This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Script Error re-direct (IE) - Suspect Rootkit

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Your help with this issue is greatly appreciated!

The problem: Internet Script error box pops up throughout the day. It lists a different random website in the error box. This happens even with IE closed (the process as well), It does not actually open the site it mentions.

Ran scans with malwarebytes, symantec, combofix, smitfraudfix, and the trend micro and sophos anti-rootkit programs

Checked the hosts file and it seems fine.

Ran OTL and gmer. Here are the logs:

OTL:


OTL logfile created on: 5/5/2011 05:04:50 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\administrator.AJC-INT\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 85.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.69 Gb Total Space | 49.23 Gb Free Space | 69.65% Space Free | Partition Type: NTFS

Computer Name: LKVCMY9 | User Name: Tech12Hidden | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\administrator.AJC-INT\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\administrator.AJC-INT\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CA_LIC_CLNT32) – File not found
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (NGCLIENT) – C:\Program Files\Symantec\Ghost\ngctw32.exe (Symantec Corporation)
SRV - (CASUniversalAgent) – C:\Program Files\CA\SharedComponents\BrightStor\UniAgent\UnivAgent.exe (CA)
SRV - (CASDiscoverySvc) – C:\Program Files\CA\SharedComponents\BrightStor\CADS\casdscsvc.exe (CA)
SRV - (OpenFileAgent) – C:\Program Files\CA\BrightStor Backup Agent for Open Files\Ofant.exe (CA)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SUService) – c:\Program Files\Lenovo\System Update\SUService.exe ( )
SRV - (PsaSrv) – C:\WINDOWS\system32\psasrv.exe ()
SRV - (LogWatch) – C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe (Computer Associates)
SRV - (CA_LIC_CLNT) – C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe (Computer Associates International Inc.)
SRV - (ThinkVantage Registry Monitor Service) – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe ()
SRV - (tvtnetwk) – C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe ()
SRV - (IPSSVC) – C:\WINDOWS\system32\IPSSVC.EXE (Lenovo Group Limited)
SRV - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (WMConnectCDS) – C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110504.002\navex15.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110504.002\naveng.sys (Symantec Corporation)
DRV - (SAVRKBootTasks) – C:\WINDOWS\system32\SAVRKBootTasks.sys (Sophos Plc)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LUsbFilt) – C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (OFADriver) – C:\WINDOWS\system32\drivers\ofant.sys (CA)
DRV - (psadd) – C:\WINDOWS\system32\drivers\psadd.sys (Lenovo)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (PROCDD) – C:\WINDOWS\system32\drivers\PROCDD.SYS (Lenovo Group Limited)
DRV - (HPFXBULK) – C:\WINDOWS\system32\drivers\hpfxbulk.sys (Hewlett Packard)
DRV - (BCMTPM) – C:\WINDOWS\system32\drivers\btpmw32.sys (Broadcom Corp.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (PrivateDisk) – C:\Program Files\Lenovo\SafeGuard PrivateDisk\privatediskm.sys (Utimaco Safeware AG)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (pelusblf) – C:\WINDOWS\system32\drivers\PELUSBLF.SYS (Primax Electronics Ltd.)
DRV - (pelmouse) – C:\WINDOWS\system32\drivers\PELMOUSE.SYS (Primax Electronics Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 15:20:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/04/29 15:20:17 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\administrator.AJC-INT\Application Data\Mozilla\Extensions
[2011/05/04 11:00:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\administrator.AJC-INT\Application Data\Mozilla\Firefox\Profiles\g1920231.default\extensions
[2011/05/05 16:23:13 | 000,000,000 | —D | M] (XUL Cache) – C:\Documents and Settings\administrator.AJC-INT\Application Data\Mozilla\Firefox\Profiles\g1920231.default\extensions\{c75acb6f-4a60-463d-9367-ce1de49d6312}
[2011/04/08 10:06:51 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2011/04/29 15:20:54 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/28 18:58:21 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {013B4DDC-C53B-44FF-8777-6D407F06DE5f} - C:\WINDOWS\system32\AUCPLMNT32.dll ()
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (48fce1f) - {A7FBA9D1-C129-968F-9FD5-3057A814A1B9} - C:\WINDOWS\system32\msobjs32.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (CPwmIEBrowserHelper Object) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [NGTray] C:\Program Files\Symantec\Ghost\ngtray.exe (Symantec Corporation)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\RunOnce: [InnoSetupRegFile.0000000001] C:\WINDOWS\is-4CG1H.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware (registration)] C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10d.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : ThinkVantage Password Manager… - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O9 - Extra Button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe ()
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclien…ent/ieatgpc.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.201 10.1.1.9 10.1.1.203 [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ajc-int.org
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AwayNotify: DllName - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll (Lenovo Group Limited)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/30 03:13:35 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2011/05/05 17:02:38 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\administrator.AJC-INT\Desktop\OTL.exe
[2011/05/05 16:57:04 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/05 16:56:17 | 007,734,240 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\administrator.AJC-INT\Desktop\mbam-setup.exe
[2011/05/05 16:28:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/05/05 11:02:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/05/04 15:24:02 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/04 15:18:50 | 000,000,000 | —D | C] – C:\Anti Rootkit
[2011/05/04 11:00:27 | 000,786,432 | —- | C] (AIDEX Team) – C:\WINDOWS\System32\OGACheckControl32.exe
[2011/04/29 16:14:53 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Desktop\RootkitRevealer
[2011/04/29 16:07:29 | 000,018,816 | —- | C] (Sophos Plc) – C:\WINDOWS\System32\SAVRKBootTasks.sys
[2011/04/29 15:24:26 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2011/04/29 15:24:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Sophos
[2011/04/29 15:24:09 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\My Documents\Downloads
[2011/04/29 15:20:11 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Local Settings\Application Data\Mozilla
[2011/04/29 15:20:11 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Application Data\Mozilla
[2011/04/29 15:14:05 | 001,377,112 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\administrator.AJC-INT\Desktop\abc.exe
[2011/04/29 15:13:19 | 001,377,112 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\administrator.AJC-INT\Desktop\tdsskiller.exe
[2011/04/29 15:09:21 | 001,377,112 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\administrator.AJC-INT\Desktop\123.exe.exe
[2011/04/28 19:02:45 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Application Data\WinRAR
[2011/04/28 19:02:45 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Desktop\gmer
[2011/04/28 18:56:00 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/04/28 18:37:08 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/04/28 18:32:34 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/04/28 18:27:40 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/04/28 18:27:40 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/04/28 18:27:40 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/04/28 18:27:40 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/04/28 18:27:32 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/04/28 18:27:18 | 000,000,000 | —D | C] – C:\Qoobox
[2011/04/28 18:11:04 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Application Data\Logitech
[2011/04/28 18:08:27 | 001,930,720 | —- | C] (Symantec Corporation) – C:\Documents and Settings\administrator.AJC-INT\Desktop\FixTDSS.exe
[2011/04/28 15:59:21 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Application Data\SUPERAntiSpyware.com
[2011/04/28 15:53:16 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Desktop\SmitfraudFix
[2011/04/28 15:49:26 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\administrator.AJC-INT\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/28 15:49:20 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Application Data\Macromedia
[2011/04/28 15:49:19 | 000,000,000 | —D | C] – C:\Documents and Settings\administrator.AJC-INT\Application Data\Adobe
[2011/04/28 15:30:12 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\mbam-setup-1.50.1.1100.exe
[2011/04/11 17:41:22 | 000,000,000 | —D | C] – C:\a684f70c3af0ec5e31257fe70e5483
[2011/04/11 17:40:40 | 000,000,000 | —D | C] – C:\062e3bfa127fd23b07ff124a6f87c7
[2011/04/11 11:55:51 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/04/11 11:55:42 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/04/11 11:54:40 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2011/04/11 11:54:40 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2011/04/11 11:54:40 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/04/11 11:54:30 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/04/11 11:53:41 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2011/04/11 11:53:19 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/04/11 11:51:37 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2011/04/08 10:54:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Glary Registry Repair
[2011/04/08 10:54:47 | 000,000,000 | —D | C] – C:\Program Files\Glary Registry Repair
[2011/04/08 10:06:50 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/04/06 12:18:36 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2011/04/06 12:18:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2011/04/06 12:18:15 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2011/04/06 12:16:36 | 000,014,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg2.dll
[2011/04/06 12:10:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RegScrubVistaXP
[2011/04/06 12:10:27 | 000,000,000 | —D | C] – C:\Program Files\RegScrubVistaXP
[2011/04/06 11:57:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/06 11:56:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/04/06 11:56:36 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/04/06 11:55:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ParetoLogic
[2011/04/06 11:55:09 | 000,000,000 | —D | C] – C:\Program Files\ParetoLogic
[2011/04/06 11:55:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/05 17:03:44 | 000,000,287 | —- | M] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\[Closed] Random internet explorer script errors.url
[2011/05/05 17:02:39 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\administrator.AJC-INT\Desktop\OTL.exe
[2011/05/05 16:56:23 | 007,734,240 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\administrator.AJC-INT\Desktop\mbam-setup.exe
[2011/05/05 16:55:24 | 000,002,278 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/05 16:54:58 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/05 16:53:46 | 000,709,456 | —- | M] () – C:\WINDOWS\is-4CG1H.exe
[2011/05/05 16:53:46 | 000,010,562 | —- | M] () – C:\WINDOWS\is-4CG1H.msg
[2011/05/05 16:53:46 | 000,000,374 | —- | M] () – C:\WINDOWS\is-4CG1H.lst
[2011/05/05 16:18:00 | 000,000,256 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2011/05/05 11:02:34 | 000,001,743 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/05/04 18:00:00 | 000,000,446 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/05/04 15:24:01 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/04 11:00:27 | 000,184,832 | —- | M] () – C:\WINDOWS\System32\msobjs32.dll
[2011/05/04 11:00:27 | 000,000,106 | —- | M] () – C:\WINDOWS\System32\240290109
[2011/05/04 11:00:24 | 000,361,472 | —- | M] () – C:\WINDOWS\System32\AUCPLMNT32.dll
[2011/05/04 11:00:23 | 000,786,432 | —- | M] (AIDEX Team) – C:\WINDOWS\System32\OGACheckControl32.exe
[2011/04/29 16:14:17 | 000,002,545 | —- | M] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\RootkitRevealer.url
[2011/04/29 16:14:11 | 000,231,390 | —- | M] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\RootkitRevealer.zip
[2011/04/29 14:32:12 | 001,377,112 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\administrator.AJC-INT\Desktop\tdsskiller.exe
[2011/04/29 14:32:12 | 001,377,112 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\administrator.AJC-INT\Desktop\abc.exe
[2011/04/29 14:32:12 | 001,377,112 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\administrator.AJC-INT\Desktop\123.exe.exe
[2011/04/28 18:58:23 | 000,002,212 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2011/04/28 18:58:21 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/28 18:44:41 | 000,444,028 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/28 18:44:41 | 000,071,904 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/28 18:32:38 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/04/28 18:10:54 | 000,000,824 | —- | M] () – C:\Documents and Settings\administrator.AJC-INT\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/28 17:33:52 | 001,872,472 | —- | M] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\SmitfraudFix.exe
[2011/04/28 17:33:04 | 004,332,535 | R— | M] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\ComboFix.exe
[2011/04/28 15:52:44 | 000,001,462 | RHS- | M] () – C:\Documents and Settings\administrator.AJC-INT\ntuser.pol
[2011/04/28 15:49:55 | 000,709,456 | —- | M] () – C:\WINDOWS\is-G4DNK.exe
[2011/04/28 15:49:55 | 000,010,562 | —- | M] () – C:\WINDOWS\is-G4DNK.msg
[2011/04/28 15:49:55 | 000,000,374 | —- | M] () – C:\WINDOWS\is-G4DNK.lst
[2011/04/28 15:30:15 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup-1.50.1.1100.exe
[2011/04/28 15:30:15 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\administrator.AJC-INT\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/12 11:57:03 | 000,142,032 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/12 11:41:37 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/11 17:11:52 | 004,318,945 | —- | M] () – C:\ComboFix.exe
[2011/04/10 04:13:00 | 000,000,360 | —- | M] () – C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/08 10:08:39 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2011/04/08 10:06:54 | 000,000,733 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/06 12:10:29 | 000,000,798 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RegScrubVistaXP.lnk
[2011/04/06 11:56:44 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/04/06 11:55:39 | 000,000,420 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/06 11:55:38 | 000,000,378 | —- | M] () – C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/06 11:31:23 | 000,000,104 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~18734900
[2011/04/06 11:31:22 | 000,000,128 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~18734900r
[2011/04/06 11:31:15 | 000,000,336 | —- | M] () – C:\Documents and Settings\All Users\Application Data\18734900
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/05 17:03:44 | 000,000,287 | —- | C] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\[Closed] Random internet explorer script errors.url
[2011/05/05 16:53:46 | 000,709,456 | —- | C] () – C:\WINDOWS\is-4CG1H.exe
[2011/05/05 16:53:46 | 000,010,562 | —- | C] () – C:\WINDOWS\is-4CG1H.msg
[2011/05/05 16:53:46 | 000,000,374 | —- | C] () – C:\WINDOWS\is-4CG1H.lst
[2011/05/05 11:02:34 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/05/05 11:02:34 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/05/04 11:00:27 | 000,184,832 | —- | C] () – C:\WINDOWS\System32\msobjs32.dll
[2011/05/04 11:00:25 | 000,000,106 | —- | C] () – C:\WINDOWS\System32\240290109
[2011/05/04 11:00:24 | 000,361,472 | —- | C] () – C:\WINDOWS\System32\AUCPLMNT32.dll
[2011/04/29 16:14:17 | 000,002,545 | —- | C] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\RootkitRevealer.url
[2011/04/29 16:14:09 | 000,231,390 | —- | C] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\RootkitRevealer.zip
[2011/04/28 19:02:39 | 000,284,915 | —- | C] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\gmer.zip
[2011/04/28 18:58:23 | 000,002,212 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2011/04/28 18:32:38 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/04/28 18:32:37 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/04/28 18:27:40 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/04/28 18:27:40 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/04/28 18:27:40 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/04/28 18:27:40 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/04/28 18:27:40 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/04/28 15:49:55 | 000,709,456 | —- | C] () – C:\WINDOWS\is-G4DNK.exe
[2011/04/28 15:49:55 | 000,010,562 | —- | C] () – C:\WINDOWS\is-G4DNK.msg
[2011/04/28 15:49:55 | 000,000,374 | —- | C] () – C:\WINDOWS\is-G4DNK.lst
[2011/04/28 15:49:26 | 004,332,535 | R— | C] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\ComboFix.exe
[2011/04/28 15:49:26 | 001,872,472 | —- | C] () – C:\Documents and Settings\administrator.AJC-INT\Desktop\SmitfraudFix.exe
[2011/04/28 15:47:38 | 000,001,462 | RHS- | C] () – C:\Documents and Settings\administrator.AJC-INT\ntuser.pol
[2011/04/28 15:42:32 | 004,318,945 | —- | C] () – C:\ComboFix.exe
[2011/04/28 15:42:31 | 001,872,472 | —- | C] () – C:\SmitfraudFix.exe
[2011/04/08 10:08:39 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/04/08 10:06:53 | 000,000,739 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/08 10:06:53 | 000,000,733 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/06 12:19:46 | 000,087,496 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/04/06 12:10:29 | 000,000,798 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RegScrubVistaXP.lnk
[2011/04/06 11:56:44 | 000,001,685 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/04/06 11:56:38 | 000,000,446 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/04/06 11:55:38 | 000,000,420 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/06 11:55:36 | 000,000,378 | —- | C] () – C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/06 11:55:34 | 000,000,360 | —- | C] () – C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/06 11:31:22 | 000,000,128 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~18734900r
[2011/04/06 11:31:22 | 000,000,104 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~18734900
[2011/04/06 11:31:15 | 000,000,336 | —- | C] () – C:\Documents and Settings\All Users\Application Data\18734900
[2010/08/31 13:04:35 | 000,000,314 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/09/23 17:17:42 | 000,140,573 | —- | C] () – C:\WINDOWS\hpwins06.dat
[2009/09/23 17:17:42 | 000,001,756 | —- | C] () – C:\WINDOWS\hpwmdl06.dat
[2009/08/07 08:59:57 | 000,001,302 | —- | C] () – C:\WINDOWS\hpbvnstp.ini
[2009/08/06 19:12:04 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\hppapr04.dll
[2009/08/06 19:12:04 | 000,000,647 | —- | C] () – C:\WINDOWS\System32\hppapr04.dat
[2007/10/18 16:29:45 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/10/18 16:13:13 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/09/25 15:36:20 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/09/25 15:35:38 | 000,000,518 | —- | C] () – C:\Documents and Settings\All Users\Application Data\tvt_userinfo.ini
[2007/09/25 15:30:01 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\drivers\psasrv.exe
[2007/09/25 15:25:46 | 000,000,040 | —- | C] () – C:\WINDOWS\System32\profile.dat
[2007/09/25 15:18:22 | 000,650,608 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2007/09/25 15:18:22 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4764.dll
[2007/09/25 15:18:00 | 000,005,528 | —- | C] () – C:\WINDOWS\System32\Setup2k.ini
[2007/09/25 15:18:00 | 000,000,296 | —- | C] () – C:\WINDOWS\System32\presetup.ini
[2007/09/25 15:17:59 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\FSRremoC.DLL
[2007/09/25 15:17:59 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\FSRremoS.EXE
[2007/09/25 15:12:44 | 000,000,138 | —- | C] () – C:\WINDOWS\System32\Softkbd.exe.config
[2007/03/05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/11/16 19:14:14 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\psasrv.exe
[2006/06/27 05:57:45 | 000,010,042 | —- | C] () – C:\WINDOWS\System32\PROCDB.INI
[2006/06/27 05:57:41 | 000,000,487 | —- | C] () – C:\WINDOWS\System32\IPSCTRL.INI
[2006/04/30 03:31:51 | 000,004,670 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/04/30 03:22:10 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/04/30 03:19:56 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/04/30 03:10:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/04/30 02:55:59 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/04/30 02:55:55 | 000,444,028 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/04/30 02:55:55 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/04/30 02:55:55 | 000,071,904 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/04/30 02:55:55 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/04/30 02:55:54 | 000,004,547 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/04/30 02:55:52 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/04/30 02:55:50 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/04/30 02:55:44 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/04/30 02:55:44 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/04/30 02:55:37 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/04/30 02:55:28 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/04/29 20:04:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/04/29 20:03:29 | 000,142,032 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/03/31 13:36:50 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\DEVMAN.DLL
[2005/07/08 04:06:00 | 000,114,688 | —- | C] () – C:\WINDOWS\desktopset.exe

========== LOP Check ==========

[2007/09/25 15:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\administrator.AJC-INT\Application Data\Lenovo
[2007/09/25 15:35:36 | 000,000,000 | —D | M] – C:\Documents and Settings\administrator.AJC-INT\Application Data\ThinkVantage
[2010/01/25 16:17:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canon
[2007/09/25 15:35:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lenovo
[2011/04/06 11:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/05/05 16:18:00 | 000,000,256 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2011/05/04 18:00:00 | 000,000,446 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration3.job
[2011/04/06 11:55:39 | 000,000,420 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
[2011/04/06 11:55:38 | 000,000,378 | —- | M] () – C:\WINDOWS\Tasks\PC Health Advisor Defrag.job
[2011/04/10 04:13:00 | 000,000,360 | —- | M] () – C:\WINDOWS\Tasks\PC Health Advisor.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2011/04/11 17:11:52 | 004,318,945 | —- | M] () – C:\ComboFix.exe
[2011/04/28 15:30:15 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup-1.50.1.1100.exe
[2011/04/04 09:21:28 | 001,872,472 | —- | M] () – C:\SmitfraudFix.exe


< MD5 for: AGP440.SYS >
[2004/08/04 08:00:00 | 018,738,937 | -H– | M] () .cab file – C:\I386\sp2.cab:AGP440.sys
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2011/03/07 18:55:00 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2011/03/07 18:55:00 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 02:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 08:00:00 | 018,738,937 | -H– | M] () .cab file – C:\I386\sp2.cab:atapi.sys
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2011/03/07 18:55:00 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2011/03/07 18:55:00 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 01:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2005/10/11 20:07:12 | 000,874,240 | —- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B – C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 60 bytes -> C:\XP2kback:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\administrator.AJC-INT\Desktop\gmer.zip:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\administrator.AJC-INT\Desktop\abc.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Anti Rootkit:AFP_AfpInfo

< End of report >


Extras:


OTL Extras logfile created on: 5/5/2011 05:04:50 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\administrator.AJC-INT\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 85.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.69 Gb Total Space | 49.23 Gb Free Space | 69.65% Space Free | Partition Type: NTFS

Computer Name: LKVCMY9 | User Name: Tech12Hidden | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AllAlertsDisabled" = 1
"TermService" = 1
"DisableMonitoring" = 1
"FirewallDisableNotify" = 0x00000000
"UpdatesDisableNotify" = 0x00000000
"ANTIVIRUSDISABLENOTIFY" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Symantec\Ghost\ngctw32.exe" = C:\Program Files\Symantec\Ghost\ngctw32.exe:*:Enabled:Symantec Ghost Client Agent – (Symantec Corporation)
"C:\WINDOWS\system32\dpcdll32.exe" = C:\WINDOWS\system32\dpcdll32.exe:*:Enabled:Windows Update Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Symantec\Ghost\ngctw32.exe" = C:\Program Files\Symantec\Ghost\ngctw32.exe:*:Enabled:Symantec Ghost Client Agent – (Symantec Corporation)
"C:\WINDOWS\system32\dpcdll32.exe" = C:\WINDOWS\system32\dpcdll32.exe:*:Enabled:Windows Update Service


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0197A98E-5E39-4FD6-9DD0-55630776782A}" = CALicense
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = ThinkVantage Technologies Welcome Message
"{2085C617-589C-40F8-BE40-EDBC9E2CA2EB}" = Symantec AntiVirus
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{324CEC09-007A-48eb-90E0-9D42D4D5EB0A}" = NetDeviceManager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}" = ParetoLogic PC Health Advisor
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{4572EB17-A274-4EF0-B9C1-CA6061D413C9}" = CA BrightStor ARCserve Backup Client Agent for Windows
"{48227AEB-DC8E-4A90-A274-0B4A39D699B1}" = Client Security Solution
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7726CF62-7B45-4E6D-9266-615346816BCA}" = Rescue and Recovery
"{796E076A-82F7-4D49-98C8-DEC0C3BC733A}" = Diskeeper Lite
"{8675339C-128C-44DD-83BF-0A5D6ABD8297}" = System Update
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{9576B4EE-5E87-4C14-AFCE-2F6FC2B276B8}" = Broadcom TPM Driver Installer
"{986F64DC-FF15-449D-998F-EE3BCEC6666A}" = Help Center
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D22599D-E1F4-4934-8B4D-2BBA46662251}" = System Migration Assistant
"{A0FEF031-E464-4B30-0AB3-00000DB3717B}" = Symantec Ghost Console Client
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AD277ED4-7E41-4074-911D-D34AF41B9D49}" = HP Officejet Pro K5300/5400 Series
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B660EDC0-EFF9-42D3-9DEE-E821895E503E}" = CA BrightStor ARCserve Backup Diagnostic Utilities
"{BB5A79D6-60DC-4F81-BF2C-19568AA49BA3}" = CA BrightStor ARCserve Backup Agent for Open Files for Windows
"{BBE3E502-F1D6-4FC9-9844-CC0850B7C516}" = Network ScanGear Ver.2.21
"{C54ED2B6-1AF2-416F-BBA8-5E2B8CDCB5C4}" = XP Themes
"{C6876FE6-A314-4628-B0D7-F3EE5E35C4B4}" = Windows Live Toolbar
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}" = ThinkVantage Productivity Center
"{D1ADE2BF-32D3-4EC3-9BF4-F5E1A740F92E}" = Color Network ScanGear Ver.2.42
"{D728E945-256D-4477-B377-6BBA693714AC}" = Productivity Center Supplement for ThinkCentre
"{DA320635-F48C-4613-8325-D75A933C549E}" = ThinkVantage System Update Toolbar Button for IE
"{E7E836B8-4BDD-454F-82E6-5FEA17C83AD4}" = Message Center
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F386C340-DF4B-4BBA-9503-420FB7EDB395}" = Wallpapers
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVS Disc Creator 2.1_is1" = AVS Disc Creator version 2.1
"AVSDiscCreator_is1" = AVS Disc Creator version 2.1
"AwayTask" = ThinkVantage Away Manager
"CCleaner" = CCleaner
"Glary Registry Repair_is1" = Glary Registry Repair 3.3.0.852
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{BBE3E502-F1D6-4FC9-9844-CC0850B7C516}" = Network ScanGear Ver.2.21
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5
"MouseSuite98" = Mouse Suite
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office14.OUTLOOK" = Microsoft Outlook 2010
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"Picasa2" = Picasa 2
"RegScrubVistaXP_is1" = RegScrubVistaXP v1.6
"Revo Uninstaller" = Revo Uninstaller 1.83
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.4
"SP6" = Logitech SetPoint 6.0
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/28/2011 06:18:34 PM | Computer Name = LKVCMY9 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17095, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 5/5/2011 04:49:17 PM | Computer Name = LKVCMY9 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 5/5/2011 04:49:17 PM | Computer Name = LKVCMY9 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm SASDIFSV SASKUTIL SAVRT SAVRTPEL SPBBCDrv SYMTDI

Error - 5/5/2011 04:51:55 PM | Computer Name = LKVCMY9 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 5/5/2011 04:53:59 PM | Computer Name = LKVCMY9 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/5/2011 04:55:04 PM | Computer Name = LKVCMY9 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 5/5/2011 04:55:39 PM | Computer Name = LKVCMY9 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/5/2011 04:56:45 PM | Computer Name = LKVCMY9 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 5/5/2011 04:56:45 PM | Computer Name = LKVCMY9 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm SASDIFSV SASKUTIL SAVRT SAVRTPEL SPBBCDrv SYMTDI

Error - 5/5/2011 05:05:14 PM | Computer Name = LKVCMY9 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 5/5/2011 05:05:15 PM | Computer Name = LKVCMY9 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >

Gmer:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2011-05-05 18:00:14
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1.AJC\LOCALS~1\Temp\fwldapob.sys


—- Devices - GMER 1.0.15 —-

Device \FileSystem\Fastfat \Fat B96B1D20

—- Threads - GMER 1.0.15 —-

Thread System [4:116] 8A723E84
Thread System [4:120] 8A726084

—- EOF - GMER 1.0.15 —-
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Thank you. Here is the scan log you requested: aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-09 14:44:11 —————————– 14:44:11.596 OS Version: Windows 5.1.2600 Service Pack 3 14:44:11.596 Number of processors: 2 586 0x605 14:44:11.596 ComputerName: LKVCMY9 UserName: bsachs 14:44:12.237 Initialize success 14:44:21.049 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 14:44:21.049 Disk 0 Vendor: WDC_WD800JD-08MSA1 10.01E01 Size: 76324MB BusType: 3 14:44:23.049 Disk 0 MBR read successfully 14:44:23.049 Disk 0 MBR scan 14:44:23.049 Disk 0 unknown MBR code 14:44:25.049 Disk 0 scanning sectors +156296385 14:44:25.065 Disk 0 scanning C:\WINDOWS\system32\drivers 14:44:34.909 Service scanning 14:44:36.096 Disk 0 trace - called modules: 14:44:36.096 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a73f1ed]<< 14:44:36.096 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a7d3ab8] 14:44:36.096 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000007b[0x8a7ccf18] 14:44:36.096 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a7cbd98] 14:44:36.096 \Driver\atapi[0x8a7f4750] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x8a73f1ed 14:44:36.112 Scan finished successfully 14:45:13.627 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\bsachs\Desktop\MBR.dat" 14:45:13.643 The log file has been saved successfully to "C:\Documents and Settings\bsachs\Desktop\aswMBR.txt"
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI