This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

TDSS ROOT KIT/BACKDOOR INFECTION

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I have been infected with a virus TDSS ROOT KIT/BACKDOOR INFECTION, and i would appreciate any help possible to remove this virus. I had started a topic about a month ago, but i have been traveling pretty much all of May and the topic was closed.

Here is the DDS file that i ran when i first started the topic. If you need me to run another one please let me know.

Thanks,
Rachel
—————————————————————————————————————————————————————————–
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:06:52.94 on Sun 04/03/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1013 [GMT -4:00]
.
AV: CA Anti-Virus *Disabled/Outdated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
SP: CA Anti-Spyware *Disabled/Outdated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Windows\system32\lxbccoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\system32\STacSV.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Rachel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [Aim6]
uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe"
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [Malwarebytes Anti-Malware Reboot] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] c:\program files\dell support center\gs_agent\custom\dsca.exe
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\rachel\appdata\roaming\micros~1\windows\startm~1\programs\startup\digsby.lnk - c:\program files\digsby\digsby.exe
StartupFolder: c:\users\rachel\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
uPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {ACF93F61-9F60-4C1E-A015-E3B3812BD58C} - hxxps://login.imagesilo.com/Install/DocViewCtl/PVDMDocView400.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 adwarealert;adwarealert;c:\windows\system32\drivers\adwarealert.sys [2008-5-1 22512]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2008-9-9 26352]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2008-9-9 21104]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2008-9-9 161008]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2008-5-8 144696]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-7-23 21504]
R2 lxbc_device;lxbc_device;c:\windows\system32\lxbccoms.exe -service –> c:\windows\system32\lxbccoms.exe -service [?]
R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2008-9-9 255312]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-2-29 111104]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2008-9-9 185680]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2008-5-8 130280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\opencase\opencase media agent\MediaAgent.exe [2008-8-29 835208]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-29 30192]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-2-29 73728]
.
=============== File Associations ===============
.
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-04-03 14:37:02 6792528 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{85b4897c-a972-4c96-9297-70c6fce711a0}\mpengine.dll
2011-03-24 12:46:47 ——– d—–w- c:\program files\Digitech Systems
2011-03-24 12:13:26 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-24 12:13:26 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-24 12:13:26 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-11 18:12:03 ——– d—–w- c:\program files\iPod
2011-03-11 18:12:02 ——– d—–w- c:\program files\iTunes
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-03-11 18:03:18 ——– d—–w- c:\program files\Bonjour
2011-03-09 02:54:05 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-03-09 02:54:04 322560 —-a-w- c:\windows\system32\sbe.dll
2011-03-09 02:54:04 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 02:54:04 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-03-09 02:54:01 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-03-09 02:54:01 2067968 —-a-w- c:\windows\system32\mstscax.dll
.
==================== Find3M ====================
.
2011-02-18 21:36:58 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-02 22:11:20 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-01-15 01:08:57 257703058 —-a-w- c:\windows\DUMP4fa5.tmp
2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD16 rev.04.0 -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8661E439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x866247d0]; MOV EAX, [0x8662484c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x81E61912] -> \Device\Harddisk0\DR0[0x85F812F0]
3 CLASSPNP[0x8819F8B3] -> ntkrnlpa!IofCallDriver[0x81E61912] -> [0x866ADB20]
\Driver\iaStor[0x86609E78] -> IRP_MJ_CREATE -> 0x8661E439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskWDC_WD1600BEVS-75RST0___________________04.01G04#4&20766cbe&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 18:07:56.68 ===============
Hi and Welcome!! :wavey: My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Having said that….Let's get going!! :thumbup:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
Hi Sisa722,

Please read carefully and follow these steps.
———-

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-

In your next reply please post the logs created by both TDSSKiller and OTL. :)
Hi Jeff,
I ran the TDSSKiller scan and here is the report.

2011/05/30 10:00:35.0677 5612 TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24
2011/05/30 10:00:36.0110 5612 ================================================================================
2011/05/30 10:00:36.0110 5612 SystemInfo:
2011/05/30 10:00:36.0110 5612
2011/05/30 10:00:36.0110 5612 OS Version: 6.0.6002 ServicePack: 2.0
2011/05/30 10:00:36.0110 5612 Product type: Workstation
2011/05/30 10:00:36.0111 5612 ComputerName: RACHEL-PC
2011/05/30 10:00:36.0111 5612 UserName: Rachel
2011/05/30 10:00:36.0111 5612 Windows directory: C:\Windows
2011/05/30 10:00:36.0111 5612 System windows directory: C:\Windows
2011/05/30 10:00:36.0111 5612 Processor architecture: Intel x86
2011/05/30 10:00:36.0111 5612 Number of processors: 2
2011/05/30 10:00:36.0111 5612 Page size: 0x1000
2011/05/30 10:00:36.0111 5612 Boot type: Normal boot
2011/05/30 10:00:36.0111 5612 ================================================================================
2011/05/30 10:00:36.0796 5612 Initialize success
2011/05/30 10:00:39.0961 5732 ================================================================================
2011/05/30 10:00:39.0962 5732 Scan started
2011/05/30 10:00:39.0962 5732 Mode: Manual;
2011/05/30 10:00:39.0962 5732 ================================================================================
2011/05/30 10:00:40.0647 5732 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/05/30 10:00:40.0741 5732 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2011/05/30 10:00:40.0842 5732 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2011/05/30 10:00:40.0964 5732 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2011/05/30 10:00:41.0031 5732 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2011/05/30 10:00:41.0172 5732 adwarealert (49121c330185b4d69418fe68540fd768) C:\Windows\system32\DRIVERS\adwarealert.sys
2011/05/30 10:00:41.0369 5732 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/05/30 10:00:41.0453 5732 agp440 (8b10ce1c1f9f1d47e4deb1a547a00cd4) C:\Windows\system32\drivers\agp440.sys
2011/05/30 10:00:41.0512 5732 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/05/30 10:00:41.0557 5732 aliide (dc67a153fdb8105b25d05334b5e1d8e2) C:\Windows\system32\drivers\aliide.sys
2011/05/30 10:00:41.0608 5732 amdagp (848f27e5b27c1c253f6cefdc1a5d8f21) C:\Windows\system32\drivers\amdagp.sys
2011/05/30 10:00:41.0649 5732 amdide (835c4c3355088298a5ebd818fa31430f) C:\Windows\system32\drivers\amdide.sys
2011/05/30 10:00:41.0699 5732 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2011/05/30 10:00:41.0754 5732 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
2011/05/30 10:00:41.0917 5732 ApfiltrService (350f19eb5fe4ec37a2414df56cde1aa8) C:\Windows\system32\DRIVERS\Apfiltr.sys
2011/05/30 10:00:42.0170 5732 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2011/05/30 10:00:42.0302 5732 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2011/05/30 10:00:42.0403 5732 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/30 10:00:42.0483 5732 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/05/30 10:00:42.0559 5732 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/05/30 10:00:42.0696 5732 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/30 10:00:42.0767 5732 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/05/30 10:00:42.0810 5732 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/05/30 10:00:42.0859 5732 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/05/30 10:00:42.0908 5732 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/05/30 10:00:42.0957 5732 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/05/30 10:00:42.0993 5732 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/05/30 10:00:43.0073 5732 BthEnum (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys
2011/05/30 10:00:43.0122 5732 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/05/30 10:00:43.0177 5732 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
2011/05/30 10:00:43.0272 5732 BTHPORT (5a3abaa2f8eece7aefb942773766e3db) C:\Windows\system32\Drivers\BTHport.sys
2011/05/30 10:00:43.0369 5732 BTHUSB (94e2941280e3756a5e0bcb467865c43a) C:\Windows\system32\Drivers\BTHUSB.sys
2011/05/30 10:00:43.0426 5732 btwaudio (4a28e7bd365377d0512b7ef8c7596d2c) C:\Windows\system32\drivers\btwaudio.sys
2011/05/30 10:00:43.0460 5732 btwavdt (5ffde57253d665067b0886612817eb11) C:\Windows\system32\drivers\btwavdt.sys
2011/05/30 10:00:43.0503 5732 btwrchid (ab07dc8b05c31a4f95fc73019be9db15) C:\Windows\system32\DRIVERS\btwrchid.sys
2011/05/30 10:00:43.0599 5732 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/30 10:00:43.0665 5732 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/30 10:00:43.0725 5732 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
2011/05/30 10:00:43.0801 5732 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/05/30 10:00:43.0892 5732 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/05/30 10:00:43.0950 5732 cmdide (e79cbb2195e965f6e3256e2c1b23fd1c) C:\Windows\system32\drivers\cmdide.sys
2011/05/30 10:00:44.0010 5732 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/05/30 10:00:44.0039 5732 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2011/05/30 10:00:44.0092 5732 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2011/05/30 10:00:44.0174 5732 datunidr (dfeabb7cfffadea4a912ab95bdc3177a) C:\Windows\system32\DRIVERS\datunidr.sys
2011/05/30 10:00:44.0259 5732 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/05/30 10:00:44.0386 5732 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/05/30 10:00:44.0475 5732 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/05/30 10:00:44.0591 5732 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/30 10:00:44.0682 5732 e1express (7505290504c8e2d172fa378cc0497bcc) C:\Windows\system32\DRIVERS\e1e6032.sys
2011/05/30 10:00:44.0728 5732 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/05/30 10:00:44.0803 5732 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/05/30 10:00:44.0868 5732 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2011/05/30 10:00:45.0028 5732 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/05/30 10:00:45.0083 5732 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/05/30 10:00:45.0122 5732 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/30 10:00:45.0176 5732 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/05/30 10:00:45.0227 5732 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/05/30 10:00:45.0263 5732 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/30 10:00:45.0313 5732 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/05/30 10:00:45.0369 5732 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/30 10:00:45.0408 5732 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2011/05/30 10:00:45.0453 5732 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2011/05/30 10:00:45.0595 5732 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/30 10:00:45.0653 5732 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/05/30 10:00:45.0694 5732 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/05/30 10:00:45.0761 5732 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/05/30 10:00:45.0827 5732 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2011/05/30 10:00:45.0919 5732 HSF_DPV (e9e589c9ab799f52e18f057635a2b362) C:\Windows\system32\DRIVERS\HSX_DPV.sys
2011/05/30 10:00:46.0015 5732 HSXHWAZL (7845d2385f4dc7dfb3ccaf0c2fa4948e) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
2011/05/30 10:00:46.0127 5732 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/05/30 10:00:46.0178 5732 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2011/05/30 10:00:46.0250 5732 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/30 10:00:46.0308 5732 iaStor (baabb0301949774a66b955c65319635a) C:\Windows\system32\drivers\iastor.sys
2011/05/30 10:00:46.0344 5732 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2011/05/30 10:00:46.0467 5732 igfx (f7ecd4b9e7fad4a01a0ed889d40e2494) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/05/30 10:00:46.0551 5732 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/05/30 10:00:46.0602 5732 IntcHdmiAddService (cace3be2499cf00827a641869297cea6) C:\Windows\system32\drivers\IntcHdmi.sys
2011/05/30 10:00:46.0661 5732 intelide (0084046c084d68e494f8cf36bcf08186) C:\Windows\system32\DRIVERS\intelide.sys
2011/05/30 10:00:46.0711 5732 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/30 10:00:46.0787 5732 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/30 10:00:46.0852 5732 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2011/05/30 10:00:46.0921 5732 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/05/30 10:00:47.0006 5732 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/05/30 10:00:47.0065 5732 isapnp (2f8ece2699e7e2070545e9b0960a8ed2) C:\Windows\system32\drivers\isapnp.sys
2011/05/30 10:00:47.0169 5732 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/30 10:00:47.0219 5732 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/05/30 10:00:47.0289 5732 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/05/30 10:00:47.0340 5732 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/30 10:00:47.0394 5732 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/05/30 10:00:47.0462 5732 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/30 10:00:47.0560 5732 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/30 10:00:47.0615 5732 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2011/05/30 10:00:47.0656 5732 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2011/05/30 10:00:47.0708 5732 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2011/05/30 10:00:47.0763 5732 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/05/30 10:00:47.0861 5732 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2011/05/30 10:00:47.0906 5732 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2011/05/30 10:00:47.0967 5732 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/05/30 10:00:48.0016 5732 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/30 10:00:48.0074 5732 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/30 10:00:48.0104 5732 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/30 10:00:48.0147 5732 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/05/30 10:00:48.0204 5732 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2011/05/30 10:00:48.0264 5732 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/30 10:00:48.0303 5732 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/05/30 10:00:48.0353 5732 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/05/30 10:00:48.0406 5732 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/30 10:00:48.0455 5732 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/30 10:00:48.0514 5732 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/30 10:00:48.0552 5732 msahci (d420bc42a637ac3cc4f411220549c0dc) C:\Windows\system32\drivers\msahci.sys
2011/05/30 10:00:48.0597 5732 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2011/05/30 10:00:48.0668 5732 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/05/30 10:00:48.0721 5732 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/05/30 10:00:48.0789 5732 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/30 10:00:48.0840 5732 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/30 10:00:48.0903 5732 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/05/30 10:00:48.0953 5732 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/05/30 10:00:49.0004 5732 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/30 10:00:49.0044 5732 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/05/30 10:00:49.0100 5732 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/05/30 10:00:49.0191 5732 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/30 10:00:49.0266 5732 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/05/30 10:00:49.0333 5732 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/30 10:00:49.0379 5732 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/30 10:00:49.0424 5732 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/30 10:00:49.0475 5732 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/05/30 10:00:49.0525 5732 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/30 10:00:49.0576 5732 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/30 10:00:49.0733 5732 NETw4v32 (dd194a025d1c0472f45f57de8d8388eb) C:\Windows\system32\DRIVERS\NETw4v32.sys
2011/05/30 10:00:49.0833 5732 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/05/30 10:00:49.0882 5732 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/05/30 10:00:49.0935 5732 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/30 10:00:50.0022 5732 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/05/30 10:00:50.0099 5732 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/05/30 10:00:50.0145 5732 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/05/30 10:00:50.0198 5732 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2011/05/30 10:00:50.0240 5732 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2011/05/30 10:00:50.0273 5732 nv_agp (055081fd5076401c1ee1bcab08d81911) C:\Windows\system32\drivers\nv_agp.sys
2011/05/30 10:00:50.0376 5732 OEM02Dev (9d20fa5d8875f6063aa5e1c44446f698) C:\Windows\system32\DRIVERS\OEM02Dev.sys
2011/05/30 10:00:50.0412 5732 OEM02Vfx (86326062a90494bdd79ce383511d7d69) C:\Windows\system32\DRIVERS\OEM02Vfx.sys
2011/05/30 10:00:50.0471 5732 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/05/30 10:00:50.0534 5732 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/05/30 10:00:50.0596 5732 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/05/30 10:00:50.0631 5732 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/05/30 10:00:50.0713 5732 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/05/30 10:00:50.0753 5732 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
2011/05/30 10:00:50.0791 5732 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/05/30 10:00:50.0864 5732 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/05/30 10:00:51.0028 5732 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/30 10:00:51.0069 5732 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2011/05/30 10:00:51.0160 5732 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/30 10:00:51.0235 5732 PTproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys
2011/05/30 10:00:51.0292 5732 PxHelp20 (feffcfdc528764a04c8ed63d5fa6e711) C:\Windows\system32\Drivers\PxHelp20.sys
2011/05/30 10:00:51.0381 5732 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2011/05/30 10:00:51.0448 5732 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/05/30 10:00:51.0505 5732 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/30 10:00:51.0602 5732 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/05/30 10:00:51.0705 5732 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/30 10:00:51.0759 5732 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/30 10:00:51.0810 5732 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/30 10:00:51.0867 5732 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/05/30 10:00:51.0923 5732 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/30 10:00:51.0979 5732 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/30 10:00:52.0050 5732 rdpdr (0245418224cfa77bf4b41c2fe0622258) C:\Windows\system32\drivers\rdpdr.sys
2011/05/30 10:00:52.0076 5732 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/30 10:00:52.0153 5732 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/05/30 10:00:52.0271 5732 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys
2011/05/30 10:00:52.0325 5732 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
2011/05/30 10:00:52.0371 5732 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
2011/05/30 10:00:52.0401 5732 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
2011/05/30 10:00:52.0481 5732 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/30 10:00:52.0548 5732 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/05/30 10:00:52.0644 5732 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
2011/05/30 10:00:52.0674 5732 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/05/30 10:00:52.0723 5732 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/05/30 10:00:52.0786 5732 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/05/30 10:00:52.0840 5732 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/05/30 10:00:52.0922 5732 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/05/30 10:00:52.0960 5732 sffp_mmc (96ded8b20c734ac41641ce275250e55d) C:\Windows\system32\drivers\sffp_mmc.sys
2011/05/30 10:00:53.0036 5732 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/05/30 10:00:53.0064 5732 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/05/30 10:00:53.0115 5732 sisagp (08072b2fb92477fc813271a84b3a8698) C:\Windows\system32\drivers\sisagp.sys
2011/05/30 10:00:53.0154 5732 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2011/05/30 10:00:53.0198 5732 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2011/05/30 10:00:53.0250 5732 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/05/30 10:00:53.0307 5732 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/05/30 10:00:53.0391 5732 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys
2011/05/30 10:00:53.0476 5732 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/30 10:00:53.0509 5732 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/30 10:00:53.0582 5732 STHDA (6a2a5e809c2c0178326d92b19ee4aad3) C:\Windows\system32\drivers\stwrt.sys
2011/05/30 10:00:53.0647 5732 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/30 10:00:53.0702 5732 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/05/30 10:00:53.0741 5732 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/05/30 10:00:53.0784 5732 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/05/30 10:00:53.0884 5732 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/05/30 10:00:53.0964 5732 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/30 10:00:54.0044 5732 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/30 10:00:54.0097 5732 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/05/30 10:00:54.0140 5732 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/05/30 10:00:54.0214 5732 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/30 10:00:54.0298 5732 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/30 10:00:54.0371 5732 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/30 10:00:54.0439 5732 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/05/30 10:00:54.0486 5732 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/30 10:00:54.0533 5732 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
2011/05/30 10:00:54.0583 5732 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/30 10:00:54.0642 5732 uliagpkx (6d72ef05921abdf59fc45c7ebfe7e8dd) C:\Windows\system32\drivers\uliagpkx.sys
2011/05/30 10:00:54.0684 5732 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2011/05/30 10:00:54.0735 5732 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/05/30 10:00:54.0787 5732 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/05/30 10:00:54.0836 5732 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/30 10:00:54.0886 5732 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\Windows\system32\Drivers\usbaapl.sys
2011/05/30 10:00:54.0972 5732 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/30 10:00:55.0015 5732 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/05/30 10:00:55.0085 5732 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/05/30 10:00:55.0150 5732 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/30 10:00:55.0205 5732 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/05/30 10:00:55.0252 5732 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/05/30 10:00:55.0295 5732 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/05/30 10:00:55.0349 5732 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/30 10:00:55.0435 5732 VET-FILT (e6287f6c77e71adfc6badb106cd30e7d) C:\Windows\system32\drivers\VET-FILT.sys
2011/05/30 10:00:55.0463 5732 VET-REC (cb98d6c1ade8a891cbbfd9beb1774f48) C:\Windows\system32\drivers\VET-REC.sys
2011/05/30 10:00:55.0530 5732 VETEBOOT (c079f80582c31728029f3efcdfeaf221) C:\Windows\system32\drivers\VETEBOOT.sys
2011/05/30 10:00:55.0586 5732 VETEFILE (31bab965e7af8295c22f641401d622b3) C:\Windows\system32\drivers\VETEFILE.sys
2011/05/30 10:00:55.0664 5732 VETFDDNT (05bdabe6664f48c54a6d3c538c8f2cc1) C:\Windows\system32\drivers\VETFDDNT.sys
2011/05/30 10:00:55.0707 5732 VETMONNT (f5897ff7eb733670f92e798ef5358b88) C:\Windows\system32\drivers\VETMONNT.sys
2011/05/30 10:00:55.0783 5732 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/30 10:00:55.0837 5732 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/05/30 10:00:55.0886 5732 viaagp (d5929a28bdff4367a12caf06af901971) C:\Windows\system32\drivers\viaagp.sys
2011/05/30 10:00:55.0942 5732 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2011/05/30 10:00:56.0001 5732 viaide (f3b4762eb85a2aff4999401f14c3262b) C:\Windows\system32\drivers\viaide.sys
2011/05/30 10:00:56.0097 5732 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/05/30 10:00:56.0151 5732 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/05/30 10:00:56.0233 5732 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/05/30 10:00:56.0299 5732 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2011/05/30 10:00:56.0367 5732 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/05/30 10:00:56.0418 5732 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/30 10:00:56.0434 5732 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/30 10:00:56.0485 5732 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2011/05/30 10:00:56.0550 5732 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/30 10:00:56.0660 5732 winachsf (4daca8f07537d4d7e3534bb99294aa26) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
2011/05/30 10:00:56.0793 5732 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/05/30 10:00:56.0886 5732 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/05/30 10:00:56.0946 5732 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/30 10:00:57.0018 5732 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/30 10:00:57.0074 5732 XAudio (5a7ff9a18ff6d7e0527fe3abf9204ef8) C:\Windows\system32\DRIVERS\xaudio.sys
2011/05/30 10:00:57.0130 5732 yukonwlh (a4822191c7cea271903c2a4fb6d9809d) C:\Windows\system32\DRIVERS\yk60x86.sys
2011/05/30 10:00:57.0183 5732 MBR (0x1B8) (04d4350ae5fb6fc2ad3e7c26b1323c68) \Device\Harddisk0\DR0
2011/05/30 10:00:57.0189 5732 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/05/30 10:00:57.0195 5732 ================================================================================
2011/05/30 10:00:57.0195 5732 Scan finished
2011/05/30 10:00:57.0195 5732 ================================================================================
2011/05/30 10:00:57.0209 1692 Detected object count: 1
2011/05/30 10:00:57.0209 1692 Actual detected object count: 1
2011/05/30 10:01:42.0534 1692 \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
2011/05/30 10:01:42.0535 1692 \Device\Harddisk0\DR0 - ok
2011/05/30 10:01:42.0606 1692 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure
2011/05/30 10:02:08.0217 3864 Deinitialize success


I also ran the OTL scan but it did not generate an EXTRAS.TXT, only the OTL.TXT:

OTL logfile created on: 5/30/2011 10:53:50 AM - Run 4
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Rachel\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.72 Gb Available Physical Memory | 36.33% Memory free
4.21 Gb Paging File | 2.85 Gb Available in Paging File | 67.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.49 Gb Total Space | 37.19 Gb Free Space | 27.25% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.51 Gb Free Space | 55.09% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: RACHEL-PC | User Name: Rachel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rachel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Program Files\Safari\Safari.exe (Apple Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Windows\System32\lxbccoms.exe ( )
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - c:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Users\Rachel\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (VETMSGNT) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
SRV - (PPCtlPriv) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (ITMRTSVC) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (OpenCASE Media Agent) – C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe (ExtendMedia Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (lxbc_device) – C:\Windows\System32\lxbccoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (VETEFILE) – C:\Windows\System32\drivers\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT) – C:\Windows\System32\drivers\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETMONNT) – C:\Windows\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (VET-FILT) – C:\Windows\System32\drivers\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\Windows\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\Windows\System32\drivers\vet-rec.sys (Computer Associates International, Inc.)
DRV - (adwarealert) – C:\Windows\system32\DRIVERS\adwarealert.sys ()
DRV - (IntcHdmiAddService) Intel® – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (NETw4v32) Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?wl=true
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/04/09 20:40:31 | 000,000,000 | —D | M]

[2009/04/18 10:45:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Rachel\AppData\Roaming\Mozilla\Extensions
[2009/04/18 10:45:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Rachel\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2008/05/08 09:46:35 | 000,238,211 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.139mm.com
O1 - Hosts: 8358 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware Reboot] File not found
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [pccguide.exe] File not found
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [DellAutomatedPCTuneUp] C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
O4 - Startup: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Digsby.lnk = C:\Program Files\Digsby\digsby.exe ()
O4 - Startup: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {ACF93F61-9F60-4C1E-A015-E3B3812BD58C} https://login.imagesilo.com/Install/DocView…MDocView400.cab (PVDMDocViewControls.PVDMDocView)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell - "" = AutoRun
O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell\AutoRun\command - "" = H:\LaunchU3.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 60 Days ==========

[2011/05/30 10:52:56 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\Rachel\Desktop\OTL.exe
[2011/05/30 10:00:05 | 001,431,344 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Rachel\Desktop\TDSSKiller.exe
[2011/04/06 20:59:16 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/04/03 18:02:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/04/03 18:02:19 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2011/04/03 17:35:28 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Users\Rachel\Desktop\erunt-setup.exe
[2011/04/03 15:20:04 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Users\Rachel\Desktop\setup-spybotsd162.exe
[2010/02/16 23:39:58 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxbcserv.dll
[2010/02/16 23:39:58 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxbcusb1.dll
[2010/02/16 23:39:58 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxbcinpa.dll
[2010/02/16 23:39:58 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbciesc.dll
[2010/02/16 23:39:58 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBChcp.dll
[2010/02/16 23:39:57 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxbchbn3.dll
[2010/02/16 23:39:57 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxbccomc.dll
[2010/02/16 23:39:57 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxbcpmui.dll
[2010/02/16 23:39:57 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbclmpm.dll
[2010/02/16 23:39:57 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxbccoms.exe
[2010/02/16 23:39:57 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxbccomm.dll
[2010/02/16 23:39:57 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxbcih.exe
[2010/02/16 23:39:57 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxbccfg.exe
[2010/02/16 23:39:57 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxbcprox.dll
[2010/02/16 23:39:57 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxbcpplc.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2011/05/30 10:52:56 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Rachel\Desktop\OTL.exe
[2011/05/30 10:50:40 | 000,002,305 | —- | M] () – C:\Users\Rachel\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/30 10:12:10 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/30 10:12:10 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/30 10:10:33 | 000,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{4F32B8DA-94A1-456C-B67C-C330643BF1EE}.job
[2011/05/30 10:03:54 | 000,005,648 | —- | M] () – C:\Users\Rachel\AppData\Local\d3d9caps.dat
[2011/05/30 10:03:36 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/30 10:03:36 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/30 10:03:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/30 10:02:38 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/05/30 09:59:53 | 001,301,452 | —- | M] () – C:\Users\Rachel\Desktop\tdsskiller.zip
[2011/05/25 07:10:16 | 001,431,344 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Rachel\Desktop\TDSSKiller.exe
[2011/05/24 19:14:10 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2011/04/06 20:54:56 | 264,420,498 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/04/03 18:14:18 | 000,002,037 | —- | M] () – C:\Users\Rachel\Desktop\Attach.zip
[2011/04/03 18:13:43 | 000,002,027 | —- | M] () – C:\Users\Rachel\Desktop\Attach.rar
[2011/04/03 18:06:49 | 000,625,664 | —- | M] () – C:\Users\Rachel\Desktop\dds.scr
[2011/04/03 18:02:39 | 000,000,915 | —- | M] () – C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/04/03 18:02:20 | 000,000,735 | —- | M] () – C:\Users\Rachel\Desktop\NTREGOPT.lnk
[2011/04/03 18:02:20 | 000,000,716 | —- | M] () – C:\Users\Rachel\Desktop\ERUNT.lnk
[2011/04/03 17:35:29 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\Rachel\Desktop\erunt-setup.exe
[2011/04/03 15:25:09 | 000,001,057 | —- | M] () – C:\Users\Rachel\Desktop\Spybot - Search & Destroy.lnk
[2011/04/03 15:22:27 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\Rachel\Desktop\setup-spybotsd162.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/30 09:59:49 | 001,301,452 | —- | C] () – C:\Users\Rachel\Desktop\tdsskiller.zip
[2011/04/03 18:14:18 | 000,002,037 | —- | C] () – C:\Users\Rachel\Desktop\Attach.zip
[2011/04/03 18:13:17 | 000,002,027 | —- | C] () – C:\Users\Rachel\Desktop\Attach.rar
[2011/04/03 18:06:42 | 000,625,664 | —- | C] () – C:\Users\Rachel\Desktop\dds.scr
[2011/04/03 18:02:39 | 000,000,915 | —- | C] () – C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/04/03 18:02:20 | 000,000,735 | —- | C] () – C:\Users\Rachel\Desktop\NTREGOPT.lnk
[2011/04/03 18:02:20 | 000,000,716 | —- | C] () – C:\Users\Rachel\Desktop\ERUNT.lnk
[2011/04/03 15:25:09 | 000,001,057 | —- | C] () – C:\Users\Rachel\Desktop\Spybot - Search & Destroy.lnk
[2010/06/21 20:47:13 | 000,005,103 | —- | C] () – C:\ProgramData\xqkcebzs.dik
[2010/02/16 23:42:33 | 000,000,150 | —- | C] () – C:\Windows\Lexstat.ini
[2010/02/16 23:39:58 | 000,413,696 | —- | C] () – C:\Windows\System32\lxbcutil.dll
[2010/02/16 23:39:58 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBCinst.dll
[2009/10/12 16:07:20 | 000,087,552 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2009/09/19 18:34:33 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/19 18:34:33 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/06 12:17:28 | 000,000,091 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2009/08/16 11:36:10 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/05/13 20:28:02 | 000,000,004 | —- | C] () – C:\Users\Rachel\AppData\Roaming\8AB4F8
[2009/05/13 20:28:01 | 000,870,128 | —- | C] () – C:\Users\Rachel\AppData\Roaming\mcs.rma
[2009/04/25 18:03:47 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/02/28 04:01:29 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/05/08 20:20:40 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/05/03 21:43:29 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2008/05/03 21:43:29 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2008/05/03 21:43:29 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2008/05/03 21:43:29 | 000,049,152 | —- | C] () – C:\Windows\VFind.exe
[2008/05/03 21:06:24 | 000,072,704 | -H– | C] () – C:\Users\Rachel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/01 21:23:48 | 000,022,512 | —- | C] () – C:\Windows\System32\drivers\adwarealert.sys
[2008/04/29 19:21:07 | 000,109,747 | —- | C] () – C:\ProgramData\BMcf449fba.xml
[2008/04/29 19:21:07 | 000,000,022 | —- | C] () – C:\ProgramData\pskt.ini
[2008/04/27 11:35:21 | 000,000,000 | —- | C] () – C:\Windows\cdplayer.ini
[2008/04/17 22:38:08 | 000,005,648 | —- | C] () – C:\Users\Rachel\AppData\Local\d3d9caps.dat
[2008/03/13 19:53:55 | 000,000,000 | -H– | C] () – C:\Users\Rachel\AppData\Roaming\wklnhst.dat
[2008/02/29 19:07:53 | 000,910,304 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2008/02/29 19:07:53 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2008/02/29 19:07:53 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1253.dll
[2008/02/29 19:07:51 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2008/02/29 19:07:50 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2008/02/29 11:27:39 | 000,000,076 | RHS- | C] () – C:\Windows\CT4CET.bin
[2008/02/29 11:14:53 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2007/07/25 18:40:02 | 000,999,424 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2007/02/22 19:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxbccoin.dll
[2006/11/10 09:26:12 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/07 15:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/03 19:25:56 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,419,160 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,604,502 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,170 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/17 01:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/10/25 15:51:14 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbcvs.dll
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2008/03/07 20:15:57 | 000,000,000 | -H-D | M] – C:\Users\Rachel\AppData\Roaming\acccore
[2011/04/03 14:21:05 | 000,000,000 | -H-D | M] – C:\Users\Rachel\AppData\Roaming\LimeWire
[2009/09/06 12:08:31 | 000,000,000 | —D | M] – C:\Users\Rachel\AppData\Roaming\McGraw-HillLicensing
[2008/03/13 19:53:57 | 000,000,000 | -H-D | M] – C:\Users\Rachel\AppData\Roaming\Template
[2008/03/05 19:52:55 | 000,000,000 | -H-D | M] – C:\Users\Rachel\AppData\Roaming\tmp
[2010/08/26 20:26:12 | 000,000,516 | —- | M] () – C:\Windows\Tasks\CAAntiSpywareScan_Daily as Rachel at 7 23 PM.job
[2011/05/30 10:02:35 | 000,032,580 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/05/30 10:10:33 | 000,000,424 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{4F32B8DA-94A1-456C-B67C-C330643BF1EE}.job

========== Purity Check ==========



< End of report >
Hi Sisa722,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    DRV - (adwarealert) – C:\Windows\system32\DRIVERS\adwarealert.sys ()
    O4 - HKLM..\Run: [Malwarebytes Anti-Malware Reboot] File not found
    O4 - HKLM..\Run: [pccguide.exe] File not found
    O4 - HKCU..\Run: [Aim6] File not found
    O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell - "" = AutoRun
    O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell\AutoRun\command - "" = H:\LaunchU3.exe
    
    :Files
    C:\ProgramData\ntuser.pol
    C:\Windows\System32\drivers\adwarealert.sys
    C:\ProgramData\BMcf449fba.xml
    C:\ProgramData\pskt.ini
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

I have found something of interest that I would like you to submit to an online virus scan. Please visit the site located Here and submit C:\Windows\System32\igmedkrn.dll.

Follow steps one and two as shown below [external image: Posted Image]

Let the scan proceed and let me know what the results are about this file.


In your next reply please post the logs created by OTL and VirusTotal. :thumbup:
Hi Jeff here are the results from the OTL scan first and then the Virus Total scan


OTL logfile created on: 5/30/2011 10:31:03 PM - Run 6
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Rachel\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.59% Memory free
4.22 Gb Paging File | 3.14 Gb Available in Paging File | 74.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.49 Gb Total Space | 37.10 Gb Free Space | 27.19% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.51 Gb Free Space | 55.09% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: RACHEL-PC | User Name: Rachel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rachel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Windows\System32\lxbccoms.exe ( )
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - c:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Users\Rachel\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (VETMSGNT) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
SRV - (PPCtlPriv) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (ITMRTSVC) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (OpenCASE Media Agent) – C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe (ExtendMedia Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (lxbc_device) – C:\Windows\System32\lxbccoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (VETEFILE) – C:\Windows\System32\drivers\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT) – C:\Windows\System32\drivers\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETMONNT) – C:\Windows\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (VET-FILT) – C:\Windows\System32\drivers\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\Windows\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\Windows\System32\drivers\vet-rec.sys (Computer Associates International, Inc.)
DRV - (adwarealert) – C:\Windows\system32\DRIVERS\adwarealert.sys ()
DRV - (IntcHdmiAddService) Intel® – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (NETw4v32) Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?wl=true
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/04/09 20:40:31 | 000,000,000 | —D | M]

[2009/04/18 10:45:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Rachel\AppData\Roaming\Mozilla\Extensions
[2009/04/18 10:45:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Rachel\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2008/05/08 09:46:35 | 000,238,211 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.139mm.com
O1 - Hosts: 8358 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware Reboot] File not found
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [pccguide.exe] File not found
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [DellAutomatedPCTuneUp] C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
O4 - Startup: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Digsby.lnk = C:\Program Files\Digsby\digsby.exe ()
O4 - Startup: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {ACF93F61-9F60-4C1E-A015-E3B3812BD58C} https://login.imagesilo.com/Install/DocView…MDocView400.cab (PVDMDocViewControls.PVDMDocView)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rachel\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell - "" = AutoRun
O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell\AutoRun\command - "" = H:\LaunchU3.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 60 Days ==========

[2011/05/30 18:30:47 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/30 10:52:56 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\Rachel\Desktop\OTL.exe
[2011/05/30 10:00:05 | 001,431,344 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Rachel\Desktop\TDSSKiller.exe
[2011/04/06 20:59:16 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/04/03 18:02:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/04/03 18:02:19 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2011/04/03 17:35:28 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Users\Rachel\Desktop\erunt-setup.exe
[2011/04/03 15:20:04 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Users\Rachel\Desktop\setup-spybotsd162.exe
[2010/02/16 23:39:58 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxbcserv.dll
[2010/02/16 23:39:58 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxbcusb1.dll
[2010/02/16 23:39:58 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxbcinpa.dll
[2010/02/16 23:39:58 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbciesc.dll
[2010/02/16 23:39:58 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBChcp.dll
[2010/02/16 23:39:57 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxbchbn3.dll
[2010/02/16 23:39:57 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxbccomc.dll
[2010/02/16 23:39:57 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxbcpmui.dll
[2010/02/16 23:39:57 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbclmpm.dll
[2010/02/16 23:39:57 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxbccoms.exe
[2010/02/16 23:39:57 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxbccomm.dll
[2010/02/16 23:39:57 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxbcih.exe
[2010/02/16 23:39:57 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxbccfg.exe
[2010/02/16 23:39:57 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxbcprox.dll
[2010/02/16 23:39:57 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxbcpplc.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2011/05/30 22:27:11 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/30 22:27:11 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/30 22:19:58 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/30 22:19:58 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/30 22:19:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/30 18:20:37 | 000,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{4F32B8DA-94A1-456C-B67C-C330643BF1EE}.job
[2011/05/30 10:52:56 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Rachel\Desktop\OTL.exe
[2011/05/30 10:50:40 | 000,002,305 | —- | M] () – C:\Users\Rachel\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/30 10:03:54 | 000,005,648 | —- | M] () – C:\Users\Rachel\AppData\Local\d3d9caps.dat
[2011/05/30 10:02:38 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/05/30 09:59:53 | 001,301,452 | —- | M] () – C:\Users\Rachel\Desktop\tdsskiller.zip
[2011/05/25 07:10:16 | 001,431,344 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Rachel\Desktop\TDSSKiller.exe
[2011/05/24 19:14:10 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2011/04/06 20:54:56 | 264,420,498 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/04/03 18:14:18 | 000,002,037 | —- | M] () – C:\Users\Rachel\Desktop\Attach.zip
[2011/04/03 18:13:43 | 000,002,027 | —- | M] () – C:\Users\Rachel\Desktop\Attach.rar
[2011/04/03 18:06:49 | 000,625,664 | —- | M] () – C:\Users\Rachel\Desktop\dds.scr
[2011/04/03 18:02:39 | 000,000,915 | —- | M] () – C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/04/03 18:02:20 | 000,000,735 | —- | M] () – C:\Users\Rachel\Desktop\NTREGOPT.lnk
[2011/04/03 18:02:20 | 000,000,716 | —- | M] () – C:\Users\Rachel\Desktop\ERUNT.lnk
[2011/04/03 17:35:29 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\Rachel\Desktop\erunt-setup.exe
[2011/04/03 15:25:09 | 000,001,057 | —- | M] () – C:\Users\Rachel\Desktop\Spybot - Search & Destroy.lnk
[2011/04/03 15:22:27 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\Rachel\Desktop\setup-spybotsd162.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/30 09:59:49 | 001,301,452 | —- | C] () – C:\Users\Rachel\Desktop\tdsskiller.zip
[2011/04/03 18:14:18 | 000,002,037 | —- | C] () – C:\Users\Rachel\Desktop\Attach.zip
[2011/04/03 18:13:17 | 000,002,027 | —- | C] () – C:\Users\Rachel\Desktop\Attach.rar
[2011/04/03 18:06:42 | 000,625,664 | —- | C] () – C:\Users\Rachel\Desktop\dds.scr
[2011/04/03 18:02:39 | 000,000,915 | —- | C] () – C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/04/03 18:02:20 | 000,000,735 | —- | C] () – C:\Users\Rachel\Desktop\NTREGOPT.lnk
[2011/04/03 18:02:20 | 000,000,716 | —- | C] () – C:\Users\Rachel\Desktop\ERUNT.lnk
[2011/04/03 15:25:09 | 000,001,057 | —- | C] () – C:\Users\Rachel\Desktop\Spybot - Search & Destroy.lnk
[2010/06/21 20:47:13 | 000,005,103 | —- | C] () – C:\ProgramData\xqkcebzs.dik
[2010/02/16 23:42:33 | 000,000,150 | —- | C] () – C:\Windows\Lexstat.ini
[2010/02/16 23:39:58 | 000,413,696 | —- | C] () – C:\Windows\System32\lxbcutil.dll
[2010/02/16 23:39:58 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBCinst.dll
[2009/10/12 16:07:20 | 000,087,552 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2009/09/19 18:34:33 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/19 18:34:33 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/06 12:17:28 | 000,000,091 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2009/08/16 11:36:10 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/05/13 20:28:02 | 000,000,004 | —- | C] () – C:\Users\Rachel\AppData\Roaming\8AB4F8
[2009/05/13 20:28:01 | 000,870,128 | —- | C] () – C:\Users\Rachel\AppData\Roaming\mcs.rma
[2009/04/25 18:03:47 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/02/28 04:01:29 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/05/08 20:20:40 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/05/03 21:43:29 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2008/05/03 21:43:29 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2008/05/03 21:43:29 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2008/05/03 21:43:29 | 000,049,152 | —- | C] () – C:\Windows\VFind.exe
[2008/05/03 21:06:24 | 000,072,704 | -H– | C] () – C:\Users\Rachel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/01 21:23:48 | 000,022,512 | —- | C] () – C:\Windows\System32\drivers\adwarealert.sys
[2008/04/29 19:21:07 | 000,109,747 | —- | C] () – C:\ProgramData\BMcf449fba.xml
[2008/04/29 19:21:07 | 000,000,022 | —- | C] () – C:\ProgramData\pskt.ini
[2008/04/27 11:35:21 | 000,000,000 | —- | C] () – C:\Windows\cdplayer.ini
[2008/04/17 22:38:08 | 000,005,648 | —- | C] () – C:\Users\Rachel\AppData\Local\d3d9caps.dat
[2008/03/13 19:53:55 | 000,000,000 | -H– | C] () – C:\Users\Rachel\AppData\Roaming\wklnhst.dat
[2008/02/29 19:07:53 | 000,910,304 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2008/02/29 19:07:53 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2008/02/29 19:07:53 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1253.dll
[2008/02/29 19:07:51 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2008/02/29 19:07:50 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2008/02/29 11:27:39 | 000,000,076 | RHS- | C] () – C:\Windows\CT4CET.bin
[2008/02/29 11:14:53 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2007/07/25 18:40:02 | 000,999,424 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2007/02/22 19:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxbccoin.dll
[2006/11/10 09:26:12 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/07 15:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/03 19:25:56 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,419,160 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,604,502 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,170 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/17 01:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/10/25 15:51:14 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbcvs.dll
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

< End of report >




0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: igmedkrn.dll
Submission date: 2011-05-31 02:44:42 (UTC)
Current status: finished
Result: 0 /42 (0.0%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.05.31.00 2011.05.30 -
AntiVir 7.11.8.173 2011.05.31 -
Antiy-AVL 2.0.3.7 2011.05.31 -
Avast 4.8.1351.0 2011.05.30 -
Avast5 5.0.677.0 2011.05.30 -
AVG 10.0.0.1190 2011.05.30 -
BitDefender 7.2 2011.05.31 -
CAT-QuickHeal 11.00 2011.05.30 -
ClamAV 0.97.0.0 2011.05.31 -
Commtouch 5.3.2.6 2011.05.31 -
Comodo 8898 2011.05.31 -
DrWeb 5.0.2.03300 2011.05.31 -
eSafe 7.0.17.0 2011.05.26 -
eTrust-Vet 36.1.8357 2011.05.30 -
F-Prot 4.6.2.117 2011.05.30 -
F-Secure 9.0.16440.0 2011.05.31 -
Fortinet 4.2.257.0 2011.05.31 -
GData 22 2011.05.31 -
Ikarus T3.1.1.104.0 2011.05.31 -
Jiangmin 13.0.900 2011.05.30 -
K7AntiVirus 9.104.4740 2011.05.30 -
Kaspersky 9.0.0.837 2011.05.31 -
McAfee 5.400.0.1158 2011.05.31 -
McAfee-GW-Edition 2010.1D 2011.05.31 -
Microsoft 1.6903 2011.05.30 -
NOD32 6166 2011.05.31 -
Norman 6.07.07 2011.05.30 -
nProtect 2011-05-30.02 2011.05.30 -
Panda 10.0.3.5 2011.05.30 -
PCTools 7.0.3.5 2011.05.19 -
Prevx 3.0 2011.05.31 -
Rising 23.60.00.03 2011.05.30 -
Sophos 4.65.0 2011.05.31 -
SUPERAntiSpyware 4.40.0.1006 2011.05.31 -
Symantec 20111.1.0.186 2011.05.31 -
TheHacker 6.7.0.1.214 2011.05.31 -
TrendMicro 9.200.0.1012 2011.05.30 -
TrendMicro-HouseCall 9.200.0.1012 2011.05.31 -
VBA32 3.12.16.0 2011.05.30 -
VIPRE 9440 2011.05.31 -
ViRobot 2011.5.30.4486 2011.05.31 -
VirusBuster 14.0.57.0 2011.05.30 -
Additional informationShow all
MD5 : 73fe6a5d98a575444bd5a14a5f39bc56
SHA1 : 86b0fc08aa449ec737aeddf4522c1b377adf48fe
SHA256: e950e788c64a8123558202dff0bd0086a8a2e4b44d1647991f49be03d9c64af1
ssdeep: 3072:a6kTDXC8+JDc/Z5IlxJuSo/XXStXvuQl26ZxnTpqxpPj1QI0cr1Qz80LcOton1WA:5FuSq
lEc
File size : 910304 bytes
First seen: 2010-03-09 04:29:11
Last seen : 2011-05-31 02:44:42
Magic: data
TrID:
LTAC compressed audio (v1.61) (99.6%)
MS Flight Simulator Aircraft Performance Info (0.3%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEiD: -
Androguard:
-
ExifTool:
file metadata
Error: File format error
FileSize: 889 kB



VT Community

0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
Hi Sisa722,

If you would now please follow these instructions… :)

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    DRV - (adwarealert) – C:\Windows\system32\DRIVERS\adwarealert.sys ()
    O4 - HKLM..\Run: [Malwarebytes Anti-Malware Reboot] File not found
    O4 - HKLM..\Run: [pccguide.exe] File not found
    O4 - HKCU..\Run: [Aim6] File not found
    O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell - "" = AutoRun
    O33 - MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}\Shell\AutoRun\command - "" = H:\LaunchU3.exe
    
    :Files
    C:\ProgramData\ntuser.pol
    C:\Windows\System32\drivers\adwarealert.sys
    C:\ProgramData\BMcf449fba.xml
    C:\ProgramData\pskt.ini
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Hi jeff,
I have tried running the OTL.exe "run fix" you sent me on the last posting, but it seems to freeze and then shutdown.
It doesn't go past "processing DRV adwarealert….."

Thanks,
Rachel
Hi Sisa722,

I notice that you have CA Antivirus installed on your system. We need to uninstall that and the best way to make sure that all of it is removed is by downloading the Computer Associates AV Remover Tool found here. Download either the 32bit or 64bit version whichever is applicable to your system onto your desktop. Once the tool is downloaded, double-click (for XP) or right-click and Run as Administrator (Vista) the icon for this tool and follow the prompts to completely remove Computer Associates AV.
———-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi Jeff, Here is the combofix.txt report ; ComboFix 11-06-02.02 - Rachel 06/02/2011 19:07:02.14.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1047 [GMT -4:00] Running from: C:\Users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_usnjsvc ((((((((((((((((((((((((( Files Created from 2011-05-02 to 2011-06-02 ))))))))))))))))))))))))))))))) 2011-06-02 23:17:18 . 2011-06-02 23:17:18 ——– d—–w- C:\Users\Default\AppData\Local\temp 2011-06-02 22:21:37 . 2011-06-02 22:21:37 ——– d—–w- C:\Windows\system32\winsflte.dl1 2011-06-02 22:21:37 . 2011-06-02 22:21:37 ——– d—–w- C:\Windows\system32\winsflt.dl1 2011-06-02 22:17:06 . 2011-05-24 23:12:56 6962000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{07CBDFA8-46DC-4CE5-945B-9E2518C3F4C7}\mpengine.dll 2011-06-02 22:15:20 . 2011-06-02 22:20:58 ——– d—–w- C:\ProgramData\CA-SupportBridge 2011-05-30 22:30:47 . 2011-05-30 22:30:47 ——– d—–w- C:\_OTL . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2011-05-24 23:14:10 . 2009-10-06 00:16:39 222080 ——w- C:\Windows\system32\MpSigStub.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 07:33:09 125952] "DellAutomatedPCTuneUp"="C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 15:49:50 465136] "Skype"="C:\Program Files\Skype\\Phone\Skype.exe" [2010-05-13 20:12:40 26192168] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 07:33:39 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-10 00:40:17 185896] "Persistence"="C:\Windows\system32\igfxpers.exe" [2007-12-15 03:53:58 133656] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 21:39:28 189736] "OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-28 05:51:42 36864] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 17:37:04 81920] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-12-15 03:54:06 137752] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-04 18:00:20 186904] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-12-15 03:53:54 154136] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-24 16:42:32 30192] "ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-25 06:03:00 17920] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 00:57:14 16384] "DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 22:43:34 118784] "Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-09-07 06:49:56 159744] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 22:17:16 47904] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 05:04:34 39792] "SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 11:07:24 405504] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2010-11-29 22:38:18 421888] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2011-03-07 20:33:40 421160] C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Digsby.lnk - C:\Program Files\Digsby\digsby.exe [2010-4-2 141488] ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-2-29 50688] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-9-7 1180952] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1932921871-4133750154-1044134656-1000] "EnableNotifications"=dword:00000001 "EnableNotificationsRef"=dword:00000001 R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 17:16:28 130384] R2 OpenCASE Media Agent;OpenCASE Media Agent;C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-29 22:29:14 835208] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-24 16:42:32 30192] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 17:16:28 753504] R4 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-11-12 11:07:16 73728] S0 adwarealert;adwarealert;C:\Windows\system32\DRIVERS\adwarealert.sys [2008-04-24 17:46:04 22512] S2 lxbc_device;lxbc_device;C:\Windows\system32\lxbccoms.exe [2007-03-16 06:24:02 537520] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-12-15 03:54:26 111104] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache Contents of the 'Scheduled Tasks' folder 2011-06-02 C:\Windows\Tasks\User_Feed_Synchronization-{4F32B8DA-94A1-456C-B67C-C330643BF1EE}.job - C:\Windows\system32\msfeedssync.exe [2011-02-09 04:43:45 . 2010-12-18 04:47:42] ——- Supplementary Scan ——- uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg TCP: DhcpNameServer = 10.0.0.1 DPF: {ACF93F61-9F60-4C1E-A015-E3B3812BD58C} - hxxps://login.imagesilo.com/Install/DocViewCtl/PVDMDocView400.cab - - - - ORPHANS REMOVED - - - - HKCU-Run-Aim6 - (no file) HKLM-Run-pccguide.exe - C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe HKLM-Run-Malwarebytes Anti-Malware Reboot - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe AddRemove-HijackThis - C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Hi Sisa722,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Windows\System32\drivers\adwarealert.sys
C:\ProgramData\BMcf449fba.xml
C:\ProgramData\pskt.ini
H:\LaunchU3.exe

Registry::
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c7437c6-3487-11df-9ced-001e4ce3d9be}]

Driver::
adwarealert


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hi Jeff, I think I deactivated all the anti virus/malware programs? There is nothing in my system tray. I ran the combofix following your instructions here is the report: (also sorry for the delay response, it seems i am no longer receiving email notifications) ComboFix 11-06-02.02 - Rachel 06/04/2011 18:12:46.15.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.864 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Rachel\Desktop\CFScript.txt SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_usnjsvc ——-\Legacy_ADWAREALERT ——-\Service_adwarealert . . ((((((((((((((((((((((((( Files Created from 2011-05-04 to 2011-06-04 ))))))))))))))))))))))))))))))) . . 2011-06-04 22:32 . 2011-06-04 22:32 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-04 21:41 . 2011-05-24 23:12 6962000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{255EED01-FF26-4230-946F-746DAFE2D5AE}\mpengine.dll 2011-06-04 21:27 . 2011-06-04 21:27 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2 2011-06-02 22:21 . 2011-06-02 22:21 ——– d—–w- c:\windows\system32\winsflte.dl1 2011-06-02 22:21 . 2011-06-02 22:21 ——– d—–w- c:\windows\system32\winsflt.dl1 2011-06-02 22:15 . 2011-06-02 22:20 ——– d—–w- c:\programdata\CA-SupportBridge 2011-05-30 22:30 . 2011-05-30 22:30 ——– d—–w- C:\_OTL 2011-05-30 14:36 . 2011-03-03 15:42 739328 —-a-w- c:\windows\system32\inetcomm.dll 2011-05-30 14:36 . 2011-02-17 06:23 420864 —-a-w- c:\windows\system32\vbscript.dll 2011-05-30 14:36 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2011-05-30 14:36 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2011-05-30 14:36 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-24 23:14 . 2009-10-06 00:16 222080 ——w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136] "Aim6"="" [BU] "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-05-13 26192168] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-10 185896] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-15 133656] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-11-01 189736] "pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [BU] "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-28 36864] "Malwarebytes Anti-Malware Reboot"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [BU] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-15 137752] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-04 186904] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-15 154136] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-24 30192] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 16384] "DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-07 159744] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160] . c:\users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Digsby.lnk - c:\program files\Digsby\digsby.exe [2010-4-2 141488] ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-2-29 50688] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-9-7 1180952] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1932921871-4133750154-1044134656-1000] "EnableNotifications"=dword:00000001 "EnableNotificationsRef"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-29 835208] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-24 30192] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] R4 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-11-12 73728] S2 lxbc_device;lxbc_device;c:\windows\system32\lxbccoms.exe [2007-03-16 537520] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2007-12-15 111104] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2011-06-04 c:\windows\Tasks\User_Feed_Synchronization-{4F32B8DA-94A1-456C-B67C-C330643BF1EE}.job - c:\windows\system32\msfeedssync.exe [2011-05-30 04:43] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg TCP: DhcpNameServer = 10.0.0.1 DPF: {ACF93F61-9F60-4C1E-A015-E3B3812BD58C} - hxxps://login.imagesilo.com/Install/DocViewCtl/PVDMDocView400.cab . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(5204) c:\windows\system32\btncopy.dll . ———————— Other Running Processes ———————— . c:\windows\system32\WLANExt.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe c:\windows\system32\STacSV.exe c:\windows\system32\DRIVERS\xaudio.exe c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe c:\windows\system32\igfxsrvc.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\ehome\ehmsas.exe c:\program files\iPod\bin\iPodService.exe c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\DellTPad\ApMsgFwd.exe c:\program files\DellTPad\HidFind.exe c:\program files\DellTPad\Apntex.exe . ************************************************************************** . Completion time: 2011-06-04 18:43:25 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-04 22:42 . Pre-Run: 42,530,717,696 bytes free Post-Run: 41,739,501,568 bytes free . - - End Of File - - 7E535B5092B7A14A8AC414D1E43E7879
Hi Sisa722,

It was no problem waiting at all. :) Looks like things are getting better.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/


In your next reply please post the logs created by both Malwarebytes and ESET Online scan and let me know how your system is running now. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI