- c:\program files (x86)\Mozilla Firefox\libEGL.dll 2011-03-23 17:15 . 2011-03-18 17:53 1893336 —-a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_42.dll 2011-03-23 17:15 . 2011-03-18 17:53 1975768 —-a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_42.dll 2011-03-15 01:57 . 2011-03-15 01:57 ——– d—–w- c:\users\Blake Foster\AppData\Local\Logitech 2011-03-15 01:48 . 2011-03-15 01:48 ——– d—–w- c:\program files\Common Files\Logitech 2011-03-15 01:48 . 2011-03-15 01:48 ——– d—–w- c:\program files\Logitech 2011-03-11 21:23 . 2011-03-14 19:57 ——– d—–w- c:\program files (x86)\Project64 1.6 2011-03-11 21:23 . 2011-03-11 21:23 40960 —-a-r- c:\users\Blake Foster\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe 2011-03-11 21:23 . 2011-03-11 21:23 40960 —-a-r- c:\users\Blake Foster\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe 2011-03-09 02:16 . 2010-12-23 06:07 961024 —-a-w- c:\windows\system32\CPFilters.dll 2011-03-09 02:16 . 2010-12-23 06:07 1118720 —-a-w- c:\windows\system32\sbe.dll 2011-03-09 02:16 . 2010-12-23 06:07 723968 —-a-w- c:\windows\system32\EncDec.dll 2011-03-09 02:16 . 2010-12-23 06:02 259072 —-a-w- c:\windows\system32\mpg2splt.ax 2011-03-09 02:16 . 2010-12-23 05:28 850432 —-a-w- c:\windows\SysWow64\sbe.dll 2011-03-09 02:16 . 2010-12-23 05:28 642048 —-a-w- c:\windows\SysWow64\CPFilters.dll 2011-03-09 02:16 . 2010-12-23 05:28 534528 —-a-w- c:\windows\SysWow64\EncDec.dll 2011-03-09 02:16 . 2010-12-23 05:24 199680 —-a-w- c:\windows\SysWow64\mpg2splt.ax 2011-03-09 02:16 . 2010-12-18 06:12 3138048 —-a-w- c:\windows\system32\mstscax.dll 2011-03-09 02:16 . 2010-12-18 05:30 2690560 —-a-w- c:\windows\SysWow64\mstscax.dll 2011-03-09 02:16 . 2010-12-18 06:08 1097216 —-a-w- c:\windows\system32\mstsc.exe 2011-03-09 02:16 . 2010-12-18 05:26 1034240 —-a-w- c:\windows\SysWow64\mstsc.exe . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-09 02:02 . 2010-06-24 16:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-02 22:11 . 2010-08-08 16:57 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-01-10 19:19 . 2011-01-10 19:19 178800 —-a-w- c:\windows\SysWow64\CmdLineExt_x64.dll 2011-01-07 08:06 . 2011-02-09 02:19 46080 —-a-w- c:\windows\system32\atmlib.dll 2011-01-07 07:27 . 2011-02-09 02:19 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2011-01-07 05:49 . 2011-02-09 02:19 366080 —-a-w- c:\windows\system32\atmfd.dll 2011-01-07 05:33 . 2011-02-09 02:19 294400 —-a-w- c:\windows\SysWow64\atmfd.dll 2011-01-05 04:00 . 2011-02-09 02:19 3127808 —-a-w- c:\windows\system32\win32k.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . R3 GPU-Z;GPU-Z;c:\users\BLAKEF~2\AppData\Local\Temp\GPU-Z.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe [2010-05-04 89600] R4 dlea_device;dlea_device;c:\windows\system32\dleacoms.exe [2010-05-21 1052328] R4 dleaCATSCustConnectService;dleaCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe [2010-05-21 45224] R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-03-25 1405384] R4 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2009-12-10 65536] R4 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 SASDIFSV;SASDIFSV;c:\users\BLAKEF~2\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x] S1 SASKUTIL;SASKUTIL;c:\users\BLAKEF~2\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-24 13336] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-06-09 2320920] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2008147149-1644845097-2794928718-1001Core.job - c:\users\Blake Foster\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-08 16:50] . 2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2008147149-1644845097-2794928718-1001UA.job - c:\users\Blake Foster\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-08 16:50] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local FF - ProfilePath - c:\users\Blake Foster\AppData\Roaming\Mozilla\Firefox\Profiles\trihwblg.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - google.com FF - user.js: network.protocol-handler.warn-external.dnupdate - false . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-04-01 20:35:06 ComboFix-quarantined-files.txt 2011-04-02 00:35 . Pre-Run: 55,491,481,600 bytes free Post-Run: 55,231,971,328 bytes free . - - End Of File - - 5718FC5475756117C5EA501E3243B65C

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI