This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

shutdown on start up XP

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer shuts down on start up has to be unplugged to be restarted. When started it runs slow, freezes often and shuts down when opening some programs. Will not system restore. below are log files as directed

OTL logfile created on: 15/05/2011 11:47:43 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 145.46 Gb Free Space | 48.80% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.70 Gb Free Space | 5.45% Space Free | Partition Type: NTFS

Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\dvd43\DVD43_Tray.exe ()
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\OPLIMIT\OCRAWR32.EXE (Caere Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\OPLIMIT\OAHOOK32.DLL (Caere Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SpeedDiskService) – C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (Symantec RemoteAssist) – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (MSSQL$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110430.001\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110513.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SYMSpeedDisk) – C:\WINDOWS\system32\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (SymDSMon) – C:\WINDOWS\system32\drivers\SymDSMon.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS (Symantec Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (MPE) – C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (USB28xxBGA) – C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (USB28xxOEM) – C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (ASPI32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
DRV - (ScFBPNT2) – C:\WINDOWS\system32\drivers\ScFBPNT2.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.abc.net.au/"

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2010/08/20 09:16:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A53A86BF-726B-433B-A4FB-64298888E5D0}: C:\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\ [2011/03/24 10:49:35 | 000,000,000 | —D | M]

[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions\[removed]
[2010/04/02 16:02:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\[removed]

O1 HOSTS File: ([2010/04/05 21:50:35 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (Caere Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\WINDOWS\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - xvidvfw.dll File not found
Drivers32: VIDC.YV12 - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/15 11:33:52 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/09 12:12:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/09 12:12:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\malcom
[2011/05/09 12:12:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/09 12:12:44 | 000,000,000 | —D | C] – C:\Program Files\malcom
[2011/05/08 10:02:50 | 007,082,224 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/07 15:56:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/07 15:37:46 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/05/07 15:37:40 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/05/03 12:37:55 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Norton Utilities
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/05/02 16:37:25 | 000,000,000 | —D | C] – C:\Program Files\CDBurnerXP
[2011/05/02 16:09:40 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Xilisoft
[2011/05/02 16:09:24 | 000,000,000 | —D | C] – C:\Program Files\Xilisoft
[2011/05/01 10:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\PK
[2011/04/30 18:02:00 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\jacks mess
[2011/04/23 15:20:15 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\FrostWire
[2011/04/23 15:20:04 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FrostWire
[2011/04/23 15:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\FrostWire
[2011/04/15 10:10:31 | 021,460,432 | —- | C] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/15 11:46:11 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/15 11:35:18 | 000,625,664 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/15 11:11:23 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/05/15 11:01:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/15 11:00:50 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/15 10:59:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/15 10:45:10 | 000,000,757 | —- | M] () – C:\WINDOWS\oplimit.ini
[2011/05/12 07:57:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2011/05/11 08:34:22 | 000,000,610 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2011/05/10 18:33:49 | 021,039,108 | —- | M] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/09 11:47:18 | 000,001,688 | —- | M] () – C:\Documents and Settings\User\Desktop\Cyberlink PowerDirector.lnk
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/04 19:50:26 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/02 16:09:40 | 000,000,830 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/05/02 11:00:55 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/05/02 10:16:59 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 6.0 Professional.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | M] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/15 11:35:13 | 000,625,664 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/10 20:40:30 | 021,039,108 | —- | C] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/02 16:37:28 | 000,001,556 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\CDBurnerXP.lnk
[2011/05/02 16:37:25 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/05/02 16:09:39 | 000,000,830 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | C] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[2011/04/15 10:16:07 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/03/24 10:49:36 | 000,000,120 | —- | C] () – C:\WINDOWS\Xbejinodu.dat
[2011/03/24 10:49:36 | 000,000,000 | —- | C] () – C:\WINDOWS\Mjimujoxumu.bin
[2010/10/15 10:11:16 | 000,001,940 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/15 10:06:11 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/26 23:32:20 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/23 13:04:52 | 000,000,146 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2010/05/23 13:04:52 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2010/05/23 13:04:33 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2010/05/23 13:04:32 | 000,009,853 | —- | C] () – C:\WINDOWS\HL-2170W.INI
[2010/05/23 13:04:28 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/05/23 13:04:28 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2170W.DAT
[2010/05/23 13:03:37 | 000,000,318 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,303,104 | —- | C] () – C:\WINDOWS\emunist.exe
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/07/14 13:15:00 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,610 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:34:52 | 000,020,450 | —- | C] () – C:\WINDOWS\SICALIB2.DAT
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 19:19:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/02/04 10:50:07 | 000,000,323 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 23:50:47 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/19 23:49:51 | 000,331,480 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/19 20:22:52 | 000,115,200 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:08:54 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/19 14:05:27 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 22:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 22:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 22:00:00 | 000,480,114 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 22:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 22:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 22:00:00 | 000,086,296 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 22:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 22:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 22:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 22:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 22:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 22:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/02/09 13:46:30 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll

========== LOP Check ==========

[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/05/18 09:57:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/09/21 12:31:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2010/04/14 12:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2010/11/09 15:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/11 13:02:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/09/27 10:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Socusoft
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/05/11 09:41:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/02/23 16:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2010/07/05 20:25:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\4Media
[2010/06/06 14:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aura4You
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/04/06 18:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canon Easy-WebPrint EX
[2010/08/13 10:52:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CD-LabelPrint
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2010/07/28 16:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2011/05/02 16:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FrostWire
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2010/11/09 15:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\MyHeritage
[2010/07/22 18:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NCH Swift Sound
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2010/04/16 18:49:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Nvu
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/06/26 16:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2010/08/20 10:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tific
[2010/05/29 22:53:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Desktop Search
[2010/07/06 22:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Search
[2010/04/11 17:50:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\WinPatrol
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/14 22:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\atapi.sys
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/12 06:59:45 | 000,017,968 | —- | M] () – C:\avi_log.txt
[2009/01/19 14:03:10 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/28 15:33:52 | 000,015,698 | —- | M] () – C:\ComboFix.txt
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/11/19 12:19:55 | 000,077,730 | —- | M] () – C:\Fifa_World_Cup_will.jpg
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/04 08:00:35 | 000,002,575 | —- | M] () – C:\looklog.txt
[2010/05/01 18:22:02 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/02/14 16:12:02 | 001,389,056 | —- | M] (Creative Technology Ltd.) – C:\monfilt.sys
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 22:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 22:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/15 10:58:26 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/11/19 12:27:13 | 000,045,676 | —- | M] () – C:\ps2_007nightfire.jpg
[2010/04/08 09:22:20 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\rasacd.sys
[2010/07/02 14:44:44 | 000,009,685 | —- | M] () – C:\scramble.log
[2010/09/26 11:34:14 | 000,009,934 | —- | M] () – C:\Setup Log.txt
[2010/04/06 08:15:50 | 000,012,284 | —- | M] () – C:\TDSSKiller.2.2.8.1_06.04.2010_08.15.50_log.txt
[2010/06/06 14:20:27 | 000,000,976 | —- | M] () – C:\testFindSector.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/19 14:07:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/08/26 15:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2009/03/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDA1.DLL
[2005/08/26 15:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2009/03/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPA1.DLL
[2008/07/06 22:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/02/09 13:46:28 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 20:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/12/10 07:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ZIMFPRNT.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[1998/08/31 21:44:56 | 000,016,384 | —- | M] (Ulead Systems, Inc.) – C:\WINDOWS\Photo Express 2 SE.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/04/15 10:10:31 | 021,460,432 | —- | M] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\Program Files\atapi.sys

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/19 23:49:01 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/19 23:49:01 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/19 23:49:01 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/19 14:07:45 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/19 14:11:21 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/19 14:11:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2010/08/19 20:36:08 | 096,307,688 | —- | M] (Symantec Corporation) – C:\Documents and Settings\User\Desktop\NAV-UPGRADE-ESD-17-6-0-32-EN.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-11 04:45:14

< >

< >

< Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. >

< >

< When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. >

< Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. >

< You may need two posts to fit them both in. >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A96964
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96D0C06F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D287FACF

< End of report >

OTL logfile created on: 15/05/2011 11:47:43 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 145.46 Gb Free Space | 48.80% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.70 Gb Free Space | 5.45% Space Free | Partition Type: NTFS

Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\dvd43\DVD43_Tray.exe ()
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\OPLIMIT\OCRAWR32.EXE (Caere Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\OPLIMIT\OAHOOK32.DLL (Caere Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SpeedDiskService) – C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (Symantec RemoteAssist) – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (MSSQL$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110430.001\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110513.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SYMSpeedDisk) – C:\WINDOWS\system32\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (SymDSMon) – C:\WINDOWS\system32\drivers\SymDSMon.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS (Symantec Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (MPE) – C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (USB28xxBGA) – C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (USB28xxOEM) – C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (ASPI32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
DRV - (ScFBPNT2) – C:\WINDOWS\system32\drivers\ScFBPNT2.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.abc.net.au/"

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2010/08/20 09:16:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A53A86BF-726B-433B-A4FB-64298888E5D0}: C:\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\ [2011/03/24 10:49:35 | 000,000,000 | —D | M]

[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions\[removed]
[2010/04/02 16:02:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\[removed]

O1 HOSTS File: ([2010/04/05 21:50:35 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (Caere Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\WINDOWS\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - xvidvfw.dll File not found
Drivers32: VIDC.YV12 - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/15 11:33:52 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/09 12:12:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/09 12:12:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\malcom
[2011/05/09 12:12:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/09 12:12:44 | 000,000,000 | —D | C] – C:\Program Files\malcom
[2011/05/08 10:02:50 | 007,082,224 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/07 15:56:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/07 15:37:46 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/05/07 15:37:40 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/05/03 12:37:55 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Norton Utilities
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/05/02 16:37:25 | 000,000,000 | —D | C] – C:\Program Files\CDBurnerXP
[2011/05/02 16:09:40 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Xilisoft
[2011/05/02 16:09:24 | 000,000,000 | —D | C] – C:\Program Files\Xilisoft
[2011/05/01 10:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\PK
[2011/04/30 18:02:00 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\jacks mess
[2011/04/23 15:20:15 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\FrostWire
[2011/04/23 15:20:04 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FrostWire
[2011/04/23 15:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\FrostWire
[2011/04/15 10:10:31 | 021,460,432 | —- | C] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/15 11:46:11 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/15 11:35:18 | 000,625,664 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/15 11:11:23 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/05/15 11:01:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/15 11:00:50 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/15 10:59:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/15 10:45:10 | 000,000,757 | —- | M] () – C:\WINDOWS\oplimit.ini
[2011/05/12 07:57:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2011/05/11 08:34:22 | 000,000,610 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2011/05/10 18:33:49 | 021,039,108 | —- | M] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/09 11:47:18 | 000,001,688 | —- | M] () – C:\Documents and Settings\User\Desktop\Cyberlink PowerDirector.lnk
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/04 19:50:26 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/02 16:09:40 | 000,000,830 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/05/02 11:00:55 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/05/02 10:16:59 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 6.0 Professional.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | M] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/15 11:35:13 | 000,625,664 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/10 20:40:30 | 021,039,108 | —- | C] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/02 16:37:28 | 000,001,556 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\CDBurnerXP.lnk
[2011/05/02 16:37:25 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/05/02 16:09:39 | 000,000,830 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | C] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[2011/04/15 10:16:07 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/03/24 10:49:36 | 000,000,120 | —- | C] () – C:\WINDOWS\Xbejinodu.dat
[2011/03/24 10:49:36 | 000,000,000 | —- | C] () – C:\WINDOWS\Mjimujoxumu.bin
[2010/10/15 10:11:16 | 000,001,940 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/15 10:06:11 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/26 23:32:20 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/23 13:04:52 | 000,000,146 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2010/05/23 13:04:52 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2010/05/23 13:04:33 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2010/05/23 13:04:32 | 000,009,853 | —- | C] () – C:\WINDOWS\HL-2170W.INI
[2010/05/23 13:04:28 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/05/23 13:04:28 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2170W.DAT
[2010/05/23 13:03:37 | 000,000,318 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,303,104 | —- | C] () – C:\WINDOWS\emunist.exe
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/07/14 13:15:00 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,610 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:34:52 | 000,020,450 | —- | C] () – C:\WINDOWS\SICALIB2.DAT
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 19:19:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/02/04 10:50:07 | 000,000,323 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 23:50:47 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/19 23:49:51 | 000,331,480 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/19 20:22:52 | 000,115,200 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:08:54 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/19 14:05:27 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 22:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 22:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 22:00:00 | 000,480,114 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 22:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 22:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 22:00:00 | 000,086,296 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 22:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 22:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 22:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 22:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 22:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 22:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/02/09 13:46:30 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll

========== LOP Check ==========

[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/05/18 09:57:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/09/21 12:31:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2010/04/14 12:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2010/11/09 15:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/11 13:02:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/09/27 10:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Socusoft
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/05/11 09:41:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/02/23 16:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2010/07/05 20:25:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\4Media
[2010/06/06 14:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aura4You
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/04/06 18:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canon Easy-WebPrint EX
[2010/08/13 10:52:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CD-LabelPrint
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2010/07/28 16:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2011/05/02 16:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FrostWire
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2010/11/09 15:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\MyHeritage
[2010/07/22 18:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NCH Swift Sound
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2010/04/16 18:49:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Nvu
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/06/26 16:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2010/08/20 10:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tific
[2010/05/29 22:53:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Desktop Search
[2010/07/06 22:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Search
[2010/04/11 17:50:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\WinPatrol
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/14 22:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\atapi.sys
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/12 06:59:45 | 000,017,968 | —- | M] () – C:\avi_log.txt
[2009/01/19 14:03:10 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/28 15:33:52 | 000,015,698 | —- | M] () – C:\ComboFix.txt
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/11/19 12:19:55 | 000,077,730 | —- | M] () – C:\Fifa_World_Cup_will.jpg
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/04 08:00:35 | 000,002,575 | —- | M] () – C:\looklog.txt
[2010/05/01 18:22:02 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/02/14 16:12:02 | 001,389,056 | —- | M] (Creative Technology Ltd.) – C:\monfilt.sys
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 22:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 22:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/15 10:58:26 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/11/19 12:27:13 | 000,045,676 | —- | M] () – C:\ps2_007nightfire.jpg
[2010/04/08 09:22:20 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\rasacd.sys
[2010/07/02 14:44:44 | 000,009,685 | —- | M] () – C:\scramble.log
[2010/09/26 11:34:14 | 000,009,934 | —- | M] () – C:\Setup Log.txt
[2010/04/06 08:15:50 | 000,012,284 | —- | M] () – C:\TDSSKiller.2.2.8.1_06.04.2010_08.15.50_log.txt
[2010/06/06 14:20:27 | 000,000,976 | —- | M] () – C:\testFindSector.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/19 14:07:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/08/26 15:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2009/03/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDA1.DLL
[2005/08/26 15:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2009/03/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPA1.DLL
[2008/07/06 22:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/02/09 13:46:28 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 20:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/12/10 07:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ZIMFPRNT.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[1998/08/31 21:44:56 | 000,016,384 | —- | M] (Ulead Systems, Inc.) – C:\WINDOWS\Photo Express 2 SE.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/04/15 10:10:31 | 021,460,432 | —- | M] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\Program Files\atapi.sys

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/19 23:49:01 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/19 23:49:01 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/19 23:49:01 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/19 14:07:45 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/19 14:11:21 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/19 14:11:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2010/08/19 20:36:08 | 096,307,688 | —- | M] (Symantec Corporation) – C:\Documents and Settings\User\Desktop\NAV-UPGRADE-ESD-17-6-0-32-EN.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-11 04:45:14

< >

< >

< Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. >

< >

< When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. >

< Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. >

< You may need two posts to fit them both in. >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A96964
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96D0C06F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D287FACF

< End of report >

OTL logfile created on: 15/05/2011 11:47:43 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 145.46 Gb Free Space | 48.80% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.70 Gb Free Space | 5.45% Space Free | Partition Type: NTFS

Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\dvd43\DVD43_Tray.exe ()
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\OPLIMIT\OCRAWR32.EXE (Caere Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\OPLIMIT\OAHOOK32.DLL (Caere Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SpeedDiskService) – C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (Symantec RemoteAssist) – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (MSSQL$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110430.001\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110513.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SYMSpeedDisk) – C:\WINDOWS\system32\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (SymDSMon) – C:\WINDOWS\system32\drivers\SymDSMon.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS (Symantec Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (MPE) – C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (USB28xxBGA) – C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (USB28xxOEM) – C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (ASPI32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
DRV - (ScFBPNT2) – C:\WINDOWS\system32\drivers\ScFBPNT2.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.abc.net.au/"

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2010/08/20 09:16:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A53A86BF-726B-433B-A4FB-64298888E5D0}: C:\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\ [2011/03/24 10:49:35 | 000,000,000 | —D | M]

[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions\[removed]
[2010/04/02 16:02:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\[removed]

O1 HOSTS File: ([2010/04/05 21:50:35 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (Caere Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\WINDOWS\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - xvidvfw.dll File not found
Drivers32: VIDC.YV12 - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/15 11:33:52 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/09 12:12:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/09 12:12:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\malcom
[2011/05/09 12:12:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/09 12:12:44 | 000,000,000 | —D | C] – C:\Program Files\malcom
[2011/05/08 10:02:50 | 007,082,224 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/07 15:56:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/07 15:37:46 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/05/07 15:37:40 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/05/03 12:37:55 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Norton Utilities
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/05/02 16:37:25 | 000,000,000 | —D | C] – C:\Program Files\CDBurnerXP
[2011/05/02 16:09:40 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Xilisoft
[2011/05/02 16:09:24 | 000,000,000 | —D | C] – C:\Program Files\Xilisoft
[2011/05/01 10:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\PK
[2011/04/30 18:02:00 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\jacks mess
[2011/04/23 15:20:15 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\FrostWire
[2011/04/23 15:20:04 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FrostWire
[2011/04/23 15:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\FrostWire
[2011/04/15 10:10:31 | 021,460,432 | —- | C] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/15 11:46:11 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/15 11:35:18 | 000,625,664 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/15 11:11:23 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/05/15 11:01:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/15 11:00:50 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/15 10:59:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/15 10:45:10 | 000,000,757 | —- | M] () – C:\WINDOWS\oplimit.ini
[2011/05/12 07:57:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2011/05/11 08:34:22 | 000,000,610 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2011/05/10 18:33:49 | 021,039,108 | —- | M] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/09 11:47:18 | 000,001,688 | —- | M] () – C:\Documents and Settings\User\Desktop\Cyberlink PowerDirector.lnk
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/04 19:50:26 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/02 16:09:40 | 000,000,830 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/05/02 11:00:55 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/05/02 10:16:59 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 6.0 Professional.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | M] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/15 11:35:13 | 000,625,664 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/10 20:40:30 | 021,039,108 | —- | C] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/02 16:37:28 | 000,001,556 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\CDBurnerXP.lnk
[2011/05/02 16:37:25 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/05/02 16:09:39 | 000,000,830 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | C] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[2011/04/15 10:16:07 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/03/24 10:49:36 | 000,000,120 | —- | C] () – C:\WINDOWS\Xbejinodu.dat
[2011/03/24 10:49:36 | 000,000,000 | —- | C] () – C:\WINDOWS\Mjimujoxumu.bin
[2010/10/15 10:11:16 | 000,001,940 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/15 10:06:11 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/26 23:32:20 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/23 13:04:52 | 000,000,146 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2010/05/23 13:04:52 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2010/05/23 13:04:33 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2010/05/23 13:04:32 | 000,009,853 | —- | C] () – C:\WINDOWS\HL-2170W.INI
[2010/05/23 13:04:28 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/05/23 13:04:28 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2170W.DAT
[2010/05/23 13:03:37 | 000,000,318 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,303,104 | —- | C] () – C:\WINDOWS\emunist.exe
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/07/14 13:15:00 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,610 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:34:52 | 000,020,450 | —- | C] () – C:\WINDOWS\SICALIB2.DAT
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 19:19:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/02/04 10:50:07 | 000,000,323 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 23:50:47 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/19 23:49:51 | 000,331,480 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/19 20:22:52 | 000,115,200 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:08:54 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/19 14:05:27 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 22:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 22:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 22:00:00 | 000,480,114 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 22:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 22:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 22:00:00 | 000,086,296 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 22:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 22:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 22:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 22:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 22:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 22:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/02/09 13:46:30 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll

========== LOP Check ==========

[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/05/18 09:57:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/09/21 12:31:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2010/04/14 12:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2010/11/09 15:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/11 13:02:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/09/27 10:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Socusoft
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/05/11 09:41:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/02/23 16:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2010/07/05 20:25:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\4Media
[2010/06/06 14:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aura4You
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/04/06 18:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canon Easy-WebPrint EX
[2010/08/13 10:52:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CD-LabelPrint
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2010/07/28 16:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2011/05/02 16:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FrostWire
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2010/11/09 15:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\MyHeritage
[2010/07/22 18:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NCH Swift Sound
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2010/04/16 18:49:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Nvu
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/06/26 16:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2010/08/20 10:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tific
[2010/05/29 22:53:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Desktop Search
[2010/07/06 22:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Search
[2010/04/11 17:50:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\WinPatrol
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/14 22:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\atapi.sys
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/12 06:59:45 | 000,017,968 | —- | M] () – C:\avi_log.txt
[2009/01/19 14:03:10 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/28 15:33:52 | 000,015,698 | —- | M] () – C:\ComboFix.txt
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/11/19 12:19:55 | 000,077,730 | —- | M] () – C:\Fifa_World_Cup_will.jpg
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/04 08:00:35 | 000,002,575 | —- | M] () – C:\looklog.txt
[2010/05/01 18:22:02 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/02/14 16:12:02 | 001,389,056 | —- | M] (Creative Technology Ltd.) – C:\monfilt.sys
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 22:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 22:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/15 10:58:26 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/11/19 12:27:13 | 000,045,676 | —- | M] () – C:\ps2_007nightfire.jpg
[2010/04/08 09:22:20 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\rasacd.sys
[2010/07/02 14:44:44 | 000,009,685 | —- | M] () – C:\scramble.log
[2010/09/26 11:34:14 | 000,009,934 | —- | M] () – C:\Setup Log.txt
[2010/04/06 08:15:50 | 000,012,284 | —- | M] () – C:\TDSSKiller.2.2.8.1_06.04.2010_08.15.50_log.txt
[2010/06/06 14:20:27 | 000,000,976 | —- | M] () – C:\testFindSector.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/19 14:07:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/08/26 15:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2009/03/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDA1.DLL
[2005/08/26 15:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2009/03/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPA1.DLL
[2008/07/06 22:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/02/09 13:46:28 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 20:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/12/10 07:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ZIMFPRNT.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[1998/08/31 21:44:56 | 000,016,384 | —- | M] (Ulead Systems, Inc.) – C:\WINDOWS\Photo Express 2 SE.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/04/15 10:10:31 | 021,460,432 | —- | M] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\Program Files\atapi.sys

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/19 23:49:01 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/19 23:49:01 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/19 23:49:01 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/19 14:07:45 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/19 14:11:21 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/19 14:11:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2010/08/19 20:36:08 | 096,307,688 | —- | M] (Symantec Corporation) – C:\Documents and Settings\User\Desktop\NAV-UPGRADE-ESD-17-6-0-32-EN.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-11 04:45:14

< >

< >

< Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. >

< >

< When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. >

< Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. >

< You may need two posts to fit them both in. >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A96964
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96D0C06F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D287FACF

< End of report >

OTL logfile created on: 15/05/2011 11:47:43 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 145.46 Gb Free Space | 48.80% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.70 Gb Free Space | 5.45% Space Free | Partition Type: NTFS

Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\dvd43\DVD43_Tray.exe ()
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\OPLIMIT\OCRAWR32.EXE (Caere Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\OPLIMIT\OAHOOK32.DLL (Caere Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SpeedDiskService) – C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (Symantec RemoteAssist) – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (MSSQL$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SONY_MEDIAMGR) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110430.001\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110513.037\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110513.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SYMSpeedDisk) – C:\WINDOWS\system32\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (SymDSMon) – C:\WINDOWS\system32\drivers\SymDSMon.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS (Symantec Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (MPE) – C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (USB28xxBGA) – C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (USB28xxOEM) – C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (ASPI32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
DRV - (ScFBPNT2) – C:\WINDOWS\system32\drivers\ScFBPNT2.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.abc.net.au/"

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2010/08/20 09:16:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A53A86BF-726B-433B-A4FB-64298888E5D0}: C:\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\ [2011/03/24 10:49:35 | 000,000,000 | —D | M]

[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions\[removed]
[2010/04/02 16:02:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\[removed]

O1 HOSTS File: ([2010/04/05 21:50:35 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (Caere Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\WINDOWS\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - xvidvfw.dll File not found
Drivers32: VIDC.YV12 - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/15 11:33:52 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/09 12:12:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/09 12:12:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\malcom
[2011/05/09 12:12:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/09 12:12:44 | 000,000,000 | —D | C] – C:\Program Files\malcom
[2011/05/08 10:02:50 | 007,082,224 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/07 15:56:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/07 15:37:46 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/05/07 15:37:40 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/05/07 15:37:40 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/05/03 12:37:55 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Norton Utilities
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/05/02 16:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/05/02 16:37:25 | 000,000,000 | —D | C] – C:\Program Files\CDBurnerXP
[2011/05/02 16:09:40 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Xilisoft
[2011/05/02 16:09:24 | 000,000,000 | —D | C] – C:\Program Files\Xilisoft
[2011/05/01 10:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\PK
[2011/04/30 18:02:00 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\jacks mess
[2011/04/23 15:20:15 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\FrostWire
[2011/04/23 15:20:04 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FrostWire
[2011/04/23 15:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\FrostWire
[2011/04/15 10:10:31 | 021,460,432 | —- | C] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/15 11:46:11 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/15 11:35:18 | 000,625,664 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/05/15 11:11:23 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/05/15 11:01:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/15 11:00:50 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/15 10:59:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/15 10:45:10 | 000,000,757 | —- | M] () – C:\WINDOWS\oplimit.ini
[2011/05/12 07:57:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2011/05/11 08:34:22 | 000,000,610 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2011/05/10 18:33:49 | 021,039,108 | —- | M] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/09 11:47:18 | 000,001,688 | —- | M] () – C:\Documents and Settings\User\Desktop\Cyberlink PowerDirector.lnk
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2011/05/04 19:50:26 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/02 16:09:40 | 000,000,830 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/05/02 11:00:55 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/05/02 10:16:59 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 6.0 Professional.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | M] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/15 11:35:13 | 000,625,664 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2011/05/10 20:40:30 | 021,039,108 | —- | C] () – C:\Documents and Settings\User\Desktop\police force ad.mpg
[2011/05/09 12:12:51 | 000,000,642 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/02 16:37:28 | 000,001,556 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\CDBurnerXP.lnk
[2011/05/02 16:37:25 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/05/02 16:09:39 | 000,000,830 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft Audio Maker 3.lnk
[2011/04/27 12:05:07 | 000,129,155 | —- | C] () – C:\Documents and Settings\User\Desktop\nicki sullivan electrol update.jpg
[2011/04/15 10:16:07 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/03/24 10:49:36 | 000,000,120 | —- | C] () – C:\WINDOWS\Xbejinodu.dat
[2011/03/24 10:49:36 | 000,000,000 | —- | C] () – C:\WINDOWS\Mjimujoxumu.bin
[2010/10/15 10:11:16 | 000,001,940 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/15 10:06:11 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/26 23:32:20 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/23 13:04:52 | 000,000,146 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2010/05/23 13:04:52 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2010/05/23 13:04:33 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2010/05/23 13:04:32 | 000,009,853 | —- | C] () – C:\WINDOWS\HL-2170W.INI
[2010/05/23 13:04:28 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/05/23 13:04:28 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2170W.DAT
[2010/05/23 13:03:37 | 000,000,318 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,303,104 | —- | C] () – C:\WINDOWS\emunist.exe
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/07/14 13:15:00 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,610 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:34:52 | 000,020,450 | —- | C] () – C:\WINDOWS\SICALIB2.DAT
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 19:19:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/02/04 10:50:07 | 000,000,323 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 23:50:47 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/19 23:49:51 | 000,331,480 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/19 20:22:52 | 000,115,200 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:08:54 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/19 14:05:27 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 22:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 22:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 22:00:00 | 000,480,114 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 22:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 22:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 22:00:00 | 000,086,296 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 22:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 22:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 22:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 22:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 22:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 22:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/02/09 13:46:30 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll

========== LOP Check ==========

[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/05/18 09:57:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/09/21 12:31:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2010/04/14 12:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2010/11/09 15:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/11 13:02:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/09/27 10:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Socusoft
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/05/11 09:41:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/02/23 16:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2010/07/05 20:25:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\4Media
[2010/06/06 14:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aura4You
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/04/06 18:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canon Easy-WebPrint EX
[2010/08/13 10:52:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CD-LabelPrint
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2010/07/28 16:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2011/05/02 16:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FrostWire
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2010/11/09 15:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\MyHeritage
[2010/07/22 18:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NCH Swift Sound
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2010/04/16 18:49:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Nvu
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/06/26 16:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2010/08/20 10:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tific
[2010/05/29 22:53:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Desktop Search
[2010/07/06 22:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Search
[2010/04/11 17:50:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\WinPatrol
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/14 22:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\atapi.sys
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/12 06:59:45 | 000,017,968 | —- | M] () – C:\avi_log.txt
[2009/01/19 14:03:10 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/05/11 09:04:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/28 15:33:52 | 000,015,698 | —- | M] () – C:\ComboFix.txt
[2009/01/19 14:07:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/11/19 12:19:55 | 000,077,730 | —- | M] () – C:\Fifa_World_Cup_will.jpg
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/04 08:00:35 | 000,002,575 | —- | M] () – C:\looklog.txt
[2010/05/01 18:22:02 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/02/14 16:12:02 | 001,389,056 | —- | M] (Creative Technology Ltd.) – C:\monfilt.sys
[2009/01/19 14:07:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 22:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 22:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/15 10:58:26 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/11/19 12:27:13 | 000,045,676 | —- | M] () – C:\ps2_007nightfire.jpg
[2010/04/08 09:22:20 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\rasacd.sys
[2010/07/02 14:44:44 | 000,009,685 | —- | M] () – C:\scramble.log
[2010/09/26 11:34:14 | 000,009,934 | —- | M] () – C:\Setup Log.txt
[2010/04/06 08:15:50 | 000,012,284 | —- | M] () – C:\TDSSKiller.2.2.8.1_06.04.2010_08.15.50_log.txt
[2010/06/06 14:20:27 | 000,000,976 | —- | M] () – C:\testFindSector.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/19 14:07:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/08/26 15:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2009/03/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDA1.DLL
[2005/08/26 15:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2009/03/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPA1.DLL
[2008/07/06 22:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/02/09 13:46:28 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 20:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/12/10 07:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ZIMFPRNT.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[1998/08/31 21:44:56 | 000,016,384 | —- | M] (Ulead Systems, Inc.) – C:\WINDOWS\Photo Express 2 SE.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/04/15 10:10:31 | 021,460,432 | —- | M] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) – C:\Program Files\atapi.sys

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/19 23:49:01 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/19 23:49:01 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/19 23:49:01 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/19 14:07:45 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/19 14:11:21 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/19 14:11:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/15 11:33:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2011/05/08 10:02:50 | 007,082,224 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-rules.exe
[2010/08/19 20:36:08 | 096,307,688 | —- | M] (Symantec Corporation) – C:\Documents and Settings\User\Desktop\NAV-UPGRADE-ESD-17-6-0-32-EN.exe
[2011/05/15 11:33:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-11 04:45:14

< >

< >

< Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. >

< >

< When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. >

< Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. >

< You may need two posts to fit them both in. >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A96964
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96D0C06F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D287FACF

< End of report >
Hi,

Please do the following:

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-18 08:44:43 —————————– 08:44:43.250 OS Version: Windows 5.1.2600 Service Pack 3 08:44:43.250 Number of processors: 4 586 0xF0B 08:44:43.250 ComputerName: OWNER-92DFBD76A UserName: User 08:44:46.968 Initialize success 08:44:51.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-6 08:44:51.109 Disk 0 Vendor: ST3320613AS SD22 Size: 305245MB BusType: 3 08:44:51.125 Disk 0 MBR read successfully 08:44:51.125 Disk 0 MBR scan 08:44:51.125 Disk 0 Windows XP default MBR code 08:44:51.125 Disk 0 scanning sectors +625121280 08:44:51.187 Disk 0 scanning C:\WINDOWS\system32\drivers 08:45:00.937 Service scanning 08:45:04.265 Disk 0 trace - called modules: 08:45:04.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll dvd43llh.sys atapi.sys pciide.sys 08:45:04.265 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a7eeab8] 08:45:04.265 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000073[0x8a84db58] 08:45:04.281 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-6[0x8a87f940] 08:45:04.281 \Driver\atapi[0x8a872560] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> dvd43llh.sys[0xba469b20] 08:45:04.296 Scan finished successfully 08:45:32.359 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\User\Desktop\MBR.dat" 08:45:32.359 The log file has been saved successfully to "C:\Documents and Settings\User\Desktop\aswMBR.txt"
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 11-05-17.03 - User 19/05/2011 8:01.6.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1312 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
.
((((((((((((((((((((((((( Files Created from 2011-04-18 to 2011-05-18 )))))))))))))))))))))))))))))))
.
.
2011-05-17 10:02 . 2011-05-17 10:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype Extras
2011-05-17 10:01 . 2011-05-17 10:01 ——– d—–w- c:\program files\Common Files\Skype
2011-05-09 02:12 . 2010-12-20 08:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-09 02:12 . 2010-12-20 08:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-09 02:12 . 2011-05-09 02:12 ——– d—–w- c:\program files\malcom
2011-05-07 05:56 . 2011-05-07 05:56 ——– d—–w- c:\program files\Common Files\Java
2011-05-07 05:37 . 2011-02-02 09:19 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-03 02:37 . 2011-05-03 03:23 ——– d—–w- c:\documents and settings\User\Application Data\Norton Utilities
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\documents and settings\User\Application Data\Canneverbe Limited
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\program files\CDBurnerXP
2011-05-02 06:37 . 2009-11-12 03:48 7168 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2011-05-02 06:09 . 2011-05-02 06:09 ——– d—–w- c:\program files\Xilisoft
2011-04-23 05:20 . 2011-05-02 06:42 ——– d—–w- c:\documents and settings\User\Application Data\FrostWire
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-15 00:10 . 2011-04-15 00:10 21460432 —-a-w- c:\program files\15.0.0.122RC5_NUesd_MUI.exe
2011-03-07 05:33 . 2009-01-19 04:05 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2008-04-14 12:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2008-04-14 12:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2008-04-14 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2008-04-14 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2008-04-14 12:00 385024 —-a-w- c:\windows\system32\html.iec
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-18_11.08.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-18 21:26 . 2011-05-18 21:26 16384 c:\windows\Temp\Perflib_Perfdata_250.dat
+ 2011-05-18 21:24 . 2011-05-18 21:24 16384 c:\windows\Temp\Perflib_Perfdata_134.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-23 827904]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-12 127036]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Photo Express Calendar Checker SE.lnk]
backup=c:\windows\pss\Photo Express Calendar Checker SE.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^PMB Media Check Tool.lnk]
backup=c:\windows\pss\PMB Media Check Tool.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-07-27 02:10 1983816 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40 767312 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-02 08:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
2004-01-14 01:10 409600 —-a-w- c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2008-04-10 03:36 29757440 —-a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 19:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 01:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PE2CKFNT SE]
1998-07-03 01:51 25088 ——w- c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-09 19:15 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-17 02:26 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1233:UDP"= 1233:UDP:Windows Media Format SDK (svchost.exe)
"1232:UDP"= 1232:UDP:Windows Media Format SDK (svchost.exe)
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1108000.005\symds.sys [24/09/2010 3:14 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1108000.005\symefa.sys [24/09/2010 3:14 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110430.001\BHDrvx86.sys [3/05/2011 8:32 AM 802936]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1108000.005\cchpx86.sys [24/09/2010 3:14 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1108000.005\ironx86.sys [24/09/2010 3:14 PM 116784]
R2 DiskDoctorService;Norton Disk Doctor Service;c:\program files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [15/04/2011 10:16 AM 1029480]
R2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe [24/09/2010 3:14 PM 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [16/05/2011 10:30 AM 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110514.001\IDSXpx86.sys [17/05/2011 8:04 PM 341944]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
S3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [15/04/2011 10:16 AM 128248]
S3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [15/04/2011 10:16 AM 108800]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S4 SpeedDiskService;Norton SpeedDisk Service;c:\program files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [15/04/2011 10:16 AM 1037672]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
.
2011-05-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]
.
2011-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
2011-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-19 08:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.8.0.5\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(4088)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\oplimit\oahook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\program files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
c:\windows\System32\DLA\DLASHX_W.DLL
c:\windows\system32\DLAAPI_W.DLL
c:\windows\System32\DLA\DLACResW.dll
c:\program files\Microsoft Office\Office10\msohev.dll
.
Completion time: 2011-05-19 08:10:04
ComboFix-quarantined-files.txt 2011-05-18 22:09
ComboFix2.txt 2011-05-18 11:11
ComboFix3.txt 2010-04-28 05:33
.
Pre-Run: 157,100,650,496 bytes free
Post-Run: 157,083,758,592 bytes free
.
- - End Of File - - 3937BE5C2146D172CF391303B75D952D
Hi That was the 6th run of ComboFix, have you ran it before for a previous infection or were you receiving help elsewhere, it would be helpful if I could see the previous logs, they will be located in c:\qoobox\combofix2.txt, c:\qoobox\combofix3.txt, c:\qoobox\combofix4.txt etc. also did you place a copy of atapi.sys in program files or do you know anything about it's presence there? c:\program files\atapi.sys Please advise your outstanding issues
I ran combofix twice for you as the computer froze up during first run through. I have ran combfix for a previous infection that nortons picked up but coulld not fix this was done with advice from your people, but that was quite some time ago.

I only have combofix.text 2 and 3 in qoobox.

Computer still shuts down on start up neend to be unplugged to start again but not as often as before. very slow to start up freezes often and shut down on some programs which seems random but particularily on DVD player and Nero.

ComboFix 11-05-17.01 - User 18/05/2011 21:01:36.5.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1263 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}
c:\documents and settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\chrome.manifest
c:\documents and settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\chrome\content\_cfg.js
c:\documents and settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\chrome\content\overlay.xul
c:\documents and settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\install.rdf
c:\documents and settings\User\System
c:\documents and settings\User\System\win_qs8.jqx
c:\documents and settings\User\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2011-04-18 to 2011-05-18 )))))))))))))))))))))))))))))))
.
.
2011-05-17 10:02 . 2011-05-17 10:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype Extras
2011-05-17 10:01 . 2011-05-17 10:01 ——– d—–w- c:\program files\Common Files\Skype
2011-05-09 02:12 . 2010-12-20 08:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-09 02:12 . 2010-12-20 08:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-09 02:12 . 2011-05-09 02:12 ——– d—–w- c:\program files\malcom
2011-05-07 05:56 . 2011-05-07 05:56 ——– d—–w- c:\program files\Common Files\Java
2011-05-07 05:37 . 2011-02-02 09:19 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-03 02:37 . 2011-05-03 03:23 ——– d—–w- c:\documents and settings\User\Application Data\Norton Utilities
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\documents and settings\User\Application Data\Canneverbe Limited
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\program files\CDBurnerXP
2011-05-02 06:37 . 2009-11-12 03:48 7168 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2011-05-02 06:09 . 2011-05-02 06:09 ——– d—–w- c:\program files\Xilisoft
2011-04-23 05:20 . 2011-05-02 06:42 ——– d—–w- c:\documents and settings\User\Application Data\FrostWire
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-15 00:10 . 2011-04-15 00:10 21460432 —-a-w- c:\program files\15.0.0.122RC5_NUesd_MUI.exe
2011-03-07 05:33 . 2009-01-19 04:05 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2008-04-14 12:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2008-04-14 12:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2008-04-14 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2008-04-14 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2008-04-14 12:00 385024 —-a-w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2008-04-14 12:00 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2008-04-14 12:00 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-16 09:35 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-23 827904]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-12 127036]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Photo Express Calendar Checker SE.lnk]
backup=c:\windows\pss\Photo Express Calendar Checker SE.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^PMB Media Check Tool.lnk]
backup=c:\windows\pss\PMB Media Check Tool.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-07-27 02:10 1983816 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40 767312 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-02 08:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
2004-01-14 01:10 409600 —-a-w- c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2008-04-10 03:36 29757440 —-a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 19:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 01:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PE2CKFNT SE]
1998-07-03 01:51 25088 ——w- c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-09 19:15 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-17 02:26 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1233:UDP"= 1233:UDP:Windows Media Format SDK (svchost.exe)
"1232:UDP"= 1232:UDP:Windows Media Format SDK (svchost.exe)
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1108000.005\symds.sys [24/09/2010 3:14 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1108000.005\symefa.sys [24/09/2010 3:14 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110430.001\BHDrvx86.sys [3/05/2011 8:32 AM 802936]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1108000.005\cchpx86.sys [24/09/2010 3:14 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1108000.005\ironx86.sys [24/09/2010 3:14 PM 116784]
R2 DiskDoctorService;Norton Disk Doctor Service;c:\program files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [15/04/2011 10:16 AM 1029480]
R2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe [24/09/2010 3:14 PM 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [16/05/2011 10:30 AM 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110514.001\IDSXpx86.sys [17/05/2011 8:04 PM 341944]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
S3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [15/04/2011 10:16 AM 128248]
S3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [15/04/2011 10:16 AM 108800]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S4 SpeedDiskService;Norton SpeedDisk Service;c:\program files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [15/04/2011 10:16 AM 1037672]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
.
2011-05-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]
.
2011-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
2011-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-18 21:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.8.0.5\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-05-18 21:11:28
ComboFix-quarantined-files.txt 2011-05-18 11:11
ComboFix2.txt 2010-04-28 05:33
.
Pre-Run: 156,867,092,480 bytes free
Post-Run: 157,095,124,992 bytes free
.
- - End Of File - - 941EFF6CF9B5F49BDFE001600595E766

ComboFix 10-04-26.05 - User 28/04/2010 15:29:23.4.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1368 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\User\System
c:\documents and settings\User\System\win_qs8.jqx

.
((((((((((((((((((((((((( Files Created from 2010-03-28 to 2010-04-28 )))))))))))))))))))))))))))))))
.

2010-04-28 03:40 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVENG.SYS
2010-04-28 03:40 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVEX15.SYS
2010-04-28 03:40 . 2009-12-09 09:00 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\CCERASER.DLL
2010-04-28 03:40 . 2009-10-25 18:32 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\EECTRL.SYS
2010-04-28 03:40 . 2009-10-25 18:32 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\ECMSVR32.DLL
2010-04-28 03:40 . 2009-10-25 18:32 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVENG32.DLL
2010-04-28 03:40 . 2009-10-25 18:32 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVEX32A.DLL
2010-04-28 03:40 . 2009-10-25 18:32 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\ERASER.SYS
2010-04-27 00:43 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSvix86.sys
2010-04-27 00:43 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSXpx86.sys
2010-04-27 00:43 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\Scxpx86.dll
2010-04-27 00:43 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSxpx86.dll
2010-04-27 00:43 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSviA64.sys
2010-04-21 22:02 . 2010-04-21 22:02 ——– d—–w- c:\program files\Common Files\Apple
2010-04-21 22:02 . 2010-04-21 22:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-16 21:45 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\Scxpx86.dll
2010-04-16 21:45 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSvix86.sys
2010-04-16 21:45 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSXpx86.sys
2010-04-16 21:45 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSxpx86.dll
2010-04-16 21:45 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSviA64.sys
2010-04-16 08:49 . 2010-04-16 08:49 ——– d—–w- c:\documents and settings\User\Application Data\Nvu
2010-04-14 02:38 . 2010-04-14 02:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-04-13 05:52 . 2010-04-13 05:51 286720 —-a-w- c:\windows\iun507.exe
2010-04-13 05:51 . 2010-04-13 05:58 ——– d—–w- c:\program files\PersonalWebKit3
2010-04-11 07:53 . 2010-04-27 07:48 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-11 07:52 . 2010-04-27 07:47 ——– d—–w- c:\program files\SpywareBlaster
2010-04-11 07:50 . 2010-04-11 07:50 ——– d—–w- c:\documents and settings\User\Application Data\WinPatrol
2010-04-11 07:50 . 2009-01-19 04:07 0 —-a-w- c:\documents and settings\User\Application Data\WinPatrol\Config.sys
2010-04-11 07:50 . 2009-01-19 04:07 0 —-a-w- c:\documents and settings\User\Application Data\WinPatrol\Autoexec.bat
2010-04-11 07:50 . 2010-04-11 07:50 ——– d—–w- c:\program files\BillP Studios
2010-04-11 03:30 . 2010-04-11 03:30 ——– d—–w- c:\program files\ESET
2010-04-10 23:24 . 2010-03-29 14:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-10 23:24 . 2010-03-29 14:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- C:\rasacd.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 -c–a-w- c:\windows\system32\dllcache\atapi.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 —-a-w- C:\atapi.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 ——w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-05 22:15 . 2010-04-05 22:15 ——– d—–w- C:\tds old log
2010-04-04 07:41 . 2010-04-04 07:41 ——– d—–w- c:\program files\Sophos
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-22 12:26 . 2009-03-10 06:23 ——– d—–w- c:\documents and settings\User\Application Data\AdobeUM
2010-04-21 22:02 . 2009-01-21 11:13 ——– d—–w- c:\program files\QuickTime
2010-04-14 22:44 . 2009-11-11 08:00 79488 —-a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-04-14 02:38 . 2009-01-19 10:15 86480 —-a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-13 10:37 . 2009-05-17 02:26 ——– d—–w- c:\program files\Google
2010-04-09 09:59 . 2009-02-02 11:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-09 09:58 . 2009-02-02 11:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-07 23:22 . 2008-04-14 12:00 8832 —-a-w- c:\windows\system32\drivers\rasacd.old
2010-04-06 04:27 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.old
2010-04-04 10:18 . 2009-05-21 03:39 ——– d—–w- c:\program files\Ultra QuickTime Converter
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\program files\EwisoftWeb
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\documents and settings\All Users\Application Data\EwisoftWeb
2010-03-10 06:15 . 2008-04-14 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-04-14 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2008-04-14 12:00 2146304 ——w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 00:01 2024448 ——w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-14 12:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-14 12:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]

c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Photo Express Calendar Checker SE.lnk - c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2009-3-8 55296]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\programs\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1233:UDP"= 1233:UDP:Windows Media Format SDK (svchost.exe)
"1232:UDP"= 1232:UDP:Windows Media Format SDK (svchost.exe)

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1008000.029\SymEFA.sys [28/01/2010 10:22 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1008000.029\BHDrvx86.sys [28/01/2010 10:22 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1008000.029\cchpx86.sys [28/01/2010 10:21 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSXpx86.sys [27/04/2010 10:43 AM 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [28/01/2010 10:21 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [23/04/2010 11:25 AM 102448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
.
Contents of the 'Scheduled Tasks' folder

2010-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]

2010-04-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]

2010-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]

2010-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-28 15:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
Completion time: 2010-04-28 15:33:52
ComboFix-quarantined-files.txt 2010-04-28 05:33

Pre-Run: 225,537,400,832 bytes free
Post-Run: 226,196,549,632 bytes free

- - End Of File - - 993BB5D286129FE57F6EAF844CA3EAE4
OK thanks, that was helpful, I have an idea of what you had in the past.
Your issues may not be malware related, but we have a few more scans we can run just to make certain.

Please do the following:


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
2011/05/19 11:45:42.0953 1308 TDSS rootkit removing tool 2.5.1.0 May 13 2011 13:20:29 2011/05/19 11:45:44.0031 1308 ================================================================================ 2011/05/19 11:45:44.0031 1308 SystemInfo: 2011/05/19 11:45:44.0031 1308 2011/05/19 11:45:44.0031 1308 OS Version: 5.1.2600 ServicePack: 3.0 2011/05/19 11:45:44.0031 1308 Product type: Workstation 2011/05/19 11:45:44.0031 1308 ComputerName: OWNER-92DFBD76A 2011/05/19 11:45:44.0031 1308 UserName: User 2011/05/19 11:45:44.0031 1308 Windows directory: C:\WINDOWS 2011/05/19 11:45:44.0031 1308 System windows directory: C:\WINDOWS 2011/05/19 11:45:44.0031 1308 Processor architecture: Intel x86 2011/05/19 11:45:44.0031 1308 Number of processors: 4 2011/05/19 11:45:44.0031 1308 Page size: 0x1000 2011/05/19 11:45:44.0031 1308 Boot type: Normal boot 2011/05/19 11:45:44.0031 1308 ================================================================================ 2011/05/19 11:45:45.0171 1308 Initialize success 2011/05/19 11:45:58.0890 2076 ================================================================================ 2011/05/19 11:45:58.0890 2076 Scan started 2011/05/19 11:45:58.0890 2076 Mode: Manual; 2011/05/19 11:45:58.0890 2076 ================================================================================ 2011/05/19 11:45:59.0828 2076 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/05/19 11:46:00.0125 2076 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/05/19 11:46:01.0078 2076 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/05/19 11:46:01.0343 2076 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys 2011/05/19 11:46:03.0046 2076 ASPI (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\System32\DRIVERS\ASPI32.sys 2011/05/19 11:46:03.0250 2076 ASPI32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\ASPI32.sys 2011/05/19 11:46:03.0421 2076 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/05/19 11:46:03.0671 2076 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys 2011/05/19 11:46:04.0015 2076 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/05/19 11:46:04.0203 2076 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/05/19 11:46:04.0375 2076 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/05/19 11:46:04.0828 2076 BHDrvx86 (925a191c8c06124426c63ceb2ea93085) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110518.001\BHDrvx86.sys 2011/05/19 11:46:05.0109 2076 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/05/19 11:46:05.0390 2076 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/05/19 11:46:05.0875 2076 ccHP (e941e709847fa00e0dd6d58d2b8fb5e1) C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys 2011/05/19 11:46:06.0734 2076 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/05/19 11:46:06.0968 2076 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/05/19 11:46:07.0218 2076 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/05/19 11:46:08.0296 2076 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/05/19 11:46:08.0500 2076 DLABOIOM (a14524d3f130a57163e0b3e057fc85d5) C:\WINDOWS\system32\DLA\DLABOIOM.SYS 2011/05/19 11:46:08.0687 2076 DLACDBHM (7581407a6a3c56860ae31e6e423fe824) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 2011/05/19 11:46:08.0843 2076 DLADResN (7c4cdf8a684b63d7482e0bf7440dc3b5) C:\WINDOWS\system32\DLA\DLADResN.SYS 2011/05/19 11:46:09.0031 2076 DLAIFS_M (97bca2aac06a9fea56615b4b15bdb9b8) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 2011/05/19 11:46:09.0203 2076 DLAOPIOM (be8d558cf749424f0de612813f7c6725) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 2011/05/19 11:46:09.0375 2076 DLAPoolM (7e5277cb45dc5e2a86af8ce093c7ef31) C:\WINDOWS\system32\DLA\DLAPoolM.SYS 2011/05/19 11:46:09.0546 2076 DLARTL_N (693dfd92d41a3d270053cd97834e4960) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS 2011/05/19 11:46:09.0734 2076 DLAUDFAM (d886b6d02b51e5bd61b8a571a16d5ca2) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 2011/05/19 11:46:09.0937 2076 DLAUDF_M (2c0ecf7a9d5162d87c64e2ae868b5039) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 2011/05/19 11:46:10.0312 2076 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/05/19 11:46:10.0718 2076 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/05/19 11:46:10.0921 2076 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/05/19 11:46:11.0109 2076 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/05/19 11:46:11.0453 2076 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/05/19 11:46:11.0640 2076 DRVMCDB (73623d89faef4d1aa600edee8b490bc5) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 2011/05/19 11:46:11.0843 2076 DRVNDDM (2aeee1600d0f14ba535f90a1f4411b54) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 2011/05/19 11:46:12.0046 2076 dvd43llh (1fc1eed3ea0c3a0ecf8a95b97e1b4831) C:\WINDOWS\system32\DRIVERS\dvd43llh.sys 2011/05/19 11:46:12.0234 2076 eeCtrl (5461f01b7def17dc90d90b029f874c3b) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/05/19 11:46:12.0390 2076 EraserUtilRebootDrv (17fcc372d03ba39f3aee85198c0ec594) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/05/19 11:46:12.0640 2076 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/05/19 11:46:12.0906 2076 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 2011/05/19 11:46:13.0109 2076 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/05/19 11:46:13.0312 2076 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/05/19 11:46:13.0531 2076 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2011/05/19 11:46:13.0734 2076 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/05/19 11:46:13.0937 2076 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/05/19 11:46:14.0140 2076 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/05/19 11:46:14.0359 2076 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/05/19 11:46:14.0593 2076 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/05/19 11:46:15.0000 2076 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/05/19 11:46:15.0562 2076 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/05/19 11:46:17.0359 2076 ialm (cd32607f1cc8ac67224334ae123f7b98) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 2011/05/19 11:46:19.0187 2076 IDSxpx86 (50fa4c70534cf3b5c17ec83debe07afd) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110518.001\IDSxpx86.sys 2011/05/19 11:46:19.0437 2076 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/05/19 11:46:20.0031 2076 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/05/19 11:46:20.0250 2076 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2011/05/19 11:46:20.0500 2076 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/05/19 11:46:20.0796 2076 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/05/19 11:46:21.0015 2076 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/05/19 11:46:21.0250 2076 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/05/19 11:46:21.0500 2076 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/05/19 11:46:21.0718 2076 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/05/19 11:46:21.0906 2076 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/05/19 11:46:22.0078 2076 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/05/19 11:46:22.0296 2076 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/05/19 11:46:22.0531 2076 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/05/19 11:46:22.0796 2076 L1e (303627228dd739d98289679901a38c8f) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys 2011/05/19 11:46:23.0328 2076 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/05/19 11:46:23.0546 2076 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/05/19 11:46:24.0125 2076 monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\monfilt.sys 2011/05/19 11:46:24.0750 2076 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/05/19 11:46:24.0953 2076 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/05/19 11:46:25.0125 2076 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/05/19 11:46:25.0328 2076 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys 2011/05/19 11:46:25.0703 2076 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/05/19 11:46:26.0156 2076 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/05/19 11:46:26.0562 2076 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/05/19 11:46:26.0765 2076 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/05/19 11:46:26.0937 2076 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/05/19 11:46:27.0109 2076 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/05/19 11:46:27.0296 2076 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/05/19 11:46:27.0484 2076 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/05/19 11:46:27.0656 2076 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys 2011/05/19 11:46:27.0875 2076 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/05/19 11:46:28.0093 2076 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/05/19 11:46:28.0343 2076 NAVENG (920d9701bba90dbb7ccfd3536ea4d6f9) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110518.021\NAVENG.SYS 2011/05/19 11:46:28.0796 2076 NAVEX15 (31b1a9b53c3319b97f7874347cd992d2) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110518.021\NAVEX15.SYS 2011/05/19 11:46:29.0062 2076 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/05/19 11:46:29.0343 2076 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/05/19 11:46:29.0546 2076 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/05/19 11:46:29.0781 2076 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/05/19 11:46:30.0000 2076 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/05/19 11:46:30.0234 2076 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/05/19 11:46:30.0500 2076 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/05/19 11:46:30.0750 2076 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/05/19 11:46:30.0984 2076 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/05/19 11:46:31.0343 2076 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/05/19 11:46:31.0734 2076 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/05/19 11:46:31.0937 2076 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/05/19 11:46:32.0140 2076 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/05/19 11:46:32.0343 2076 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/05/19 11:46:32.0546 2076 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/05/19 11:46:32.0796 2076 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/05/19 11:46:33.0015 2076 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/05/19 11:46:33.0406 2076 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/05/19 11:46:33.0640 2076 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/05/19 11:46:34.0875 2076 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/05/19 11:46:35.0140 2076 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/05/19 11:46:35.0328 2076 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/05/19 11:46:35.0640 2076 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/05/19 11:46:36.0781 2076 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/05/19 11:46:36.0984 2076 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/05/19 11:46:37.0187 2076 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/05/19 11:46:37.0390 2076 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/05/19 11:46:37.0656 2076 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/05/19 11:46:37.0890 2076 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/05/19 11:46:38.0140 2076 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/05/19 11:46:38.0453 2076 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/05/19 11:46:38.0671 2076 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 2011/05/19 11:46:38.0906 2076 ScFBPNT2 (50b724c9d03111245df270bc3f49f04d) C:\WINDOWS\system32\drivers\ScFBPNT2.SYS 2011/05/19 11:46:39.0109 2076 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/05/19 11:46:39.0281 2076 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/05/19 11:46:39.0468 2076 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/05/19 11:46:39.0671 2076 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/05/19 11:46:40.0015 2076 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/05/19 11:46:40.0359 2076 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/05/19 11:46:40.0546 2076 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/05/19 11:46:40.0921 2076 SRTSP (ec5c3c6260f4019b03dfaa03ec8cbf6a) C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS 2011/05/19 11:46:41.0171 2076 SRTSPX (55d5c37ed41231e3ac2063d16df50840) C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS 2011/05/19 11:46:41.0437 2076 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/05/19 11:46:41.0718 2076 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\WINDOWS\system32\drivers\StarOpen.sys 2011/05/19 11:46:41.0921 2076 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/05/19 11:46:42.0093 2076 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/05/19 11:46:42.0281 2076 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/05/19 11:46:42.0875 2076 SymDS (56890bf9d9204b93042089d4b45ae671) C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS 2011/05/19 11:46:43.0171 2076 SymDSMon (4c155fa65cbf81513e4b9d088737e9cf) C:\WINDOWS\system32\drivers\SymDSMon.sys 2011/05/19 11:46:43.0437 2076 SymEFA (1c91df5188150510a6f0cf78f7d94b69) C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS 2011/05/19 11:46:43.0687 2076 SymEvent (961b48b86f94d4cc8ceb483f8aa89374) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2011/05/19 11:46:44.0234 2076 SymIRON (dc80fbf0a348e54853ef82eed4e11e35) C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS 2011/05/19 11:46:44.0609 2076 SYMSpeedDisk (e9983667331d463f1e5b34f9170a9ae0) C:\WINDOWS\system32\drivers\SymSpeedDisk.sys 2011/05/19 11:46:44.0890 2076 SYMTDI (41aad61f87ca8e3b5d0f7fe7fba0797d) C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS 2011/05/19 11:46:45.0468 2076 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/05/19 11:46:45.0765 2076 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/05/19 11:46:46.0015 2076 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/05/19 11:46:46.0234 2076 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/05/19 11:46:46.0437 2076 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/05/19 11:46:46.0812 2076 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/05/19 11:46:47.0312 2076 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/05/19 11:46:47.0734 2076 USB28xxBGA (f0e0bd77c255c95d317cd69c2e8efb92) C:\WINDOWS\system32\DRIVERS\emBDA.sys 2011/05/19 11:46:48.0031 2076 USB28xxOEM (925e82ffe06a37799e5cb486528ed835) C:\WINDOWS\system32\DRIVERS\emOEM.sys 2011/05/19 11:46:48.0234 2076 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/05/19 11:46:48.0453 2076 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/05/19 11:46:48.0625 2076 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/05/19 11:46:48.0812 2076 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/05/19 11:46:49.0000 2076 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/05/19 11:46:49.0187 2076 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/05/19 11:46:49.0359 2076 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/05/19 11:46:49.0531 2076 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/05/19 11:46:49.0750 2076 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 2011/05/19 11:46:49.0953 2076 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/05/19 11:46:50.0187 2076 VIAHdAudAddService (6b2c9ee4c16616e9398bbd0bc80ceb22) C:\WINDOWS\system32\drivers\viahduaa.sys 2011/05/19 11:46:50.0609 2076 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/05/19 11:46:50.0859 2076 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/05/19 11:46:51.0234 2076 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/05/19 11:46:51.0468 2076 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/05/19 11:46:51.0671 2076 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/05/19 11:46:51.0875 2076 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/05/19 11:46:52.0093 2076 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/05/19 11:46:52.0312 2076 ================================================================================ 2011/05/19 11:46:52.0312 2076 Scan finished 2011/05/19 11:46:52.0312 2076 ================================================================================ Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6612 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 19/05/2011 12:02:44 PM mbam-log-2011-05-19 (12-02-44).txt Scan type: Quick scan Objects scanned: 155941 Time elapsed: 12 minute(s), 53 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) C:\Downloads\Setup.exe a variant of Win32/Kryptik.LEK trojan C:\Program Files\downloads\cdbxp_setup_4.3.8.2523.exe Win32/OpenCandy application C:\Program Files\downloads\frostwire-4.21.5.windows.exe Win32/OpenCandy application C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP317\A0111402.dll a variant of Win32/Kryptik.KNA trojan F:\programs\Nero-8.1.1.4_eng_trial.exe Win32/Toolbar.AskSBar application
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=118569

KillAll::

Collect::
C:\Downloads\Setup.exe 

File::
C:\Program Files\downloads\cdbxp_setup_4.3.8.2523.exe
C:\Program Files\downloads\frostwire-4.21.5.windows.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please advise how the computer is running now and if there are any outstanding issues.
Hi,
Ran combofix as directed.rebooted
recieved message need to verify files via internet -
recieved message webserver appears to be temperarily inaccessible combofix created submission form located at c:\cf-submit.htm. Please use to manually upload later?


ComboFix 11-05-18.04 - User 20/05/2011 8:47.7.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1392 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\cfscript.txt
AV: Norton AntiVirus *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
FILE ::
"c:\program files\downloads\cdbxp_setup_4.3.8.2523.exe"
"c:\program files\downloads\frostwire-4.21.5.windows.exe"
.
file zipped: c:\downloads\Setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-04-19 to 2011-05-19 )))))))))))))))))))))))))))))))
.
.
2011-05-19 02:53 . 2011-05-19 02:53 ——– d—–w- c:\program files\ESET
2011-05-19 01:42 . 2011-05-19 01:42 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\WinZip
2011-05-17 10:02 . 2011-05-17 10:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype Extras
2011-05-17 10:01 . 2011-05-17 10:01 ——– d—–w- c:\program files\Common Files\Skype
2011-05-09 02:12 . 2010-12-20 08:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-09 02:12 . 2010-12-20 08:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-09 02:12 . 2011-05-09 02:12 ——– d—–w- c:\program files\malcom
2011-05-07 05:56 . 2011-05-07 05:56 ——– d—–w- c:\program files\Common Files\Java
2011-05-07 05:37 . 2011-02-02 09:19 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-03 02:37 . 2011-05-03 03:23 ——– d—–w- c:\documents and settings\User\Application Data\Norton Utilities
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\documents and settings\User\Application Data\Canneverbe Limited
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2011-05-02 06:37 . 2011-05-02 06:37 ——– d—–w- c:\program files\CDBurnerXP
2011-05-02 06:37 . 2009-11-12 03:48 7168 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2011-05-02 06:09 . 2011-05-02 06:09 ——– d—–w- c:\program files\Xilisoft
2011-04-23 05:20 . 2011-05-02 06:42 ——– d—–w- c:\documents and settings\User\Application Data\FrostWire
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-15 00:10 . 2011-04-15 00:10 21460432 —-a-w- c:\program files\15.0.0.122RC5_NUesd_MUI.exe
2011-03-07 05:33 . 2009-01-19 04:05 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2008-04-14 12:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2008-04-14 12:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2008-04-14 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2008-04-14 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2008-04-14 12:00 385024 —-a-w- c:\windows\system32\html.iec
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-23 827904]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-12 127036]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-09 421888]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2011-4-15 610120]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Photo Express Calendar Checker SE.lnk]
backup=c:\windows\pss\Photo Express Calendar Checker SE.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^PMB Media Check Tool.lnk]
backup=c:\windows\pss\PMB Media Check Tool.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-07-27 02:10 1983816 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40 767312 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-02 08:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
2004-01-14 01:10 409600 —-a-w- c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2008-04-10 03:36 29757440 —-a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 19:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 01:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PE2CKFNT SE]
1998-07-03 01:51 25088 ——w- c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-09 19:15 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-17 02:26 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1233:UDP"= 1233:UDP:Windows Media Format SDK (svchost.exe)
"1232:UDP"= 1232:UDP:Windows Media Format SDK (svchost.exe)
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1108000.005\symds.sys [24/09/2010 3:14 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1108000.005\symefa.sys [24/09/2010 3:14 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110518.001\BHDrvx86.sys [19/05/2011 11:32 AM 802936]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1108000.005\cchpx86.sys [24/09/2010 3:14 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1108000.005\ironx86.sys [24/09/2010 3:14 PM 116784]
R2 DiskDoctorService;Norton Disk Doctor Service;c:\program files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [15/04/2011 10:16 AM 1029480]
R2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe [24/09/2010 3:14 PM 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [16/05/2011 10:30 AM 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110518.001\IDSXpx86.sys [19/05/2011 11:32 AM 341944]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
S3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [15/04/2011 10:16 AM 128248]
S3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [15/04/2011 10:16 AM 108800]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S4 SpeedDiskService;Norton SpeedDisk Service;c:\program files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [15/04/2011 10:16 AM 1037672]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
.
2011-05-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]
.
2011-05-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
2011-05-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-20 09:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.8.0.5\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3936)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\oplimit\oahook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\SearchProtocolHost.exe
c:\program files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe
c:\windows\system32\igfxsrvc.exe
c:\oplimit\ocrawr32.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Completion time: 2011-05-20 09:22:51 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-19 23:22
ComboFix2.txt 2011-05-18 22:10
ComboFix3.txt 2011-05-18 11:11
ComboFix4.txt 2010-04-28 05:33
.
Pre-Run: 157,476,868,096 bytes free
Post-Run: 157,423,452,160 bytes free
.
- - End Of File - - 225C0510AAC59A883E93D926DD4BB24C
Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/index.php?showtopic=118569&view=findpost&p=731568

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes Date and Time stamp )
Select this file and click Open
In the Largest box please put
File Requested By CatByte
Failed Collect::

Finally click SendFile

Please return here and let me know when that file has been uploaded.



How is the computer running now? Are there any outstanding issues?
hi

the "submit" file shouldn't be that large


Click Start>Run and copy/paste the following bolded text into the Run box and click OK:

C:\Qoobox\ComboFix-quarantined-files.txt

A report should pop open for you. Please post the contents in your next reply.
2011-05-19 22:46:46 . 2011-05-19 22:47:00 13,848,382 —-a-w- C:\Qoobox\Quarantine\[4]-Submit_2011-05-20_08.46.39.zip 2011-05-18 11:06:41 . 2011-05-19 22:58:17 5,999 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2011-05-18 10:58:03 . 2011-05-19 22:46:39 276 —-a-w- C:\Qoobox\Quarantine\catchme.log 2011-03-24 00:49:35 . 2011-03-24 00:49:35 5,954 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\chrome\content\overlay.xul.vir 2011-03-24 00:49:35 . 2011-03-24 00:49:35 2,138 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\chrome\content\_cfg.js.vir 2011-03-24 00:49:35 . 2011-03-24 00:49:35 764 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\install.rdf.vir 2011-03-24 00:49:35 . 2011-03-24 00:49:35 122 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\{A53A86BF-726B-433B-A4FB-64298888E5D0}\chrome.manifest.vir 2010-06-26 06:25:38 . 2010-07-01 08:09:03 99 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\User\System\win_qs8.jqx.vir

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI