This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu/406

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I open Firefox 4, www.searchqu/406 is the home page and can't be changed.
IE 8 won't open. I re-installed which first uninstalled ED before installing it again, but it still won't open at all.

Here's otl.txt

OTL logfile created on: 5/19/2011 11:31:37 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Brian\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 111.03 Gb Free Space | 74.50% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 912.39 Gb Free Space | 97.95% Space Free | Partition Type: NTFS

Computer Name: BRIAN-PC | User Name: Brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Brian\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_user_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_system_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_comm_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe (Symantec Corporation)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\MemoKit Plus\MemoKitP2.exe (Software Benefits Inc.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe (Speedbit Ltd.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Webshots\3.1.5.7619\Webshots.scr (Webshots.com)
PRC - C:\Program Files\AGI\core\4.2.0.10754\AGCoreService.exe (AG Interactive)
PRC - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Samsung\Samsung ML-2510 Series\SPanel\SPanel.exe ()
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Brian\Desktop\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\asoehook.dll (Symantec Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (GoToAssist Express Customer) – C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (VideoAcceleratorService) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (AGCoreService) – C:\Program Files\AGI\core\4.2.0.10754\AGCoreService.exe (AG Interactive)
SRV - (N360) – C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Symantec RemoteAssist) – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110519.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110519.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20110518.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20110518.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (HECI) Intel® – C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (DgiVecp) – C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Webshots\3.1.5.7617\Firefox
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/18 17:09:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2011/02/01 15:36:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2011/01/27 10:40:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/05/19 08:46:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/18 17:06:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/18 17:05:56 | 000,000,000 | —D | M]

[2011/05/18 17:06:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Brian\Application Data\Mozilla\Extensions
[2011/05/03 13:54:40 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\28gelbns.default\extensions
[2011/05/02 13:28:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\28gelbns.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/03 13:54:37 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\28gelbns.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/03/23 05:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\28gelbns.default\searchplugins\SearchquWebSearch.xml
[2011/05/18 17:06:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/08 07:30:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/04/04 18:28:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2011/02/01 15:36:52 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPLGN
[2010/11/18 17:09:42 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2009/02/02 09:44:26 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/19 08:46:13 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2011/04/14 09:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2009/03/31 22:47:26 | 000,324,976 | —- | M] (Symantec Corporation) – C:\Program Files\Mozilla Firefox\components\coFFPlgn.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/03/30 17:13:54 | 000,098,304 | —- | M] (RealNetworks) – C:\Program Files\Mozilla Firefox\plugins\npraclient.dll
[2005/04/27 13:10:49 | 000,102,400 | —- | M] (RealNetworks) – C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
[2009/03/03 10:51:42 | 000,098,304 | —- | M] (Zylom) – C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/03/23 05:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2007/07/27 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\MemoKit Plus.lnk = C:\Program Files\MemoKit Plus\mkp.exe (Software Benefits Inc.)
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\MemoKit.lnk = C:\Program Files\MemoKit\mk.exe (Software Benefits Inc.)
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\Webshots Daily Features.lnk = C:\Program Files\Webshots Daily Features\Webshots Daily Features.exe ()
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\3.1.5.7619\Launcher.exe (Webshots.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O15 - HKCU\..Trusted Domains: localhost ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1204066816593 (WUWebControl Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1204066916531 (MUWebControl Class)
O16 - DPF: {6E704581-CCAE-46D2-9C64-20D724B3624E} http://radaol-prod-web-rr.streamops.aol.co…agi3.0.84.2.cab (UnagiAx Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\615\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\GoToAssist Express Customer: DllName - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/25 18:13:41 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/10/28 00:29:30 | 000,000,126 | —- | M] () - E:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{0bb0205f-e4aa-11dc-9aa7-001cc019431e}\Shell\AutoRun\command - "" = LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/19 11:18:55 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Brian\Desktop\OTL.exe
[2011/05/18 19:17:41 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\mbam-setup-1.50.1.1100.exe
[2011/05/18 18:46:10 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2011/05/18 15:52:31 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/05/17 08:13:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Start Menu\Programs\Citrix
[2011/05/04 12:11:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Carbonite
[2011/05/03 08:43:34 | 000,098,392 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/05/03 08:43:34 | 000,027,984 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\sbbd.exe
[2011/05/03 08:43:17 | 000,000,000 | —D | C] – C:\VIPRERESCUE
[2011/05/02 20:58:46 | 000,000,000 | R–D | C] – C:\Documents and Settings\Brian\My Documents\Favorites
[2011/04/28 17:47:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Application Data\searchquband
[2011/04/28 17:42:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Application Data\vlc
[2011/04/28 17:41:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Application Data\searchqutoolbar
[2011/04/28 17:39:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Local Settings\Application Data\Ilivid Player
[2011/04/28 17:37:23 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{20A57913-6F1B-4186-B9E9-027E73723021}
[2011/04/28 17:37:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iLivid
[2011/04/28 17:37:07 | 000,000,000 | —D | C] – C:\Program Files\iLivid
[2011/04/28 17:35:26 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/04/28 17:35:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Local Settings\Application Data\PackageAware
[2011/04/20 06:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/04/20 06:42:44 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/04/20 06:42:42 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/04/20 06:37:43 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2008/04/12 19:22:21 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/19 11:26:19 | 000,002,515 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2011/05/19 11:21:40 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1978930551-3468942544-422502521-1003.job
[2011/05/19 11:21:39 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1978930551-3468942544-422502521-1003.job
[2011/05/19 11:18:59 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brian\Desktop\OTL.exe
[2011/05/19 10:51:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/19 10:48:58 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{386A6991-B593-4D60-9B25-7364DEF665AA}.job
[2011/05/19 08:28:06 | 000,000,585 | —- | M] () – C:\WINDOWS\aclockzp2.dat
[2011/05/19 08:19:11 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/05/19 08:06:22 | 000,000,364 | —- | M] () – C:\WINDOWS\tasks\RegCure Startup.job
[2011/05/19 04:20:12 | 000,001,940 | —- | M] () – C:\Documents and Settings\Brian\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/19 03:36:01 | 000,000,372 | —- | M] () – C:\WINDOWS\tasks\RegCure.job
[2011/05/19 03:23:01 | 000,000,792 | —- | M] () – C:\Documents and Settings\Brian\Start Menu\Programs\Startup\Webshots Daily Features.lnk
[2011/05/19 03:20:43 | 000,000,716 | —- | M] () – C:\WINDOWS\aclockz6.dat
[2011/05/19 03:20:05 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/05/19 03:19:57 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/19 03:19:56 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/19 03:19:56 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/05/19 03:19:55 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/05/19 03:19:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/18 18:29:02 | 000,000,442 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration.job
[2011/05/18 17:06:03 | 000,000,742 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/18 17:06:03 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/18 17:01:39 | 000,002,205 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/18 17:00:00 | 000,000,390 | —- | M] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2011/05/18 16:09:54 | 000,000,496 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Brian.job
[2011/05/18 16:00:07 | 000,000,815 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/18 15:58:06 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/05/18 15:15:53 | 000,870,128 | —- | M] () – C:\Documents and Settings\Brian\Application Data\mcs.rma
[2011/05/18 15:15:53 | 000,000,004 | —- | M] () – C:\Documents and Settings\Brian\Application Data\23E802
[2011/05/18 08:14:00 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/05/17 23:49:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/17 12:21:54 | 000,000,792 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/05/17 08:13:41 | 000,001,184 | —- | M] () – C:\Documents and Settings\Brian\Desktop\GoToAssist Customer.lnk
[2011/05/04 12:12:00 | 000,001,873 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Carbonite InfoCenter.lnk
[2011/05/03 03:31:17 | 000,016,986 | —- | M] () – C:\Documents and Settings\Brian\Desktop\Restore Report 03-21-1970 08-29-40AM.html
[2011/05/03 00:12:28 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/05/02 23:38:56 | 000,000,172 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Rhapsody.url
[2011/05/02 09:03:21 | 000,000,777 | —- | M] () – C:\Documents and Settings\Brian\Start Menu\Programs\Startup\Webshots.lnk
[2011/04/28 17:53:18 | 000,011,264 | —- | M] () – C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/28 17:43:49 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iLivid Download Manager.lnk
[2011/04/20 06:49:34 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/04/20 06:43:56 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/18 19:17:41 | 085,041,152 | —- | C] () – C:\VIPRERescue8635.exe
[2011/05/18 17:06:03 | 000,000,742 | —- | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/18 17:06:03 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/05/18 17:06:03 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/18 15:57:16 | 000,001,940 | —- | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/18 15:52:09 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/04 12:12:00 | 000,001,873 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Carbonite InfoCenter.lnk
[2011/05/03 00:12:28 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/04/28 17:37:22 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iLivid Download Manager.lnk
[2011/04/20 06:43:56 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/13 13:13:45 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/27 09:26:36 | 000,000,585 | —- | C] () – C:\WINDOWS\aclockzp2.dat
[2010/12/08 11:59:48 | 000,037,336 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2010/09/16 13:06:25 | 000,114,243 | —- | C] () – C:\WINDOWS\System32\drivers\klin.dat
[2010/09/16 13:06:25 | 000,097,859 | —- | C] () – C:\WINDOWS\System32\drivers\klick.dat
[2010/03/29 09:33:56 | 000,870,128 | —- | C] () – C:\Documents and Settings\Brian\Application Data\mcs.rma
[2010/03/26 16:33:56 | 000,000,004 | —- | C] () – C:\Documents and Settings\Brian\Application Data\23E802
[2009/11/09 10:11:12 | 105,615,136 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009/11/09 10:11:12 | 004,394,016 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox2.dat
[2009/11/04 09:26:05 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/10/13 15:01:05 | 000,055,172 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/08/04 09:25:07 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/23 09:58:47 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4885.dll
[2009/06/04 13:26:09 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\RashProp.dll
[2009/06/04 13:26:08 | 000,132,096 | —- | C] () – C:\WINDOWS\System32\RashIcon.dll
[2008/11/25 17:22:41 | 000,339,968 | —- | C] () – C:\WINDOWS\System32\pythoncom25.dll
[2008/11/25 17:22:41 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\pywintypes25.dll
[2008/08/06 12:24:28 | 000,000,340 | —- | C] () – C:\Documents and Settings\Brian\Application Data\cookie.vp
[2008/04/12 19:25:48 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/03/10 10:20:54 | 000,015,779 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/03/06 08:45:01 | 000,000,716 | —- | C] () – C:\WINDOWS\aclockz6.dat
[2008/03/05 14:16:10 | 000,011,264 | —- | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/26 15:34:31 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/26 14:02:24 | 000,000,128 | —- | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\fusioncache.dat
[2008/02/26 13:48:23 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/02/25 18:44:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/02/25 18:22:34 | 000,204,800 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4833.dll
[2008/02/25 18:15:38 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/02/25 18:10:43 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/02/25 10:00:31 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/02/25 09:58:57 | 000,265,416 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/07/27 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2007/07/27 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2007/07/27 05:00:00 | 000,444,832 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2007/07/27 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2007/07/27 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2007/07/27 05:00:00 | 000,072,582 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2007/07/27 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2007/07/27 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2007/07/27 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2007/07/27 05:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2007/07/27 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2007/07/27 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2008/03/05 19:51:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/02/08 10:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\agi
[2009/06/19 08:18:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cached Installations
[2010/12/15 12:58:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2010/08/27 15:27:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Deadtime Stories
[2009/06/19 08:21:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2009/07/16 14:55:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2008/10/25 19:28:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2011/04/04 18:05:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/09/16 09:11:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
[2011/01/27 10:12:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2011/04/04 18:05:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PLAV
[2008/04/23 15:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Playtonium Games
[2010/04/29 07:30:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/11/18 17:13:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Speedbit
[2008/09/15 17:37:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/02/26 14:00:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tanagra
[2011/04/04 18:24:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/22 13:09:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2011/04/28 17:37:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{20A57913-6F1B-4186-B9E9-027E73723021}
[2010/04/21 08:39:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/16 09:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/25 10:21:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/03/05 19:37:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Acronis
[2011/02/08 10:26:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\agi
[2010/01/31 17:46:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\BloodTies
[2009/06/19 08:29:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\DriverCure
[2009/08/19 14:14:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\GameHousev1001
[2010/04/02 11:09:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\GlarySoft
[2009/06/19 08:22:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\ParetoLogic
[2010/12/10 09:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Registry Mechanic
[2011/04/28 17:47:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\searchquband
[2011/04/28 17:47:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\searchqutoolbar
[2009/08/10 10:32:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Slacker
[2011/01/10 16:43:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\W Photo Studio Viewer
[2008/02/26 14:44:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Webshots
[2010/07/21 20:28:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\WebshotsDailyFeatures.D47BD63EE77CC0AC7AE23BFA386A3F1EDA7C080D.1
[2011/05/19 03:20:05 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
[2011/05/19 03:19:56 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
[2011/05/18 18:29:02 | 000,000,442 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2011/05/18 17:00:00 | 000,000,390 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job
[2011/05/19 08:06:22 | 000,000,364 | —- | M] () – C:\WINDOWS\Tasks\RegCure Startup.job
[2011/05/19 03:36:01 | 000,000,372 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job
[2011/05/19 10:48:58 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{386A6991-B593-4D60-9B25-7364DEF665AA}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/02/25 18:13:41 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/02/25 18:47:55 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2008/02/25 18:13:41 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/06/14 19:11:20 | 000,000,105 | —- | M] () – C:\DownloadLog.txt
[2009/06/19 08:20:30 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2008/02/25 18:13:41 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/02/05 10:57:08 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup-1.50.1.1100.exe
[2009/08/07 15:49:18 | 003,942,048 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup.exe
[2008/02/25 18:13:41 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/07/27 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/29 09:01:25 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/19 03:19:31 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2008/02/25 18:28:03 | 000,000,206 | —- | M] () – C:\realtek.log
[2008/02/25 18:28:03 | 000,000,575 | —- | M] () – C:\RHDSetup.log
[2010/09/16 09:06:36 | 000,002,357 | —- | M] () – C:\rollback.ini
[2009/08/07 15:49:11 | 006,881,824 | —- | M] () – C:\SUPERAntiSpyware.exe
[2011/03/08 12:05:30 | 085,041,152 | —- | M] () – C:\VIPRERescue8635.exe

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/02/25 18:13:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/04/12 19:22:15 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/02/25 09:58:06 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/02/25 09:58:06 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/02/25 09:58:06 | 000,909,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/29 09:09:07 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/06/15 08:35:11 | 000,000,183 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\allmyfaves logo.url
[2008/02/25 18:48:14 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/29 12:56:50 | 000,000,178 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Music.url
[2010/03/03 09:43:53 | 000,001,951 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Real SuperPass Home.url
[2011/05/02 23:38:56 | 000,000,172 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Rhapsody.url
[2008/02/25 18:17:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/19 11:18:59 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brian\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-19 10:02:53

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >
Here's extras.txt:


OTL Extras logfile created on: 5/19/2011 11:31:37 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Brian\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 111.03 Gb Free Space | 74.50% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 912.39 Gb Free Space | 97.95% Space Free | Partition Type: NTFS

Computer Name: BRIAN-PC | User Name: Brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Slacker\Software Player\slacker.player.exe" = C:\Program Files\Slacker\Software Player\slacker.player.exe:*:Enabled:Slacker Software Player – (Slacker)
"C:\Program Files\Rhapsody\rhapsody.exe" = C:\Program Files\Rhapsody\rhapsody.exe:*:Enabled:RealNetworks Rhapsody – (Rhapsody International Inc.)
"C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe" = C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe:*:Enabled:DTX broker – (Visicom Media Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{10C69612-017B-45F5-B986-7D113D5A2EA3}" = MSN Toolbar
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}" = Adobe Media Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 24
"{2857dbef-0b50-361c-8690-7d505747009f}" = Webshots Desktop
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{353FE16B-30FE-469A-BF55-B978F4218003}" = iTunes
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}" = Acronis True Image Home
"{48963B63-7A10-49D6-8B08-61E6132453D0}" = ViewSonic Monitor Drivers
"{48FF6DE6-0619-4562-B4B1-21F161FE0DE0}" = Symantec Technical Support Advanced Chat Controls
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5FCCD531-1B38-4A94-924C-127F722F1033}" = Nero 8
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{777AD08E-B32A-4456-AFE1-094DBECEB268}" = Intel® Network Connections [removed]
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{84F1DE76-C48C-4281-87A0-CC9548D1E7F9}" = Rhapsody Player Engine
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9819EF4D-7A28-54B5-8A25-CE97793845A4}" = Webshots Daily Features
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3D44AD8-D3C9-45E4-B861-3B653C6EF620}" = Rhapsody MP3 Download Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c17590d2-ecb4-4b15-8820-f58798dcc118}" = Webshots Toolbar for IE
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{fba28920-8485-3586-980c-54c863eb45e6}" = Webshots Toolbar for Firefox
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"am-deadtimestories" = Deadtime Stories
"am-goldrushtreasurehunt" = Gold Rush - Treasure Hunt
"am-mysterypithelotteryticket" = Mystery P.I. - The Lottery Ticket
"am-plantsvszombiestm" = Plants vs. Zombies™
"am-sunsetstudiodeluxe" = Sunset Studio Deluxe
"am-superblackjack" = Super Blackjack
"ancientsecrets" = Ancient Secrets
"Belarc Advisor" = Belarc Advisor 8.1
"Carbonite Backup" = Carbonite
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Glary Utilities_is1" = Glary Utilities 2.21.0.863
"Gold Rush - Treasure Hunt" = Gold Rush - Treasure Hunt
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist Corporate
"GoToAssist Express Customer" = GoToAssist Customer 1.6.0.290
"HDMI" = Intel® Graphics Media Accelerator Driver
"HECI" = Intel® Management Engine Interface
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iLivid" = iLivid
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"MemoKit - Software Benefits Inc" = MemoKit - Software Benefits Inc
"MemoKit Plus - Software Benefits Inc" = MemoKit Plus - Software Benefits Inc
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Mystery P.I. - The Lottery Ticket" = Mystery P.I. - The Lottery Ticket
"Mystery P.I.™ - The Vegas Heist" = Mystery P.I.™ - The Vegas Heist
"N360" = Norton 360 Premier Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSS" = Norton Security Scan
"plantsvszombiestm" = Plants vs. Zombies™
"RealArcade" = RealArcade
"RealPlayer 12.0" = RealPlayer
"RegCure" = RegCure
"Rhapsody" = Rhapsody
"RoadRash" = RoadRash
"Samsung ML-2510 Series" = Samsung ML-2510 Series
"SCRABBLE" = SCRABBLE
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"Slacker SoftwarePlayer" = Slacker Software Player
"Web Games Player Plugin" = Web Games Player Plugin
"WebshotsDailyFeatures.D47BD63EE77CC0AC7AE23BFA386A3F1EDA7C080D.1" = Webshots Daily Features
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.5.0.457
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Puzzle Pirates" = Puzzle Pirates
"Vuze Launcher" = Vuze Launcher

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/18/2011 6:37:44 PM | Computer Name = BRIAN-PC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 5/18/2011 6:37:44 PM | Computer Name = BRIAN-PC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 5/18/2011 6:39:29 PM | Computer Name = BRIAN-PC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 5/18/2011 6:39:29 PM | Computer Name = BRIAN-PC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 5/18/2011 6:39:29 PM | Computer Name = BRIAN-PC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 5/18/2011 6:39:29 PM | Computer Name = BRIAN-PC | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 5/18/2011 7:21:47 PM | Computer Name = BRIAN-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x41002054.

Error - 5/18/2011 7:21:48 PM | Computer Name = BRIAN-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x41002054.

Error - 5/19/2011 1:30:08 AM | Computer Name = BRIAN-PC | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 2.0.1.4120, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/19/2011 1:30:10 AM | Computer Name = BRIAN-PC | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 2.0.1.4120, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 5/14/2011 4:44:55 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:44:57 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:44:59 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:45:01 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:45:03 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:45:05 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:55:16 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:55:19 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:55:21 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/14/2011 4:55:23 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.


< End of report >
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post










Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
    FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
    [2011/03/23 05:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\28gelbns.default\searchplugins\SearchquWebSearch.xml
    [2011/03/23 05:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll ()
    O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll ()
    O3 - HKLM\..\Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
    [2011/04/28 17:47:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Application Data\searchquband
    [2011/04/28 17:41:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Application Data\searchqutoolbar
    [2011/04/28 17:39:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Local Settings\Application Data\Ilivid Player
    [2011/04/28 17:37:23 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{20A57913-6F1B-4186-B9E9-027E73723021}
    [2011/04/28 17:37:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iLivid
    [2011/04/28 17:37:07 | 000,000,000 | —D | C] – C:\Program Files\iLivid
    [2011/04/28 17:35:26 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
    [2011/04/28 17:43:49 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iLivid Download Manager.lnk
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )







Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage Prefs.js: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" removed from keyword.URL C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\28gelbns.default\searchplugins\SearchquWebSearch.xml moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. File C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C17590D2-ECB4-4b15-8820-F58798DCC118} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C17590D2-ECB4-4b15-8820-F58798DCC118}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll deleted successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll deleted successfully. File C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}\ not found. C:\Documents and Settings\Brian\Application Data\searchquband folder moved successfully. C:\Documents and Settings\Brian\Application Data\searchqutoolbar\coupons folder moved successfully. C:\Documents and Settings\Brian\Application Data\searchqutoolbar folder moved successfully. C:\Documents and Settings\Brian\Local Settings\Application Data\Ilivid Player folder moved successfully. Folder C:\Documents and Settings\All Users\Application Data\{20A57913-6F1B-4186-B9E9-027E73723021}\ not found. Folder C:\Documents and Settings\All Users\Start Menu\Programs\iLivid\ not found. Folder C:\Program Files\iLivid\ not found. C:\Program Files\Windows iLivid Toolbar\ToolBar\components folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\searchbar folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\options folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\uwa folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2 folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2 folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\modules folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\lib folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\data\search folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\data folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar folder moved successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr\FirefoxExtension\content folder moved successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr\FirefoxExtension\components folder moved successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr\FirefoxExtension folder moved successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr folder moved successfully. C:\Program Files\Windows iLivid Toolbar folder moved successfully. File C:\Documents and Settings\All Users\Desktop\iLivid Download Manager.lnk not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Brian ->Temp folder emptied: 1568441 bytes ->Temporary Internet Files folder emptied: 5983390 bytes ->Java cache emptied: 71505622 bytes ->FireFox cache emptied: 28653652 bytes ->Google Chrome cache emptied: 412629197 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 75483 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56466 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 83067 bytes ->Flash cache emptied: 495 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 41108952 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2190207 bytes %systemroot%\System32 .tmp files removed: 4370961 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1144076 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 93620722 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 485527 bytes RecycleBin emptied: 82719 bytes Total Files Cleaned = 633.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 05202011_001059 Files\Folders moved on Reboot… C:\WINDOWS\temp\CitrixLogs\GoToAssist Express Customer\290\log188.tmp\GoToAssist Express Customer_00.LOG moved successfully. C:\WINDOWS\temp\CitrixLogs\GoToAssist Express Customer\290\log188.tmp\mgn_service-service_00.log moved successfully. C:\WINDOWS\temp\Perflib_Perfdata_1610.dat moved successfully. File\Folder C:\WINDOWS\temp\Perflib_Perfdata_5e8.dat not found! Registry entries deleted on Reboot…
ComboFix 11-05-19.01 - Brian 05/20/2011 6:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2021.1171 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 Premier Edition *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 Premier Edition *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Brian\g2ax_customer_downloadhelper_win32_x86.exe
c:\documents and settings\Brian\g2mdlhlpx.exe
c:\documents and settings\Brian\GoToAssistDownloadHelper.exe
c:\documents and settings\Brian\WINDOWS
E:\autorun.inf
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . Failed to delete
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . Failed to delete
.
—– BITS: Possible infected sites —–
.
hxxp://buy-download.norton.com
.
((((((((((((((((((((((((( Files Created from 2011-04-20 to 2011-05-20 )))))))))))))))))))))))))))))))
.
.
2011-05-20 07:10 . 2011-05-20 07:10 ——– d—–w- C:\_OTL
2011-05-19 19:45 . 2011-05-19 19:45 53248 —-a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\msihook.dll
2011-05-19 19:45 . 2011-05-19 19:45 126976 —-a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\knlwrap.exe
2011-05-19 19:45 . 2011-05-19 19:45 114688 —-a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\scpthdlr.dll
2011-05-19 19:43 . 2011-05-19 19:43 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2011-05-19 19:43 . 2011-05-19 19:43 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2011-05-19 19:43 . 2011-05-19 19:43 ——– d—–w- c:\program files\ScanSoft
2011-05-19 19:40 . 2011-05-19 19:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Brother
2011-05-19 02:17 . 2011-03-08 19:05 85041152 —-a-w- C:\VIPRERescue8635.exe
2011-05-19 02:17 . 2011-02-05 17:57 7734208 —-a-w- C:\mbam-setup-1.50.1.1100.exe
2011-05-18 22:52 . 2011-05-18 22:55 ——– dc-h–w- c:\windows\ie8
2011-05-03 15:43 . 2010-11-09 20:56 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-05-03 15:43 . 2010-11-09 20:56 27984 —-a-w- c:\windows\system32\sbbd.exe
2011-05-03 15:43 . 2011-05-19 05:06 ——– d—–w- C:\VIPRERESCUE
2011-04-29 00:42 . 2011-04-29 00:46 ——– d—–w- c:\documents and settings\Brian\Application Data\vlc
2011-04-29 00:35 . 2011-04-29 00:35 ——– d—–w- c:\documents and settings\Brian\Local Settings\Application Data\PackageAware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 23:20 . 2011-04-06 23:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20 . 2011-04-06 23:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-07 05:33 . 2008-02-26 01:11 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2007-07-27 12:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2007-07-27 12:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2007-07-27 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2007-07-27 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2007-07-27 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2007-07-27 12:00 385024 ——w- c:\windows\system32\html.iec
2008-04-13 02:22 . 2008-04-13 02:22 774144 —-a-w- c:\program files\RngInterstitial.dll
2011-04-14 16:26 . 2011-05-19 00:06 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2009-04-01 05:47 . 2009-02-10 02:33 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2010-08-06 17:57 . 2009-10-23 14:37 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2011-03-04 03:52 762000 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2011-03-04 03:52 762000 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2011-03-04 03:52 762000 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-26 68856]
"NortonUpdateAgent"="c:\documents and settings\All Users\Application Data\Norton\NUA.exe" [2011-04-05 2692024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2006-02-14 507904]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-06 30192]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-02-17 1169776]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-02-17 1945960]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-02-17 149024]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 16806912]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-11-08 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-11-08 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-11-08 137752]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2010-11-19 274608]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2011-03-04 948880]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
.
c:\documents and settings\Brian\Start Menu\Programs\Startup\
MemoKit Plus.lnk - c:\program files\MemoKit Plus\mkp.exe [2011-1-25 34680]
MemoKit.lnk - c:\program files\MemoKit\mk.exe [2010-8-20 28672]
Webshots Daily Features.lnk - c:\program files\Webshots Daily Features\Webshots Daily Features.exe [2011-3-18 142336]
Webshots.lnk - c:\program files\Webshots\3.1.5.7619\Launcher.exe [2011-3-9 157088]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-07-29 18:08 13672 —-a-w- c:\program files\Citrix\GoToAssist\615\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist Express Customer]
2011-05-17 15:13 147832 —-a-w- c:\program files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Slacker\\Software Player\\slacker.player.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0403000.005\symds.sys [2/1/2011 3:37 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0403000.005\symefa.sys [2/1/2011 3:37 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20110518.001\BHDrvx86.sys [5/18/2011 3:52 PM 802936]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0403000.005\cchpx86.sys [2/1/2011 3:37 PM 501888]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [5/3/2011 8:43 AM 98392]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0403000.005\ironx86.sys [2/1/2011 3:37 PM 116784]
R2 AGCoreService;AG Core Services;c:\program files\AGI\core\4.2.0.10754\AGCoreService.exe [3/9/2011 9:07 AM 20480]
R2 GoToAssist Express Customer;GoToAssist Express Customer;c:\program files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe [5/17/2011 8:13 AM 161144]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [7/31/2009 8:26 AM 88176]
R2 N360;Norton 360;c:\program files\Norton 360 Premier Edition\Engine\4.3.0.5\ccsvchst.exe [2/1/2011 3:37 PM 126392]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/14/2011 12:07 PM 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20110518.001\IDSXpx86.sys [5/18/2011 5:55 PM 341944]
S2 gupdate1c9db18f3f3da74;Google Update Service (gupdate1c9db18f3f3da74);c:\program files\Google\Update\GoogleUpdate.exe [5/22/2009 1:07 PM 133104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [3/5/2008 2:01 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/22/2009 1:07 PM 133104]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49 AM 227232]
S3 SM_sugo3_FUService;sugo3 Status Monitor Service;"c:\program files\Samsung\Samsung ML-2510 Series\SPanel\ssmsrvc /Service –> c:\program files\Samsung\Samsung ML-2510 Series\SPanel\ssmsrvc [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]
.
2011-05-20 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-04-02 20:03]
.
2011-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-22 20:07]
.
2011-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-22 20:07]
.
2009-06-23 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 19:56]
.
2011-05-19 c:\windows\Tasks\Norton Security Scan for Brian.job
- c:\progra~1\NORTON~2\NORTON~1\Engine\301~1.8\Nss.exe [2011-01-14 04:15]
.
2011-05-20 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]
.
2011-05-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-05-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1978930551-3468942544-422502521-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-05-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-05-19 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1978930551-3468942544-422502521-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-05-20 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
2011-05-20 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
2011-05-19 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
2011-05-19 c:\windows\Tasks\User_Feed_Synchronization-{386A6991-B593-4D60-9B25-7364DEF665AA}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
FF - ProfilePath - c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\28gelbns.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-DATAMNGR - c:\progra~1\WI371A~1\Datamngr\DATAMN~1.EXE
AddRemove-Searchqu 406 MediaBar - c:\program files\Windows iLivid Toolbar\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-20 06:56
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360 Premier Edition\Engine\4.3.0.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360 Premier Edition\Engine\4.3.0.5\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SM_sugo3_FUService]
"ImagePath"="\"c:\program files\Samsung\Samsung ML-2510 Series\SPanel\ssmsrvc /Service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(876)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Citrix\GoToAssist\615\G2AWinLogon.dll
c:\program files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll
.
- - - - - - - > 'explorer.exe'(2608)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\program files\NORTON 360 PREMIER EDITION\ENGINE\4.3.0.5\Microsoft.VC90.CRT\MSVCR90.dll
c:\program files\NORTON 360 PREMIER EDITION\ENGINE\4.3.0.5\Microsoft.VC90.CRT\MSVCP90.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\program files\Citrix\GoToAssist Express Customer\290\g2ax_comm_customer.exe
c:\program files\Citrix\GoToAssist Express Customer\290\g2ax_system_customer.exe
c:\program files\Citrix\GoToAssist Express Customer\290\g2ax_user_customer.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\windows\RTHDCPL.EXE
c:\program files\MemoKit Plus\memokitp2.exe
c:\progra~1\Webshots\315~2.761\webshots.scr
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-05-20 07:03:26 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-20 14:03
.
Pre-Run: 119,554,150,400 bytes free
Post-Run: 119,415,148,544 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 9E83BA7D65FEEE38577864457FEE68A0
Thank you! Now I can change the home page for Firefox and Internet Explorer will open up!! Is there anything else that I need to do to test anything?
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.




After running these scans please tell me if there are any remaining problems.
Malwarebytes scan: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6630 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/20/2011 9:49:15 PM mbam-log-2011-05-20 (21-49-15).txt Scan type: Full scan (C:\|) Objects scanned: 240855 Time elapsed: 1 hour(s), 5 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I have not experienced any further symptoms. Thanks!!! Here's the Eset log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6522 # api_version=3.0.2 # EOSSerial=51bf263d6fc9ed4ba822de63bdca7ed3 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-05-21 07:12:17 # local_time=2011-05-21 12:12:17 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=3589 16777173 100 86 8205272 69235219 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=96197 # found=1 # cleaned=1 # scan_time=5014 C:\Documents and Settings\Brian\My Documents\My Downloads\Nero\Nero-8.2.8.0_eng_update.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.









Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.








Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI