This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

False Alerts

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, this morning I received a number of "fake alerts" re application errors and notification that I had experienced hard disk errors.
After running Malwarebytes Anti-Malware certain viruses were highlighted that hid the desktop, the task manager and certain drive properties.
The desktop and task manager are now visible but the fake alerts persist and various parts of programs don't run.

I have followed your advice re OTL, HiJack This and DDS.

While running OTL I received an Access Violation alert and the program stalled on "creating restore point - DO NOT INTERRUPT", therefore I do not have the requested log files for this program. (I have re-run OTL and it completed the run - providing an OTL.txt file which I have loaded before the HiJack This file.)

The others are listed below.
Any help would be appreciated. Thank you.

OTL logfile created on: 03/06/2011 12:21:49 - Run 8
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1022.07 Mb Total Physical Memory | 632.00 Mb Available Physical Memory | 61.83% Memory free
2.40 Gb Paging File | 2.18 Gb Available in Paging File | 90.66% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 109.40 Gb Free Space | 75.33% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 825.10 Gb Free Space | 88.58% Space Free | Partition Type: NTFS

Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.57\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"


FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/31 17:15:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/31 17:15:28 | 000,000,000 | —D | M]

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/06/02 08:00:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | -H– | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/05/28 04:34:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/14 17:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2009/11/06 16:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/07/23 19:19:21 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2009/11/06 16:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/29 19:58:19 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | RH-D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{612bcee4-2990-11dc-acc8-000e9bea7207}\Shell\AutoRun\command - "" = J:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave8 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)

========== Files/Folders - Created Within 30 Days ==========

[2011/06/03 08:16:19 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/06/03 05:58:51 | 000,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\beep.sys
[2011/06/03 05:55:56 | 000,000,000 | RH-D | C] – C:\Documents and Settings\chic\Recent
[2011/06/01 21:18:40 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\EverioBackup
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\WINDOWS\Cache
[2011/05/31 17:15:27 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/05/31 17:15:16 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\HpUpdate
[2011/05/31 17:14:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HP
[2011/05/31 17:14:21 | 001,761,128 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\HPScanMiniDrv_DJ1050_J410.dll
[2011/05/31 17:14:17 | 000,539,496 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911.dll
[2011/05/31 17:14:17 | 000,272,744 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911LM.dll
[2011/05/31 17:14:17 | 000,201,728 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinkcoi8911.dll
[2011/05/31 17:12:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP
[2011/05/31 17:12:18 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/05/31 17:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\HP
[2011/05/31 11:13:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/05/31 05:19:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Free YouTube Downloader
[2011/05/26 05:06:16 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/15 20:51:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ODBC
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Program Files\QuestScan
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/05/10 07:25:52 | 000,020,736 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lganddiag.sys
[2011/05/10 07:25:52 | 000,020,096 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgandgps.sys
[2011/05/10 06:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\LG PC Suite IV
[2011/05/08 15:55:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\My Music
[2011/05/08 15:52:22 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\iTunes
[2011/05/08 15:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/08 15:50:29 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/08 15:50:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/08 15:49:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/05/08 15:49:05 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/05/08 15:47:52 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/05/08 15:47:02 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/07 18:22:54 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2011/05/07 18:22:48 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\uTorrent
[2011/05/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\uTorrent
[2011/05/07 13:05:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/05/07 13:05:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/05/07 13:05:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/05/07 13:04:54 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/05/05 21:42:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/06/03 12:17:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/03 11:40:12 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/06/03 11:40:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/06/03 10:10:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/06/03 09:55:11 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\6824.sys
[2011/06/03 09:55:04 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/03 09:54:35 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/06/03 09:54:34 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/03 09:54:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/03 09:54:16 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/06/03 08:36:31 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1484.sys
[2011/06/03 08:22:24 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\Desktop\HiJackThis.exe
[2011/06/03 08:17:09 | 000,625,664 | —- | M] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2011/06/03 08:16:13 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/06/03 08:12:04 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\148D.sys
[2011/06/03 08:08:00 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2993.sys
[2011/06/03 07:57:12 | 000,107,232 | —- | M] () – C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp
[2011/06/03 07:56:08 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2004.sys
[2011/06/03 07:48:44 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1844.sys
[2011/06/03 05:28:35 | 000,000,152 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604r
[2011/06/03 05:28:35 | 000,000,136 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604
[2011/06/03 05:28:22 | 000,000,336 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\20045604
[2011/06/02 20:40:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/06/02 17:15:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/06/02 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/05/31 17:14:23 | 000,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 14:16:29 | 000,000,625 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | M] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | M] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 08:29:31 | 000,843,136 | -H– | M] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/29 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/05/28 08:55:55 | 000,112,952 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/27 18:10:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/26 05:06:16 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/10 10:59:49 | 000,002,413 | —- | M] () – C:\WINDOWS\System32\lgAxconfig.ini
[2011/05/09 23:09:37 | 000,000,742 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/09 23:09:37 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/08 15:51:13 | 000,001,452 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/07 13:05:56 | 000,486,540 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/07 13:05:56 | 000,088,424 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/05 21:34:23 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk

========== Files Created - No Company Name ==========

[2011/06/03 09:55:11 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\6824.sys
[2011/06/03 08:36:31 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\1484.sys
[2011/06/03 08:17:10 | 000,625,664 | —- | C] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2011/06/03 08:12:04 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\148D.sys
[2011/06/03 08:08:00 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\2993.sys
[2011/06/03 07:57:11 | 000,107,232 | —- | C] () – C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp
[2011/06/03 07:56:08 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\2004.sys
[2011/06/03 07:48:44 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\1844.sys
[2011/06/03 05:57:10 | 1071,796,224 | -HS- | C] () – C:\hiberfil.sys
[2011/06/03 05:28:35 | 000,000,152 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~20045604r
[2011/06/03 05:28:35 | 000,000,136 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~20045604
[2011/06/03 05:28:22 | 000,000,336 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\20045604
[2011/05/31 17:15:13 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2011/05/31 17:14:23 | 000,001,981 | —- | C] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | C] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 08:32:03 | 000,843,136 | -H– | C] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/28 08:55:55 | 000,112,952 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/08 15:51:13 | 000,001,452 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/08 15:47:55 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/05 21:34:23 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | -H– | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | -H– | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | -H– | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/07/19 20:26:15 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2005/05/17 18:17:52 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlcdcnv4.dll
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll

========== LOP Check ==========

[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/29 16:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/23 17:50:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2011/05/05 21:42:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/05/10 07:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/29 16:34:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/05/30 06:35:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2011/06/03 06:02:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/05/08 15:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/25 23:57:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2010/12/09 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2009/12/31 09:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/05/30 14:09:15 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/04/22 12:02:09 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2007/07/15 12:35:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\iWin
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2010/02/07 19:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Search Settings
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2010/12/31 21:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2011/06/03 07:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\uTorrent
[2009/03/24 21:02:57 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vghd
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation
[2011/06/03 10:10:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/06/02 20:40:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/06/02 17:15:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/06/02 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2010/08/02 20:24:56 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripDowngrade.job
[2010/08/02 20:24:57 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/06/03 09:54:35 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/11/24 22:47:54 | 000,000,735 | —- | M] () – C:\892.cin
[2010/06/02 21:33:44 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/08/11 11:18:33 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/11/03 03:45:47 | 000,003,291 | —- | M] () – C:\data
[2006/01/17 11:43:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2005/11/17 20:51:24 | 000,005,148 | RH– | M] () – C:\dell.sdr
[2011/06/03 08:08:53 | 000,058,503 | —- | M] () – C:\dlcd.log
[2010/10/25 20:43:22 | 000,009,432 | —- | M] () – C:\dlcdscan.log
[2009/02/18 22:37:03 | 000,003,532 | —- | M] () – C:\drmHeader.bin
[2006/01/29 14:07:03 | 000,013,312 | —- | M] () – C:\dvb.GRF
[2006/01/28 20:59:03 | 000,008,192 | —- | M] () – C:\dvb4.GRF
[2010/02/21 13:11:54 | 000,000,157 | —- | M] () – C:\error.txt
[2011/06/03 09:54:16 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2010/11/22 22:11:18 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2005/11/24 22:18:42 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/11/17 21:11:23 | 000,000,897 | -H– | M] () – C:\IPH.PH
[2010/05/07 19:49:49 | 000,029,887 | —- | M] () – C:\log.txt
[2006/10/08 20:03:52 | 000,000,036 | —- | M] () – C:\mediamp3.dat
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/27 22:24:22 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/03 09:54:03 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2006/02/25 15:44:24 | 000,184,320 | —- | M] () – C:\PlayerHost.dll
[2008/06/24 18:14:29 | 000,003,021 | —- | M] () – C:\rollback.ini
[2007/11/08 20:03:17 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/06/21 04:46:26 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcdPP5C.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/04/25 08:58:07 | 000,001,746 | -H– | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/27 22:36:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2008/06/23 18:36:24 | 000,773,120 | —- | M] () – C:\WINDOWS\system32\NEROINSTAEC43759.DB

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/24 21:16:36 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/03 08:22:24 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\desktop\HiJackThis.exe
[2011/06/03 08:16:13 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\desktop\OTL.exe
[2009/05/03 09:04:25 | 003,550,592 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\chic\desktop\procexp.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2010/05/20 15:27:26 | 000,013,023 | —- | M] () – C:\WINDOWS\VX1000.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-28 03:34:35

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:453B2FDD421AAE3E
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B1CD2545

< End of report >


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:38:30, on 03/06/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17096)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\chic\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

–
End of file - 8033 bytes


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 8:39:40.50 on 03/06/2011
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.611 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\chic\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = ;*.local
BHO: HistoryTriggerBHO Class: {21a88cb9-84d2-4020-a2d1-b25a21034884} - c:\program files\lg electronics\lg pc suite iv\linkair\LinkAirBrowserHelper.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\i386\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD}
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/E/1/F/E1F6B9B3-49AA-42BB-9115-D9FB57768CC2/wmavax.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\chic\applic~1\mozilla\firefox\profiles\a8kz582u.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig
FF - prefs.js: keyword.URL - hxxp://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords=
FF - plugin: c:\documents and settings\chic\local settings\application data\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: g:\program files\itunes\mozilla plugins\npitunes.dll
.
—- FIREFOX POLICIES —-

FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-4-22 352656]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-10 55152]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys –> c:\windows\system32\drivers\ntcdrdrv.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [2005-12-19 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [2005-11-24 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys –> c:\windows\system32\drivers\lgandbus.sys [?]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2011-5-10 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2011-5-10 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys –> c:\windows\system32\drivers\lgandmodem.sys [?]
S3 AndNetDiag;LG AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys –> c:\windows\system32\drivers\lgandnetdiag.sys [?]
S3 AndNetGps;LG AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys –> c:\windows\system32\drivers\lgandnetgps.sys [?]
S3 ANDNetModem;LG AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys –> c:\windows\system32\drivers\lgandnetmodem.sys [?]
S3 andnetndis;LG AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys –> c:\windows\system32\drivers\lgandnetndis.sys [?]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2007-12-30 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [2005-12-25 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [2005-12-25 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-4-3 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [2005-5-11 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [2005-5-11 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [2005-5-11 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [2005-5-11 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [2005-5-11 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys –> c:\windows\system32\drivers\ManyCam.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-10 14336]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-4-3 233472]
.
=============== Created Last 30 ================
.
2011-06-03 07:36:31 116224 —-a-w- c:\windows\system32\drivers\1484.sys
2011-06-03 07:12:04 116224 —-a-w- c:\windows\system32\drivers\148D.sys
2011-06-03 07:08:00 116224 —-a-w- c:\windows\system32\drivers\2993.sys
2011-06-03 06:56:08 116224 —-a-w- c:\windows\system32\drivers\2004.sys
2011-06-03 06:48:44 116224 —-a-w- c:\windows\system32\drivers\1844.sys
2011-06-03 04:58:51 4224 —-a-w- c:\windows\system32\beep.sys
2011-05-31 16:15:28 ——– d—–w- c:\windows\Cache
2011-05-31 16:15:27 ——– d—–w- c:\program files\Coupons
2011-05-31 16:15:16 ——– d—–w- c:\docume~1\chic\applic~1\HpUpdate
2011-05-31 16:14:21 1761128 —-a-w- c:\windows\system32\HPScanMiniDrv_DJ1050_J410.dll
2011-05-31 16:14:17 539496 —-a-w- c:\windows\system32\hpinksts8911.dll
2011-05-31 16:14:17 272744 —-a-w- c:\windows\system32\hpinksts8911LM.dll
2011-05-31 16:14:17 201728 —-a-w- c:\windows\system32\hpinkcoi8911.dll
2011-05-31 16:12:18 ——– d—–w- c:\program files\HP
2011-05-31 16:11:53 ——– d—–w- c:\docume~1\chic\locals~1\applic~1\HP
2011-05-26 04:06:16 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 19:51:40 ——– d—–w- c:\program files\common files\ODBC
2011-05-15 19:24:36 ——– d—–w- c:\program files\QuestScan
2011-05-15 19:24:36 ——– d—–w- c:\docume~1\alluse~1\applic~1\QuestScan
2011-05-10 06:25:52 20736 —-a-w- c:\windows\system32\drivers\lganddiag.sys
2011-05-10 06:25:52 20096 —-a-w- c:\windows\system32\drivers\lgandgps.sys
2011-05-08 14:50:29 ——– d—–w- c:\program files\iPod
2011-05-08 14:50:24 ——– d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-08 14:47:02 ——– d—–w- c:\program files\Bonjour
2011-05-07 17:22:54 ——– d—–w- c:\program files\uTorrent
2011-05-07 17:22:48 ——– d—–w- c:\docume~1\chic\applic~1\uTorrent
2011-05-07 17:22:28 ——– d—–w- c:\docume~1\chic\locals~1\applic~1\uTorrent
2011-05-07 12:05:04 ——– d—–w- c:\windows\system32\winrm
2011-05-07 12:05:04 ——– d—–w- c:\windows\system32\GroupPolicy
2011-05-07 12:04:54 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-05-05 20:42:27 ——– d—–w- c:\docume~1\alluse~1\applic~1\IObit
.
==================== Find3M ====================
.
2011-04-23 05:56:36 285480 —-a-w- c:\windows\system32\guard32.dll
2011-04-06 15:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20:16 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20:16 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-11 14:10:38 471552 —-a-w- c:\windows\apppatch\aclayers.dll
2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll
.
============= FINISH: 8:41:07.59 ===============
Hi

Please do the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2011/06/03 10:10:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
    [2011/06/03 08:36:31 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1484.sys
    [2011/06/03 09:55:11 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\6824.sys
    [2011/06/03 08:12:04 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\148D.sys
    [2011/06/03 08:08:00 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2993.sys
    [2011/06/03 07:57:12 | 000,107,232 | —- | M] () – C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp
    [2011/06/03 07:56:08 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2004.sys
    [2011/06/03 07:48:44 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1844.sys
    [2011/06/03 05:28:35 | 000,000,152 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604r
    [2011/06/03 05:28:35 | 000,000,136 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604
    [2011/06/03 05:28:22 | 000,000,336 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\20045604
    [2011/06/02 20:40:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
    [2011/06/02 17:15:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
    [2011/06/02 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
    
    :Files
    C:\WINDOWS\tasks\At*.job
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Hi, thanks for your response … please see requested log/files below …

All processes killed
========== OTL ==========
C:\WINDOWS\tasks\At1.job moved successfully.
File C:\WINDOWS\System32\drivers\1484.sys not found.
File C:\WINDOWS\System32\drivers\6824.sys not found.
File C:\WINDOWS\System32\drivers\148D.sys not found.
File C:\WINDOWS\System32\drivers\2993.sys not found.
C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp moved successfully.
File C:\WINDOWS\System32\drivers\2004.sys not found.
File C:\WINDOWS\System32\drivers\1844.sys not found.
C:\Documents and Settings\All Users\Application Data\~20045604r moved successfully.
C:\Documents and Settings\All Users\Application Data\~20045604 moved successfully.
C:\Documents and Settings\All Users\Application Data\20045604 moved successfully.
C:\WINDOWS\tasks\At2.job moved successfully.
C:\WINDOWS\tasks\At3.job moved successfully.
C:\WINDOWS\tasks\At4.job moved successfully.
========== FILES ==========
File\Folder C:\WINDOWS\tasks\At*.job not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\chic\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\chic\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator

User: All Users

User: chic
->Flash cache emptied: 470 bytes

User: Default User

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: chic
->Temp folder emptied: 26870064 bytes
->Temporary Internet Files folder emptied: 677925 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 92607375 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16832910 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 366641711 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 97390 bytes

Total Files Cleaned = 480.00 mb


OTL by OldTimer - Version 3.2.23.0 log created on 06042011_223458

Files\Folders moved on Reboot…
C:\Documents and Settings\chic\Local Settings\Temp\WCESLog.log moved successfully.
File\Folder C:\WINDOWS\temp\ldre25d.tmp not found!
C:\WINDOWS\temp\ldre2ab.tmp moved successfully.

Registry entries deleted on Reboot…


aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-04 22:42:26
—————————–
22:42:26.343 OS Version: Windows 5.1.2600 Service Pack 3
22:42:26.343 Number of processors: 2 586 0x403
22:42:26.343 ComputerName: AMANCHIC UserName: chic
22:42:26.968 Initialize success
22:42:28.828 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
22:42:28.828 Disk 0 Vendor: SAMSUNG_HD160JJ/P ZM100-34 Size: 152587MB BusType: 3
22:42:30.859 Disk 0 MBR read successfully
22:42:30.859 Disk 0 MBR scan
22:42:30.859 Disk 0 unknown MBR code
22:42:32.875 Disk 0 scanning sectors +312496380
22:42:32.890 Disk 0 scanning C:\WINDOWS\system32\drivers
22:42:44.750 Service scanning
22:42:46.625 Disk 0 trace - called modules:
22:42:46.625
22:42:46.625 Scan finished successfully
22:43:26.421 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\chic\Desktop\MBR.dat"
22:43:26.437 The log file has been saved successfully to "C:\Documents and Settings\chic\Desktop\aswMBR.txt"


MBR.zip is also attached. Thank you.

Attachments:

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please see ComboFix log file below …

ComboFix 11-06-04.02 - chic 05/06/2011 6:56.12.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.663 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\chic\WINDOWS
c:\documents and settings\chic\WINDOWS\system\cdr4_2k.sys
c:\documents and settings\chic\WINDOWS\system\cdr4_xp.sys
c:\documents and settings\chic\WINDOWS\system\cdralw2k.sys
c:\windows\AutoRun.ini
.
—– File Replicators —–
.
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut10.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut11.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut11_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut12.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut12_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut13.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut13_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut14.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut14_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut15_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut16_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut17_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut18.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut19.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut20.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut21.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut22.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut23.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut24.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut25.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut26.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut27.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut28.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut29.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut3_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut30.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut32.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut33.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut34.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut35.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut36.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut37.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut38.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut39.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut4.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut40.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut8.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut8_A888ADCD972E402C989E44C9B6E8DB64.exe
c:\windows\Installer\{CB0EAA54-406C-4119-9A63-EDD0DC1B2B47}\NewShortcut9.BB7DC861_90E5_455B_AF72_47A8D82F237A.exe
.
Infected copy of c:\windows\system32\drivers\volsnap.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-04 21:34 . 2011-06-04 21:34 ——– d—–w- C:\_OTL
2011-06-04 18:18 . 2011-06-04 18:18 116224 —-a-w- c:\windows\system32\drivers\1613F.sys
2011-06-04 18:15 . 2011-06-04 18:15 116224 —-a-w- c:\windows\system32\drivers\1703C.sys
2011-06-04 18:13 . 2011-06-04 18:13 116224 —-a-w- c:\windows\system32\drivers\19336.sys
2011-06-04 18:11 . 2011-06-04 18:11 116224 —-a-w- c:\windows\system32\drivers\16130.sys
2011-06-04 18:09 . 2011-06-04 18:09 116224 —-a-w- c:\windows\system32\drivers\1202A.sys
2011-06-04 18:07 . 2011-06-04 18:07 116224 —-a-w- c:\windows\system32\drivers\78928.sys
2011-06-04 18:04 . 2011-06-04 18:04 116224 —-a-w- c:\windows\system32\drivers\48426.sys
2011-06-04 18:02 . 2011-06-04 18:02 116224 —-a-w- c:\windows\system32\drivers\4481D.sys
2011-06-04 18:00 . 2011-06-04 18:00 116224 —-a-w- c:\windows\system32\drivers\16017.sys
2011-06-04 17:58 . 2011-06-04 17:58 116224 —-a-w- c:\windows\system32\drivers\12115.sys
2011-06-04 17:56 . 2011-06-04 17:56 116224 —-a-w- c:\windows\system32\drivers\79612.sys
2011-06-04 17:54 . 2011-06-04 17:54 116224 —-a-w- c:\windows\system32\drivers\19310.sys
2011-06-04 17:38 . 2011-06-04 17:38 116224 —-a-w- c:\windows\system32\drivers\735E.sys
2011-06-04 17:34 . 2011-06-04 17:34 116224 —-a-w- c:\windows\system32\drivers\1803.sys
2011-06-03 04:58 . 2004-08-04 05:00 4224 —-a-w- c:\windows\system32\beep.sys
2011-05-31 16:15 . 2011-05-31 16:15 ——– d—–w- c:\windows\Cache
2011-05-31 16:15 . 2011-05-31 16:15 ——– d—–w- c:\program files\Coupons
2011-05-31 16:15 . 2011-05-31 16:15 ——– d—–w- c:\documents and settings\chic\Application Data\HpUpdate
2011-05-31 16:14 . 2010-02-02 13:23 1761128 —-a-w- c:\windows\system32\HPScanMiniDrv_DJ1050_J410.dll
2011-05-31 16:14 . 2010-02-02 13:23 539496 —-a-w- c:\windows\system32\hpinksts8911.dll
2011-05-31 16:14 . 2010-02-02 13:23 272744 —-a-w- c:\windows\system32\hpinksts8911LM.dll
2011-05-31 16:14 . 2010-02-02 13:23 201728 —-a-w- c:\windows\system32\hpinkcoi8911.dll
2011-05-31 16:12 . 2011-05-31 16:16 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2011-05-31 16:12 . 2011-05-31 16:15 ——– d—–w- c:\program files\HP
2011-05-31 16:11 . 2011-05-31 16:11 ——– d—–w- c:\documents and settings\chic\Local Settings\Application Data\HP
2011-05-26 04:06 . 2011-06-04 20:13 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 19:24 . 2011-05-30 05:35 ——– d—–w- c:\documents and settings\All Users\Application Data\QuestScan
2011-05-15 19:24 . 2011-05-28 09:07 ——– d—–w- c:\program files\QuestScan
2011-05-10 06:25 . 2010-12-07 13:23 20736 —-a-w- c:\windows\system32\drivers\lganddiag.sys
2011-05-10 06:25 . 2010-12-07 13:23 20096 —-a-w- c:\windows\system32\drivers\lgandgps.sys
2011-05-08 14:50 . 2011-05-08 14:50 ——– d—–w- c:\program files\iPod
2011-05-08 14:50 . 2011-05-08 14:51 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-08 14:47 . 2011-05-08 14:47 ——– d—–w- c:\program files\Apple Software Update
2011-05-08 14:47 . 2011-05-08 14:47 ——– d—–w- c:\program files\Bonjour
2011-05-07 17:22 . 2011-06-04 17:33 ——– d—–w- c:\program files\uTorrent
2011-05-07 17:22 . 2011-06-04 15:46 ——– d—–w- c:\documents and settings\chic\Application Data\uTorrent
2011-05-07 17:22 . 2011-05-07 17:22 ——– d—–w- c:\documents and settings\chic\Local Settings\Application Data\uTorrent
2011-05-07 12:05 . 2011-05-07 12:05 ——– d—–w- c:\windows\system32\winrm
2011-05-07 12:05 . 2011-05-07 12:05 ——– d—–w- c:\windows\system32\GroupPolicy
2011-05-07 12:04 . 2011-05-07 12:05 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-29 08:11 . 2010-07-22 21:38 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-23 05:56 . 2010-06-01 18:00 285480 —-a-w- c:\windows\system32\guard32.dll
2011-04-23 05:56 . 2010-06-04 10:55 239368 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-04-23 05:56 . 2010-06-01 18:00 27576 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-04-23 05:56 . 2010-06-01 18:00 15592 —-a-w- c:\windows\system32\drivers\cmderd.sys
2011-04-06 15:20 . 2011-04-06 15:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-11 14:10 . 2004-08-10 12:50 471552 —-a-w- c:\windows\apppatch\aclayers.dll
2011-04-14 16:26 . 2011-03-27 13:07 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\i386\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
2006-11-22 20:10 151552 ——w- c:\program files\CyberLink\PCM4Everio\EverioService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
2008-05-26 19:13 57344 —-a-w- c:\program files\MarkAny\ContentSafer\MaAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 –sh–w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2005-12-18 14:26 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\WINDOWS\\system32\\dlcdcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlcdPSWX.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\chic\\My Documents\\Downloads\\BitTorrent-7.2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [04/06/2010 11:55 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [01/06/2010 19:00 27576]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [22/04/2011 12:02 352656]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/09/2009 09:11 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/09/2009 09:11 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/09/2009 09:11 12928]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [17/06/2005 12:11 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys –> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [19/12/2005 19:02 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [24/11/2005 22:38 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus.sys –> c:\windows\system32\DRIVERS\lgandbus.sys [?]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [10/05/2011 07:25 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [10/05/2011 07:25 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem.sys –> c:\windows\system32\DRIVERS\lgandmodem.sys [?]
S3 AndNetDiag;LG AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag.sys –> c:\windows\system32\DRIVERS\lgandnetdiag.sys [?]
S3 AndNetGps;LG AndroidNet USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandnetgps.sys –> c:\windows\system32\DRIVERS\lgandnetgps.sys [?]
S3 ANDNetModem;LG AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem.sys –> c:\windows\system32\DRIVERS\lgandnetmodem.sys [?]
S3 andnetndis;LG AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis.sys –> c:\windows\system32\DRIVERS\lgandnetndis.sys [?]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [30/12/2007 20:16 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 12:42 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [25/12/2005 11:22 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [25/12/2005 11:11 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [03/04/2010 10:41 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [11/05/2005 14:12 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [11/05/2005 14:12 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [11/05/2005 14:12 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [11/05/2005 14:12 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [11/05/2005 14:12 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys –> c:\windows\system32\DRIVERS\ManyCam.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [22/07/2010 22:38 39984]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [25/03/2010 11:25 30969208]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/06/2010 18:07 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22:37 4640000]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 14:37 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [10/08/2004 13:51 14336]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [03/04/2010 10:41 233472]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31/12/2009 09:33 691696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-29 c:\windows\Tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-19 03:44]
.
2011-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2011-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2011-06-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.00\MediaManager\grab.html
IE: Se&nd; to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig
FF - prefs.js: keyword.URL - hxxp://www.questscan.com/?tmp=nemo_results_removelink&prt;=QstscanPB&keywords;=

FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Glary Utilities_is1 - g:\program files\Glary Utilities\unins000.exe
AddRemove-{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1 - g:\program files\Free YouTube Downloader\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-05 07:04
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\-213E8]
"imagepath"="\??\c:\windows\TEMP\-213E8.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\2143E8]
"imagepath"="\??\c:\windows\TEMP\2143E8.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2CB90BE9-3AD9-D1A2-3C33-C3A076F28F92}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iacfkobdbkopgbloea"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"haigiamelfjfcnkl"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"faghdhhmmpjm"=hex:63,62,6e,6d,6a,62,6e,6b,69,63,6c,6a,64,64,64,70,6f,66,66,69,
67,65,62,65,62,63,67,6f,66,6c,69,64,6e,6f,67,6b,6a,6b,00,7e
"faghihgjhglb"=hex:6f,62,6c,6d,70,61,6d,6f,64,68,68,6b,6c,6a,64,6e,6b,6c,68,67,
6f,6a,67,6e,69,62,65,6f,6b,66,6d,6b,66,68,62,62,6e,68,66,6f,68,64,65,70,6d,\
.
Completion time: 2011-06-05 07:11:16
ComboFix-quarantined-files.txt 2011-06-05 06:11
.
Pre-Run: 116,934,885,376 bytes free
Post-Run: 116,882,763,776 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 2D24F4920BEE0E1AA3DD52D543DF479F
we still have more work to do with ComboFix but first I want to see what file replicator you have on board, please run a scan with ESET


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
log file below … on reading back I did not click on BACK and FINISH when using the ESET scan … does this now have to be re-run? C:\MicroGaming\Casino\YukonGold\install.exe a variant of Win32/PrimeCasino application cleaned by deleting - quarantined C:\Program Files\MP3 Player Utilities 4.00\DelDrv.exe Win32/KillFiles.NEM trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP396\A0054586.exe a variant of Win32/Kryptik.OOX trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056011.sys Win32/Olmasco.E trojan deleted - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056074.exe a variant of Win32/PrimeCasino application cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056075.exe Win32/KillFiles.NEM trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\1202A.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\12115.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\16017.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\16130.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\1613F.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\1703C.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\1803.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\19310.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\19336.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\4481D.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\48426.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\735E.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\78928.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\79612.sys Win32/Olmasco.D trojan cleaned by deleting - quarantined C:\_OTL\MovedFiles\06042011_223458\C_WINDOWS\temp\ldre2ab.tmp Win32/Olmarik.IF virus deleted - quarantined
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=118871&view=findpost&p=734344

Collect::
c:\windows\system32\drivers\1613F.sys
c:\windows\system32\drivers\1703C.sys
c:\windows\system32\drivers\19336.sys
c:\windows\system32\drivers\16130.sys
c:\windows\system32\drivers\1202A.sys
c:\windows\system32\drivers\78928.sys
c:\windows\system32\drivers\48426.sys
c:\windows\system32\drivers\4481D.sys
c:\windows\system32\drivers\16017.sys
c:\windows\system32\drivers\12115.sys
c:\windows\system32\drivers\79612.sys
c:\windows\system32\drivers\19310.sys
c:\windows\system32\drivers\735E.sys
c:\windows\system32\drivers\1803.sys
c:\windows\TEMP\-213E8.tmp
c:\windows\TEMP\2143E8.tmp

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5000:TCP"=-
"5001:TCP"=-
"5002:TCP"=-
"5003:TCP"=-
"5004:TCP"=-
"5005:TCP"=-
"5006:TCP"=-
"5007:TCP"=-
"5008:TCP"=-
"5009:TCP"=-
"5010:TCP"=-
"5011:TCP"=-
"5012:TCP"=-
"5013:TCP"=-
"5014:TCP"=-
"5015:TCP"=-
"5016:TCP"=-
"5017:TCP"=-
"5018:TCP"=-
"5019:TCP"=-
"5020:TCP"=-

Driver::
-213E8
2143E8

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
hiya,

Unfortunately I "lost" the initial log file; tried copying and pasting straight into my reply without first saving the file, and it didn't work. Sorry about that - I have re-run, not sure if this is of any use to you, but have posted the results below.
Again, sorry for the mishap.

ComboFix 11-06-05.06 - chic 06/06/2011 5:36.14.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.481 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\chic\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-05-06 to 2011-06-06 )))))))))))))))))))))))))))))))
.
.
2011-06-05 12:55 . 2011-06-05 12:55 ——– d—–w- c:\program files\ESET
2011-06-04 21:34 . 2011-06-04 21:34 ——– d—–w- C:\_OTL
2011-06-03 04:58 . 2004-08-04 05:00 4224 —-a-w- c:\windows\system32\beep.sys
2011-05-31 16:15 . 2011-05-31 16:15 ——– d—–w- c:\windows\Cache
2011-05-31 16:15 . 2011-05-31 16:15 ——– d—–w- c:\program files\Coupons
2011-05-31 16:15 . 2011-05-31 16:15 ——– d—–w- c:\documents and settings\chic\Application Data\HpUpdate
2011-05-31 16:14 . 2010-02-02 13:23 1761128 —-a-w- c:\windows\system32\HPScanMiniDrv_DJ1050_J410.dll
2011-05-31 16:14 . 2010-02-02 13:23 539496 —-a-w- c:\windows\system32\hpinksts8911.dll
2011-05-31 16:14 . 2010-02-02 13:23 272744 —-a-w- c:\windows\system32\hpinksts8911LM.dll
2011-05-31 16:14 . 2010-02-02 13:23 201728 —-a-w- c:\windows\system32\hpinkcoi8911.dll
2011-05-31 16:12 . 2011-05-31 16:16 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2011-05-31 16:12 . 2011-05-31 16:15 ——– d—–w- c:\program files\HP
2011-05-31 16:11 . 2011-05-31 16:11 ——– d—–w- c:\documents and settings\chic\Local Settings\Application Data\HP
2011-05-26 04:06 . 2011-06-04 20:13 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 19:24 . 2011-05-30 05:35 ——– d—–w- c:\documents and settings\All Users\Application Data\QuestScan
2011-05-15 19:24 . 2011-05-28 09:07 ——– d—–w- c:\program files\QuestScan
2011-05-10 06:25 . 2010-12-07 13:23 20736 —-a-w- c:\windows\system32\drivers\lganddiag.sys
2011-05-10 06:25 . 2010-12-07 13:23 20096 —-a-w- c:\windows\system32\drivers\lgandgps.sys
2011-05-08 14:50 . 2011-05-08 14:50 ——– d—–w- c:\program files\iPod
2011-05-08 14:50 . 2011-05-08 14:51 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-08 14:47 . 2011-05-08 14:47 ——– d—–w- c:\program files\Apple Software Update
2011-05-08 14:47 . 2011-05-08 14:47 ——– d—–w- c:\program files\Bonjour
2011-05-07 17:22 . 2011-06-04 17:33 ——– d—–w- c:\program files\uTorrent
2011-05-07 17:22 . 2011-06-04 15:46 ——– d—–w- c:\documents and settings\chic\Application Data\uTorrent
2011-05-07 17:22 . 2011-05-07 17:22 ——– d—–w- c:\documents and settings\chic\Local Settings\Application Data\uTorrent
2011-05-07 12:05 . 2011-05-07 12:05 ——– d—–w- c:\windows\system32\winrm
2011-05-07 12:05 . 2011-05-07 12:05 ——– d—–w- c:\windows\system32\GroupPolicy
2011-05-07 12:04 . 2011-05-07 12:05 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-29 08:11 . 2010-07-22 21:38 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-23 05:56 . 2010-06-01 18:00 285480 —-a-w- c:\windows\system32\guard32.dll
2011-04-23 05:56 . 2010-06-04 10:55 239368 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-04-23 05:56 . 2010-06-01 18:00 27576 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-04-23 05:56 . 2010-06-01 18:00 15592 —-a-w- c:\windows\system32\drivers\cmderd.sys
2011-04-06 15:20 . 2011-04-06 15:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-11 14:10 . 2004-08-10 12:50 471552 —-a-w- c:\windows\apppatch\aclayers.dll
2011-04-14 16:26 . 2011-03-27 13:07 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\i386\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
2006-11-22 20:10 151552 ——w- c:\program files\CyberLink\PCM4Everio\EverioService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
2008-05-26 19:13 57344 —-a-w- c:\program files\MarkAny\ContentSafer\MaAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 –sh–w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2005-12-18 14:26 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\WINDOWS\\system32\\dlcdcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlcdPSWX.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\chic\\My Documents\\Downloads\\BitTorrent-7.2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP"= 135:TCP:TCP Port 135
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [04/06/2010 11:55 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [01/06/2010 19:00 27576]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [22/04/2011 12:02 352656]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/09/2009 09:11 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/09/2009 09:11 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/09/2009 09:11 12928]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [17/06/2005 12:11 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys –> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [19/12/2005 19:02 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [24/11/2005 22:38 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus.sys –> c:\windows\system32\DRIVERS\lgandbus.sys [?]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [10/05/2011 07:25 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [10/05/2011 07:25 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem.sys –> c:\windows\system32\DRIVERS\lgandmodem.sys [?]
S3 AndNetDiag;LG AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag.sys –> c:\windows\system32\DRIVERS\lgandnetdiag.sys [?]
S3 AndNetGps;LG AndroidNet USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandnetgps.sys –> c:\windows\system32\DRIVERS\lgandnetgps.sys [?]
S3 ANDNetModem;LG AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem.sys –> c:\windows\system32\DRIVERS\lgandnetmodem.sys [?]
S3 andnetndis;LG AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis.sys –> c:\windows\system32\DRIVERS\lgandnetndis.sys [?]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [30/12/2007 20:16 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 12:42 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [25/12/2005 11:22 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [25/12/2005 11:11 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [03/04/2010 10:41 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [11/05/2005 14:12 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [11/05/2005 14:12 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [11/05/2005 14:12 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [11/05/2005 14:12 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [11/05/2005 14:12 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys –> c:\windows\system32\DRIVERS\ManyCam.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [22/07/2010 22:38 39984]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [25/03/2010 11:25 30969208]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/06/2010 18:07 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22:37 4640000]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 14:37 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [10/08/2004 13:51 14336]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [03/04/2010 10:41 233472]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31/12/2009 09:33 691696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-29 c:\windows\Tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-19 03:44]
.
2011-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
.
2011-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.00\MediaManager\grab.html
IE: Se&nd; to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig
FF - prefs.js: keyword.URL - hxxp://www.questscan.com/?tmp=nemo_results_removelink&prt;=QstscanPB&keywords;=

FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-06 05:51
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2CB90BE9-3AD9-D1A2-3C33-C3A076F28F92}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iacfkobdbkopgbloea"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"haigiamelfjfcnkl"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"faghdhhmmpjm"=hex:63,62,6e,6d,6a,62,6e,6b,69,63,6c,6a,64,64,64,70,6f,66,66,69,
67,65,62,65,62,63,67,6f,66,6c,69,64,6e,6f,67,6b,6a,6b,00,7e
"faghihgjhglb"=hex:6f,62,6c,6d,70,61,6d,6f,64,68,68,6b,6c,6a,64,6e,6b,6c,68,67,
6f,6a,67,6e,69,62,65,6f,6b,66,6d,6b,66,68,62,62,6e,68,66,6f,68,64,65,70,6d,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1164)
c:\windows\system32\WININET.dll
c:\windows\system32\guard32.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~4\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\fxssvc.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\SpywareGuard\sgbhp.exe
.
**************************************************************************
.
Completion time: 2011-06-06 05:56:02 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-06 04:55
ComboFix2.txt 2011-06-06 04:28
ComboFix3.txt 2011-06-05 06:11
.
Pre-Run: 116,633,923,584 bytes free
Post-Run: 116,603,543,552 bytes free
.
- - End Of File - - BDE628F9AC7229D8F85C878E447C6BDC
Hi,

I don't need it now, but for future reference, logs are saved in C;\qoobox folder

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT


Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Hi, both log files listed. MBAM run took less than 5 minutes. Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 6788 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 06/06/2011 18:14:18 mbam-log-2011-06-06 (18-14-18).txt Scan type: Quick scan Objects scanned: 153988 Time elapsed: 4 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETScan. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056076.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056077.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056078.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056079.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056080.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056081.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056082.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056083.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056084.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056085.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056086.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056087.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056088.sys Win32/Olmasco.D trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399\A0056089.sys Win32/Olmasco.D trojan Thanks again,
Hi

Please do the following:

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 21 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Please post a fresh OTL log and advise how the computer is running now and if there are any outstanding issues
The PC itself is running fine now; no more false alerts, thank you. What is worrying though is that the contents of My Documents appears to be hidden. The folder itself can no longer be found under Documents and Settings. This was also the case with my external HD, which I disconnected at the start of this saga.
Please find the latest OTL log below :-

OTL logfile created on: 07/06/2011 05:10:20 - Run 10
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1022.07 Mb Total Physical Memory | 615.52 Mb Available Physical Memory | 60.22% Memory free
2.40 Gb Paging File | 2.18 Gb Available in Paging File | 90.71% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 109.82 Gb Free Space | 75.61% Space Free | Partition Type: NTFS

Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"


FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/31 17:15:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/31 17:15:28 | 000,000,000 | —D | M]

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/06/02 08:00:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | -H– | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/06/07 05:07:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/06/07 05:07:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/14 17:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2009/11/06 16:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2009/11/06 16:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/06 05:50:59 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Firefox Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Firefox Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/07 05:07:14 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/07 05:07:14 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/07 05:07:14 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/06 21:29:43 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Desktop\Excel
[2011/06/06 18:20:12 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/06/05 13:55:42 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/06/05 06:54:11 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/06/05 06:50:24 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/06/05 06:50:24 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/06/05 06:50:23 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/06/05 06:50:23 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/06/05 06:48:02 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/05 06:47:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Favorites
[2011/06/05 06:46:59 | 004,113,725 | R— | C] (Swearware) – C:\Documents and Settings\chic\Desktop\ComboFix.exe
[2011/06/04 22:42:17 | 000,589,632 | —- | C] (AVAST Software) – C:\Documents and Settings\chic\Desktop\aswMBR.exe
[2011/06/04 22:34:58 | 000,000,000 | —D | C] – C:\_OTL
[2011/06/03 08:16:19 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/06/03 05:58:51 | 000,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\beep.sys
[2011/06/03 05:55:56 | 000,000,000 | RH-D | C] – C:\Documents and Settings\chic\Recent
[2011/06/01 21:18:40 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\EverioBackup
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\WINDOWS\Cache
[2011/05/31 17:15:27 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/05/31 17:15:16 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\HpUpdate
[2011/05/31 17:14:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HP
[2011/05/31 17:14:21 | 001,761,128 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\HPScanMiniDrv_DJ1050_J410.dll
[2011/05/31 17:14:17 | 000,539,496 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911.dll
[2011/05/31 17:14:17 | 000,272,744 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911LM.dll
[2011/05/31 17:14:17 | 000,201,728 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinkcoi8911.dll
[2011/05/31 17:12:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP
[2011/05/31 17:12:18 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/05/31 17:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\HP
[2011/05/31 11:13:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/05/31 05:19:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Free YouTube Downloader
[2011/05/26 05:06:16 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/15 20:51:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ODBC
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Program Files\QuestScan
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/05/10 07:25:52 | 000,020,736 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lganddiag.sys
[2011/05/10 07:25:52 | 000,020,096 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgandgps.sys
[2011/05/10 06:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\LG PC Suite IV
[2011/05/08 15:55:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\My Music
[2011/05/08 15:52:22 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\iTunes
[2011/05/08 15:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/08 15:50:29 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/08 15:50:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/08 15:49:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/05/08 15:49:05 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/05/08 15:47:52 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/05/08 15:47:02 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/06/07 05:01:29 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/07 05:01:28 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/07 04:55:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/07 04:55:16 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/06/06 21:40:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/06/06 21:17:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/06 05:50:59 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/06/06 05:05:36 | 004,113,725 | R— | M] (Swearware) – C:\Documents and Settings\chic\Desktop\ComboFix.exe
[2011/06/05 11:40:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/06/05 06:54:17 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/06/04 22:42:11 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\chic\Desktop\aswMBR.exe
[2011/06/04 21:13:22 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/03 18:10:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/03 14:33:37 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/03 13:40:44 | 000,054,737 | —- | M] () – C:\Documents and Settings\chic\Desktop\GMcC-TB.jpg
[2011/06/03 08:22:24 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\Desktop\HiJackThis.exe
[2011/06/03 08:16:13 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/05/31 17:14:23 | 000,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 14:16:29 | 000,000,625 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | M] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | M] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/29 08:29:31 | 000,843,136 | -H– | M] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/29 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/05/28 08:55:55 | 000,112,952 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/10 10:59:49 | 000,002,413 | —- | M] () – C:\WINDOWS\System32\lgAxconfig.ini
[2011/05/09 23:09:37 | 000,000,742 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/09 23:09:37 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/08 15:51:13 | 000,001,452 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk

========== Files Created - No Company Name ==========

[2011/06/05 06:54:17 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/06/05 06:54:15 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/06/05 06:50:24 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/06/05 06:50:24 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/06/05 06:50:24 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/06/05 06:50:23 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/06/05 06:50:23 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/06/03 13:40:42 | 000,054,737 | —- | C] () – C:\Documents and Settings\chic\Desktop\GMcC-TB.jpg
[2011/06/03 05:57:10 | 1071,796,224 | -HS- | C] () – C:\hiberfil.sys
[2011/05/31 17:14:23 | 000,001,981 | —- | C] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | C] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 08:32:03 | 000,843,136 | -H– | C] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/28 08:55:55 | 000,112,952 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/08 15:51:13 | 000,001,452 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/08 15:47:55 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | -H– | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | -H– | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | -H– | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2005/05/17 18:17:52 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlcdcnv4.dll
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll

========== LOP Check ==========

[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/29 16:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/23 17:50:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2011/05/05 21:42:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/05/10 07:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/29 16:34:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/05/30 06:35:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2011/06/03 06:02:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/05/08 15:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/25 23:57:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2010/12/09 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2009/12/31 09:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/05/30 14:09:15 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/04/22 12:02:09 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2007/07/15 12:35:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\iWin
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2010/02/07 19:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Search Settings
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2010/12/31 21:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2011/06/04 16:46:19 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\uTorrent
[2009/03/24 21:02:57 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vghd
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B1CD2545

< End of report >
Please run the following:


Please download Unhide.exe to your desktop:
  • Double-click on the Unhide.exe icon on your desktop and allow the program to run.
  • This program will remove the hidden attributes from all the files on your system.
  • Note: If you had purposely hidden any files, then you will need to hide them again after this tool has run.


the external drive can be plugged in (don't open anything on it) while running unhide.exe, then run the ESET scan, just on that drive as well

let me know if that resolves the issue
Hi, The files on my HD and External are now both visible and the false alerts have desisted. The PC itself seems to be running normally. Is there anything else I need to do to tie ends up, as it were? If not, many thanks for all your patience and assistance. I will be making a donation through PayPal as some sort of remuneration for your efforts. Thank you again, Declan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI