This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unknown virus, internet provider suspending my account. Please help

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone,
My interent provider is suspending my account after every 3-4 days saying there is a virus in my laptop. I ran a malware bytes scan three times and found some viruses the first time.the second and third time I didn't find anything..yet they say my pc is infected. what do i do now..maybe my anti virus isnt catching the problem?

i am posting scan from OTL here:

OTL. Txt
————————

OTL logfile created on: 7/1/2011 10:20:10 AM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\SAIRA RASHID\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.37 Mb Total Physical Memory | 190.51 Mb Available Physical Memory | 37.92% Memory free
1.20 Gb Paging File | 0.67 Gb Available in Paging File | 55.85% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 0.84 Gb Free Space | 2.86% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 6.25 Gb Free Space | 31.98% Space Free | Partition Type: NTFS
Drive E: | 22.08 Gb Total Space | 4.23 Gb Free Space | 19.18% Space Free | Partition Type: NTFS
Drive F: | 3.98 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: SAIRA | User Name: SAIRA RASHID | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe (Rogers Cable Communications)
PRC - C:\Program Files\Rogers\SelfHealing\RogersSelfHelpService.exe (Rogers Cable Communications)
PRC - C:\Program Files\Rogers\SelfHealing\shs.exe (Rogers Cable Communications Inc.)
PRC - C:\WINDOWS\system32\SupportAppXL\AutoDect.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_e477fed.dll ()
SRV - (nlsX86cc) – C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
SRV - (RogersUpdateManager) – C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe (Rogers Cable Communications)
SRV - (RogersSelfHelpService) – C:\Program Files\Rogers\SelfHealing\RogersSelfHelpService.exe (Rogers Cable Communications)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (msvsmon80) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (massfilter) – C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech Webcam 120(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ncr"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:9.0.0.736
FF - prefs.js..extensions.enabledItems: [removed]:1.5.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: [removed]:2.4.4000

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/12 12:21:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 21:22:49 | 000,000,000 | —D | M]

[2010/01/26 18:33:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Extensions
[2011/05/28 16:24:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions
[2010/04/27 21:16:27 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/09 23:21:13 | 000,000,000 | —D | M] (Veoh Video Compass) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions\[removed]
[2011/05/28 16:24:42 | 000,000,000 | —D | M] (ALOT Toolbar) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions\[removed]
[2011/05/01 21:22:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/01 21:22:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2010/03/07 17:41:19 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
[2010/01/26 23:48:31 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/12 12:21:37 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Athan] C:\Program Files\Athan\Athan.exe (www.IslamicFinder.org)
O4 - HKLM..\Run: [autodetect] C:\WINDOWS\system32\SupportAppXL\AutoDect.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Rogers SHS] C:\Program Files\Rogers\SelfHealing\shs.exe (Rogers Cable Communications Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\SAIRA RASHID\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2010/01/26 17:20:25 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{09c723ba-0c0a-11df-9e8b-0016cfcfe671}\Shell - "" = AutoRun
O33 - MountPoints2\{09c723ba-0c0a-11df-9e8b-0016cfcfe671}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{09c723ba-0c0a-11df-9e8b-0016cfcfe671}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{37e91a8a-727d-11df-9f7b-0016cfcfe671}\Shell\AutoRun\command - "" = G:\wubi.exe –cdmenu
O33 - MountPoints2\{417080d6-f7e0-11df-a0ce-0016cfcfe671}\Shell - "" = AutoRun
O33 - MountPoints2\{417080d6-f7e0-11df-a0ce-0016cfcfe671}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{417080d6-f7e0-11df-a0ce-0016cfcfe671}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{a603c200-1444-11df-9ead-001a920e0462}\Shell - "" = AutoRun
O33 - MountPoints2\{a603c200-1444-11df-9ead-001a920e0462}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a603c200-1444-11df-9ead-001a920e0462}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{e22176ec-2e51-11e0-a13b-0016cfcfe671}\Shell - "" = AutoRun
O33 - MountPoints2\{e22176ec-2e51-11e0-a13b-0016cfcfe671}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e22176ec-2e51-11e0-a13b-0016cfcfe671}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{fa3533a0-6947-11e0-a1e6-001a920e0462}\Shell - "" = AutoRun
O33 - MountPoints2\{fa3533a0-6947-11e0-a1e6-001a920e0462}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{fa3533a0-6947-11e0-a1e6-001a920e0462}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: dhguzy - C:\WINDOWS\system32\tlcvoth.dll ()

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/07/01 10:18:20 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe
[2011/06/12 17:16:38 | 000,000,000 | —D | C] – C:\Documents and Settings\SAIRA RASHID\Desktop\Java
[2011/06/10 21:33:12 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/10 06:58:26 | 000,105,088 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\ZTEusbser6k.sys
[2011/06/10 06:58:26 | 000,105,088 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\ZTEusbnmea.sys
[2011/06/10 06:58:26 | 000,105,088 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\ZTEusbmdm6k.sys
[2011/06/10 06:58:26 | 000,009,216 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\massfilter.sys
[2011/06/10 06:58:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SupportAppXL
[2011/06/10 06:58:12 | 000,000,000 | —D | C] – C:\Program Files\Rogers Connection Manager
[2011/06/10 06:58:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Rogers Connection Manager
[2011/06/06 20:49:39 | 000,737,280 | —- | C] (Indigo Rose Corporation) – C:\WINDOWS\iun6002.exe
[2011/06/06 20:49:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Athan
[2011/06/06 20:49:35 | 000,000,000 | —D | C] – C:\WINDOWS\System32\athan
[2011/06/06 20:49:01 | 000,000,000 | —D | C] – C:\Program Files\Athan
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/01 10:21:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1016UA.job
[2011/07/01 10:12:42 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe
[2011/07/01 10:08:02 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1003UA.job
[2011/07/01 04:08:00 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1003Core.job
[2011/06/30 22:21:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1016Core.job
[2011/06/30 19:22:09 | 000,568,310 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/06/30 19:22:09 | 000,112,624 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/06/30 19:18:07 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/30 19:17:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/29 21:27:20 | 005,811,125 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\36620_Sheila Ki Jawani.mp3
[2011/06/29 08:11:19 | 000,002,337 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Google Chrome.lnk
[2011/06/29 08:11:19 | 000,002,315 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/26 00:44:48 | 002,031,863 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\DSC01473.JPG
[2011/06/26 00:39:05 | 000,006,952 | -HS- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Folder.jpg
[2011/06/26 00:39:05 | 000,002,006 | -HS- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\AlbumArtSmall.jpg
[2011/06/26 00:35:39 | 009,172,563 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom.mp3
[2011/06/26 00:33:49 | 006,093,300 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom Remix.mp3
[2011/06/25 15:56:58 | 001,287,909 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Saira Rashid G1 License.JPG
[2011/06/25 15:53:13 | 000,101,888 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/21 20:53:55 | 000,000,653 | —- | M] () – C:\Documents and Settings\All Users\Application Data\SHSupdates.xml
[2011/06/20 20:56:44 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/12 18:52:24 | 000,000,783 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\.drjava
[2011/06/10 21:33:12 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/10 06:58:24 | 000,001,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Rogers Connection Manager.lnk
[2011/06/07 22:57:55 | 003,750,641 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\bol02(www.songs.pk).mp3
[2011/06/07 22:35:56 | 005,814,208 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Kirkir Kirkir.mp3
[2011/06/06 20:49:39 | 000,001,492 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Athan.lnk
[2011/06/06 20:49:00 | 000,737,280 | —- | M] (Indigo Rose Corporation) – C:\WINDOWS\iun6002.exe
[2011/06/04 12:12:40 | 000,000,796 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Rogers SHS.lnk
[2011/06/03 22:26:54 | 002,205,064 | —- | M] () – C:\Documents and Settings\All Users\Application Data\shs_setup_4059-354328.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/29 21:27:20 | 005,811,125 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\36620_Sheila Ki Jawani.mp3
[2011/06/26 00:35:38 | 009,172,563 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom.mp3
[2011/06/26 00:33:46 | 006,093,300 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom Remix.mp3
[2011/06/25 15:56:56 | 001,287,909 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Saira Rashid G1 License.JPG
[2011/06/25 15:53:51 | 002,031,863 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\DSC01473.JPG
[2011/06/12 17:17:55 | 000,000,783 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\.drjava
[2011/06/10 06:58:12 | 000,001,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Rogers Connection Manager.lnk
[2011/06/07 22:54:32 | 003,750,641 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\bol02(www.songs.pk).mp3
[2011/06/07 22:32:38 | 005,814,208 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Kirkir Kirkir.mp3
[2011/06/06 20:49:39 | 000,001,492 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Athan.lnk
[2011/06/03 22:26:51 | 002,205,064 | —- | C] () – C:\Documents and Settings\All Users\Application Data\shs_setup_4059-354328.exe
[2011/06/03 22:26:28 | 000,000,653 | —- | C] () – C:\Documents and Settings\All Users\Application Data\SHSupdates.xml
[2011/05/27 08:40:50 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/25 23:14:18 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/06/25 17:16:44 | 000,000,318 | —- | C] () – C:\WINDOWS\WPE PRO.INI
[2010/05/26 18:27:52 | 000,000,025 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/03/15 12:00:49 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2010/03/15 12:00:49 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2010/03/15 12:00:29 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2010/03/15 12:00:28 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2010/03/15 12:00:26 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2010/01/30 19:17:56 | 000,101,888 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/28 10:12:33 | 000,000,114 | —- | C] () – C:\WINDOWS\tokdet5.dat
[2010/01/28 08:43:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/26 19:30:06 | 000,082,289 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/01/26 19:20:43 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/01/26 19:01:16 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\AegisI5Installer.exe
[2010/01/26 18:56:34 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4814.dll
[2010/01/26 18:33:37 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/01/26 18:03:49 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2010/01/26 18:03:48 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2010/01/26 18:03:48 | 000,018,944 | —- | C] () – C:\WINDOWS\System32\WLTRYSVC.EXE
[2010/01/26 17:23:51 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/01/26 17:16:47 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/01/26 15:27:49 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2010/01/26 12:06:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/01/26 12:05:26 | 000,269,392 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/16 18:27:58 | 000,508,224 | —- | C] () – C:\WINDOWS\System32\ICCProfiles.dll
[2008/04/14 08:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 08:00:00 | 000,568,310 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 08:00:00 | 000,167,018 | RHS- | C] () – C:\WINDOWS\System32\tlcvoth.dll
[2008/04/14 08:00:00 | 000,112,624 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 08:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/05/24 19:16:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2011/07/01 10:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Easybits GO
[2010/04/25 14:21:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010/08/14 21:46:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2011/04/10 18:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2010/04/25 14:27:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/05/26 17:31:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/08/29 23:02:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2011/06/30 19:22:47 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox
[2011/07/01 08:00:46 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\go
[2010/05/02 19:59:26 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\InfraRecorder
[2010/01/26 19:30:25 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Leadertech
[2011/05/28 16:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Logia
[2010/04/25 14:27:13 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\PC Suite
[2010/04/25 14:27:20 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Samsung
[2011/03/06 22:38:32 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\uPlayer
[2010/11/19 03:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\ZTEEVDO

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/01/26 17:20:25 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/13 22:05:05 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/01/26 17:20:25 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/01/26 17:20:25 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/01/26 17:20:25 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/30 19:17:44 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2011/03/06 19:33:50 | 000,005,887 | —- | M] () – C:\scramble.log
[2011/06/12 17:24:29 | 000,000,377 | —- | M] () – C:\test.txt
[2010/02/04 18:34:21 | 000,000,161 | —- | M] () – C:\wepkeys.txt

< %systemroot%\Fonts\*.com >
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/01/26 17:19:55 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/01/26 12:04:19 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/01/26 12:04:19 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/01/26 12:04:19 | 000,913,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/01/26 17:20:33 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/01/26 17:27:43 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\SAIRA RASHID\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/01/26 17:27:42 | 000,000,079 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/07/01 10:12:42 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-16 17:11:28

< End of report >




Extras.Txt

—————————-


OTL Extras logfile created on: 7/1/2011 10:20:10 AM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\SAIRA RASHID\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.37 Mb Total Physical Memory | 190.51 Mb Available Physical Memory | 37.92% Memory free
1.20 Gb Paging File | 0.67 Gb Available in Paging File | 55.85% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 0.84 Gb Free Space | 2.86% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 6.25 Gb Free Space | 31.98% Space Free | Partition Type: NTFS
Drive E: | 22.08 Gb Total Space | 4.23 Gb Free Space | 19.18% Space Free | Partition Type: NTFS
Drive F: | 3.98 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: SAIRA | User Name: SAIRA RASHID | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"4179:TCP" = 4179:TCP:*:Enabled:pukcik

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"G:\EC OLAH\App\haloce.exe" = G:\EC OLAH\App\haloce.exe:*:Disabled:Halo
"C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX0\haloce.exe" = C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX0\haloce.exe:*:Enabled:Halo – (Microsoft Corporation)
"C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX1\haloce.exe" = C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX1\haloce.exe:*:Disabled:Halo – (Microsoft Corporation)
"G:\USB\EC OLAH\App\haloce.exe" = G:\USB\EC OLAH\App\haloce.exe:*:Enabled:Halo
"C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX2\haloce.exe" = C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX2\haloce.exe:*:Enabled:Halo – (Microsoft Corporation)
"C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX3\haloce.exe" = C:\Documents and Settings\SAIRA RASHID\Local Settings\Temp\RarSFX3\haloce.exe:*:Disabled:Halo – (Microsoft Corporation)
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX0\haloce.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX0\haloce.exe:*:Enabled:Halo
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX1\haloce.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX1\haloce.exe:*:Enabled:Halo
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX2\haloce.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX2\haloce.exe:*:Disabled:Halo
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX3\haloce.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX3\haloce.exe:*:Disabled:Halo
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk
"C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX4\haloce.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX4\haloce.exe:*:Enabled:Halo
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX6\haloce.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX6\haloce.exe:*:Enabled:Halo
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX8\haloce.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX8\haloce.exe:*:Enabled:Halo
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX9\hl.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX9\hl.exe:*:Enabled:Half-Life Launcher
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX10\hl.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX10\hl.exe:*:Enabled:Half-Life Launcher
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX11\hl.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX11\hl.exe:*:Enabled:Half-Life Launcher
"C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX12\hl.exe" = C:\Documents and Settings\Kids\Local Settings\Temp\RarSFX12\hl.exe:*:Enabled:Half-Life Launcher
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player – (Veoh Networks)
"C:\Documents and Settings\Kids\Desktop\CE\App\haloce.exe" = C:\Documents and Settings\Kids\Desktop\CE\App\haloce.exe:*:Disabled:Halo – (Microsoft Corporation)
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\iCall\iCall.exe" = C:\Program Files\iCall\iCall.exe:*:Enabled:iCall
"C:\Documents and Settings\Kids\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Kids\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"G:\Pidgin\PidginPortable\App\Pidgin\pidgin-portable.exe" = G:\Pidgin\PidginPortable\App\Pidgin\pidgin-portable.exe:*:Enabled:Pidgin
"C:\Program Files\Java\jdk1.6.0_26\bin\javaw.exe" = C:\Program Files\Java\jdk1.6.0_26\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Java\jdk1.6.0_26\jre\bin\javaw.exe" = C:\Program Files\Java\jdk1.6.0_26\jre\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{053B3DA8-91B5-4682-A130-715412A1A252}" = Paint.NET v3.5.4
"{0B43A744-B1B8-4089-9BD1-9D41C7EC0AA3}" = Microsoft SQL Server 2005 Books Online (English)
"{14735B76-8B33-4DB9-A548-9918B7A2C41E}" = Microsoft Windows SDK for Windows Server 2008 Samples (6001.18000.367)
"{19AFC1C2-B11B-3FFF-9C9F-05761BC244D9}" = Windows SDK Intellidocs
"{1CBE3804-20DF-48DA-B048-895C206E80A5}" = Microsoft SQL Server VSS Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2373A92B-1C1C-4E71-B494-5CA97F96AA19}" = Microsoft SQL Server 2005
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 25
"{32A3A4F4-B792-11D6-A78A-00B0D0160260}" = Java™ SE Development Kit 6 Update 26
"{34610DE0-3C13-42CA-8E32-01FFA38AB6E8}" = PC Connectivity Solution
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37B03AA0-B125-4649-900C-F26E1081F163}" = Camtasia Studio 7
"{3A50302D-3AAC-4B5B-918A-5FDA9ABB0F44}" = Microsoft Windows SDK for Windows Server 2008 .NET Documentation (6001.18000.367)
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{44D9A2CB-0692-3180-B5E2-26F4E807D067}" = Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x86
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{503F62C9-99C2-376A-9B74-AB03E7CDB980}" = Google Talk Plugin
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C518CC0-5CF1-481B-AB35-9BE5024DC106}" = Microsoft Windows SDK MDAC Headers and Libraries (6001.18000.367)
"{6ED32BB5-56B6-4317-A2D1-98A8313C3BAF}" = Microsoft Windows SDK for Windows Server 2008 (6001.18000.367)
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C62A94B-4AB6-485F-A111-93056684D340}" = SQLXML4
"{8E5B3FDE-62E1-4391-BBA0-0E4242AD9577}" = Microsoft Windows SDK Net Fx Interop Headers And Libraries (6001.18000.367)
"{90032DD0-ABEE-4424-AC1E-B076BDD4E350}" = Microsoft SQL Server 2005 Tools
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}" = Rogers Connection Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96327C3C-96BE-4C7A-A6F7-A71635E5949A}" = Microsoft SQL Server 2005 Backward compatibility
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BAED673-5D51-481E-B1E0-FB2E5039260B}" = Microsoft Windows SDK Intellisense and Reference Assemblies (6001.18000.367)
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A431744A-553F-4FC0-AF91-BCA47C7E0949}" = Microsoft Windows SDK for Windows Server 2008 Headers and Libraries (6001.18000.367)
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{B46C272F-8B7A-402A-9915-8B0463F035DC}" = Microsoft Windows SDK for Windows Server 2008 Utilities for Win32 Development (6001.18000.367)
"{B67C01B3-8502-4BE7-AEAB-BBDE910AD3EE}" = Microsoft Web Platform Installer 2.0
"{B7EC89B3-2B8C-44A9-815C-135F391068B0}" = Microsoft Windows SDK for Windows Server 2008 Common Utilities (6001.18000.367)
"{BBCBA2A0-F0E5-4EA8-AAC0-CF1DC592221E}" = Microsoft VC Redist 2008 (6001.18000.367)
"{BF251EAF-8697-4E89-BF09-C998F97BBC40}" = Microsoft SQL Server Native Client
"{BF61D7A1-E894-4E3D-9129-B8D44B51FF94}" = Microsoft Windows SDK for Windows Server 2008 Win32 Documentation (6001.18000.367)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C25EF637-BE7A-4761-9B45-9069989C319F}" = Microsoft Visual Studio 2005 Premier Partner Edition - ENU
"{CD590618-36BD-0710-AC86-F3B3C4AF201E}" = Microsoft Windows SDK .NET Framework Tools
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF0EDB56-BBF6-3C9F-9C50-2E3B3D444641}" = Google Talk Plugin
"{D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}" = SAMSUNG SYMBIAN USB Download Driver
"{FF4D08B0-5098-4C4A-B801-42F3B1F9FE07}" = Microsoft Document Explorer 2008 (6001.18000.367)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Akamai" = Akamai NetSession Interface
"Athan" = Athan Basic 4.1
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"DVD Flick_is1" = DVD Flick 1.3.0.7
"HDMI" = Intel® Graphics Media Accelerator Driver
"InfraRecorder" = InfraRecorder
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.6.6 (Basic)
"lvdrivers_12.0" = Logitech Webcam Software Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"PROHYBRIDR" = 2007 Microsoft Office system
"QuicktimeAlt_is1" = QuickTime Alternative 3.2.2
"RealAlt_is1" = Real Alternative 2.0.2
"Rogers Self Help Software" = Rogers Self Help Software
"Rogers Update Manager" = Rogers Update Manager
"RSH Home Networking Wizard" = RSH Home Networking Wizard
"SDKSetup_6.0.6001.18000" = Microsoft Windows SDK for Windows Server 2008 (6001.18000.367)
"Speccy" = Speccy
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 6/30/2011 10:49:34 PM | Computer Name = SAIRA | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.10 for the Network Card with network
address 001A920E0462 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 7/1/2011 4:08:00 AM | Computer Name = SAIRA | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 7/1/2011 4:08:03 AM | Computer Name = SAIRA | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 7/1/2011 4:08:03 AM | Computer Name = SAIRA | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 7/1/2011 4:18:19 AM | Computer Name = SAIRA | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001A920E0462. The following
error occurred: %%121. Your computer will continue to try and obtain an address on
its own from the network address (DHCP) server.

Error - 7/1/2011 4:50:14 AM | Computer Name = SAIRA | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001A920E0462. The following
error occurred: %%121. Your computer will continue to try and obtain an address on
its own from the network address (DHCP) server.

Error - 7/1/2011 6:16:10 AM | Computer Name = SAIRA | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001A920E0462. The following
error occurred: %%121. Your computer will continue to try and obtain an address on
its own from the network address (DHCP) server.

Error - 7/1/2011 6:47:47 AM | Computer Name = SAIRA | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001A920E0462. The following
error occurred: %%121. Your computer will continue to try and obtain an address on
its own from the network address (DHCP) server.

Error - 7/1/2011 6:53:47 AM | Computer Name = SAIRA | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001A920E0462. The following
error occurred: %%121. Your computer will continue to try and obtain an address on
its own from the network address (DHCP) server.

Error - 7/1/2011 7:07:32 AM | Computer Name = SAIRA | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001A920E0462. The following
error occurred: %%121. Your computer will continue to try and obtain an address on
its own from the network address (DHCP) server.


< End of report >
OK a mystery I like them - does your ISP state what type of infection you have, or why they believe you are infected

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O2 - BHO: (no name) - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No CLSID value found.
    O33 - MountPoints2\{417080d6-f7e0-11df-a0ce-0016cfcfe671}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\{a603c200-1444-11df-9ead-001a920e0462}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\{09c723ba-0c0a-11df-9e8b-0016cfcfe671}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\{e22176ec-2e51-11e0-a13b-0016cfcfe671}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\{fa3533a0-6947-11e0-a1e6-001a920e0462}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    NetSvcs: dhguzy - C:\WINDOWS\system32\tlcvoth.dll ()

    :Services
    dhguzy

    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "4179:TCP"=-

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download aswMBR.exe ( 1.8mb ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
hello and thanks for your reply.
so I called rogers .. the service provider asking them about the virus..they said it was a botnet drone..don't kno what that means

here are the logs:

OTL:
—————————————————————



OTL logfile created on: 7/4/2011 9:46:01 PM - Run 2
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\SAIRA RASHID\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.37 Mb Total Physical Memory | 87.13 Mb Available Physical Memory | 17.34% Memory free
1.20 Gb Paging File | 0.77 Gb Available in Paging File | 64.65% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 6.04 Gb Free Space | 20.61% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 6.21 Gb Free Space | 31.82% Space Free | Partition Type: NTFS
Drive E: | 22.08 Gb Total Space | 4.20 Gb Free Space | 19.03% Space Free | Partition Type: NTFS
Drive F: | 3.98 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: SAIRA | User Name: SAIRA RASHID | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\Athan\Athan.exe (www.IslamicFinder.org)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe (Radialpoint Inc.)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
PRC - C:\Program Files\Rogers Online Protection\Rogers Online Protection\RPS.exe (Rogers)
PRC - C:\Program Files\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe (Rogers)
PRC - C:\Program Files\Rogers Online Protection\Rogers Online Protection\Fws.exe (Rogers)
PRC - C:\Program Files\Rogers Backup Manager\VaultClientUpgrade.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Rogers Backup Manager\VaultClientSRV.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe (Rogers Cable Communications)
PRC - C:\Program Files\Rogers\SelfHealing\RogersSelfHelpService.exe (Rogers Cable Communications)
PRC - C:\Program Files\Rogers\SelfHealing\shs.exe (Rogers Cable Communications Inc.)
PRC - C:\Program Files\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\SupportAppXL\AutoDect.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (scan) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\BitDefender\scan.dll (S.C. BitDefender S.R.L)
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_e477fed.dll ()
SRV - (nlsX86cc) – C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
SRV - (ServicepointService) – C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe (Radialpoint Inc.)
SRV - (Radialpoint Security Services) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe (Rogers)
SRV - (RP_FWS) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\Fws.exe (Rogers)
SRV - (VaultClientUpgrade) – C:\Program Files\Rogers Backup Manager\VaultClientUpgrade.exe (Radialpoint SafeCare Inc.)
SRV - (VaultClientSRV) – C:\Program Files\Rogers Backup Manager\VaultClientSRV.exe (Radialpoint SafeCare Inc.)
SRV - (RogersUpdateManager) – C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe (Rogers Cable Communications)
SRV - (RogersSelfHelpService) – C:\Program Files\Rogers\SelfHealing\RogersSelfHelpService.exe (Rogers Cable Communications)
SRV - (RadialpointIDSAgent) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (PDEngine) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV - (PDAgent) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (msvsmon80) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) – C:\WINDOWS\system32\drivers\rp_skt32.sys (Radialpoint Inc.)
DRV - (Trufos) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\BitDefender\trufos.sys (BitDefender S.R.L.)
DRV - (Profos) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\BitDefender\profos.sys (BitDefender S.R.L.)
DRV - (RadialpointIDSDriver) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys (AVG Technologies )
DRV - (RadialpointIDSFilter) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys (AVG Technologies )
DRV - (RadialpointIDSShim) – C:\Program Files\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\drivers\AVGIDSShim.sys (AVG Technologies )
DRV - (RadialpointIDSEH) – C:\WINDOWS\system32\drivers\AVGIDSEH.sys (AVG Technologies )
DRV - (bdfsfltr) – C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (massfilter) – C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (DefragFS) – C:\WINDOWS\System32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech Webcam 120(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ncr"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:9.0.0.736
FF - prefs.js..extensions.enabledItems: [removed]:1.5.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: [removed]:2.4.4000

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/12 12:21:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 21:22:49 | 000,000,000 | —D | M]

[2010/01/26 18:33:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Extensions
[2011/05/28 16:24:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions
[2010/04/27 21:16:27 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/09 23:21:13 | 000,000,000 | —D | M] (Veoh Video Compass) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions\[removed]
[2011/05/28 16:24:42 | 000,000,000 | —D | M] (ALOT Toolbar) – C:\Documents and Settings\SAIRA RASHID\Application Data\Mozilla\Firefox\Profiles\h391rg2z.default\extensions\[removed]
[2011/05/01 21:22:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/01 21:22:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2010/03/07 17:41:19 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
[2010/01/26 23:48:31 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/12 12:21:37 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/07/04 21:37:06 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Athan] C:\Program Files\Athan\Athan.exe (www.IslamicFinder.org)
O4 - HKLM..\Run: [autodetect] C:\WINDOWS\system32\SupportAppXL\AutoDect.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Rogers SHS] C:\Program Files\Rogers\SelfHealing\shs.exe (Rogers Cable Communications Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\SAIRA RASHID\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2010/01/26 17:20:25 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{37e91a8a-727d-11df-9f7b-0016cfcfe671}\Shell\AutoRun\command - "" = G:\wubi.exe –cdmenu
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/04 21:35:21 | 000,000,000 | —D | C] – C:\_OTL
[2011/07/02 09:30:55 | 000,000,000 | —D | C] – C:\Documents and Settings\SAIRA RASHID\Desktop\New Folder (2)
[2011/07/01 13:19:08 | 000,025,608 | —- | C] (AVG Technologies ) – C:\WINDOWS\System32\drivers\AVGIDSEH.sys
[2011/07/01 13:18:51 | 000,000,000 | —D | C] – C:\Program Files\Rogers Backup Manager
[2011/07/01 13:17:52 | 000,285,704 | —- | C] (BitDefender S.R.L. Bucharest, ROMANIA) – C:\WINDOWS\System32\drivers\bdfsfltr.sys
[2011/07/01 13:17:42 | 000,053,192 | —- | C] (Radialpoint Inc.) – C:\WINDOWS\System32\drivers\rp_skt32.sys
[2011/07/01 13:16:37 | 000,000,000 | —D | C] – C:\Program Files\Raxco
[2011/07/01 13:16:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Raxco
[2011/07/01 13:15:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Rogers Online Protection
[2011/07/01 12:55:28 | 000,000,000 | —D | C] – C:\Documents and Settings\SAIRA RASHID\Application Data\Rogers Online Protection
[2011/07/01 12:55:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Radialpoint
[2011/07/01 12:55:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Rogers Servicepoint Agent
[2011/07/01 12:55:10 | 000,000,000 | —D | C] – C:\Program Files\Rogers Online Protection
[2011/07/01 12:55:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Rogers Online Protection
[2011/07/01 10:18:20 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe
[2011/06/12 17:16:38 | 000,000,000 | —D | C] – C:\Documents and Settings\SAIRA RASHID\Desktop\Java
[2011/06/10 06:58:26 | 000,105,088 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\ZTEusbser6k.sys
[2011/06/10 06:58:26 | 000,105,088 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\ZTEusbnmea.sys
[2011/06/10 06:58:26 | 000,105,088 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\ZTEusbmdm6k.sys
[2011/06/10 06:58:26 | 000,009,216 | —- | C] (ZTE Incorporated) – C:\WINDOWS\System32\drivers\massfilter.sys
[2011/06/10 06:58:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SupportAppXL
[2011/06/10 06:58:12 | 000,000,000 | —D | C] – C:\Program Files\Rogers Connection Manager
[2011/06/10 06:58:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Rogers Connection Manager
[2011/06/06 20:49:39 | 000,737,280 | —- | C] (Indigo Rose Corporation) – C:\WINDOWS\iun6002.exe
[2011/06/06 20:49:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Athan
[2011/06/06 20:49:35 | 000,000,000 | —D | C] – C:\WINDOWS\System32\athan
[2011/06/06 20:49:01 | 000,000,000 | —D | C] – C:\Program Files\Athan

========== Files - Modified Within 30 Days ==========

[2011/07/04 21:46:38 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/04 21:46:33 | 000,001,893 | —- | M] () – C:\WINDOWS\bcmwltrytmp.reg
[2011/07/04 21:43:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/04 21:37:06 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/07/04 21:21:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1016UA.job
[2011/07/04 21:08:13 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1003UA.job
[2011/07/03 22:21:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1016Core.job
[2011/07/03 04:08:08 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-2146840571-1417001333-1003Core.job
[2011/07/03 00:00:40 | 000,568,310 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/03 00:00:39 | 000,112,624 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/02 09:32:17 | 000,103,936 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/01 13:17:42 | 000,053,192 | —- | M] (Radialpoint Inc.) – C:\WINDOWS\System32\drivers\rp_skt32.sys
[2011/07/01 13:15:45 | 000,001,998 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Rogers Online Protection.lnk
[2011/07/01 10:12:42 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\SAIRA RASHID\Desktop\OTL.exe
[2011/06/29 21:27:20 | 005,811,125 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\36620_Sheila Ki Jawani.mp3
[2011/06/29 08:11:19 | 000,002,337 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Google Chrome.lnk
[2011/06/29 08:11:19 | 000,002,315 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/26 00:44:48 | 002,031,863 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\DSC01473.JPG
[2011/06/26 00:39:05 | 000,006,952 | -HS- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Folder.jpg
[2011/06/26 00:39:05 | 000,002,006 | -HS- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\AlbumArtSmall.jpg
[2011/06/26 00:35:39 | 009,172,563 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom.mp3
[2011/06/26 00:33:49 | 006,093,300 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom Remix.mp3
[2011/06/25 15:56:58 | 001,287,909 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Saira Rashid G1 License.JPG
[2011/06/21 20:53:55 | 000,000,653 | —- | M] () – C:\Documents and Settings\All Users\Application Data\SHSupdates.xml
[2011/06/20 20:56:44 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/12 18:52:24 | 000,000,783 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\.drjava
[2011/06/10 06:58:24 | 000,001,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Rogers Connection Manager.lnk
[2011/06/07 22:57:55 | 003,750,641 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\bol02(www.songs.pk).mp3
[2011/06/07 22:35:56 | 005,814,208 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Kirkir Kirkir.mp3
[2011/06/06 20:49:39 | 000,001,492 | —- | M] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Athan.lnk
[2011/06/06 20:49:00 | 000,737,280 | —- | M] (Indigo Rose Corporation) – C:\WINDOWS\iun6002.exe

========== Files Created - No Company Name ==========

[2011/07/02 23:56:58 | 000,001,893 | —- | C] () – C:\WINDOWS\bcmwltrytmp.reg
[2011/07/01 13:15:45 | 000,001,998 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Rogers Online Protection.lnk
[2011/06/29 21:27:20 | 005,811,125 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\36620_Sheila Ki Jawani.mp3
[2011/06/26 00:35:38 | 009,172,563 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom.mp3
[2011/06/26 00:33:46 | 006,093,300 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Ali Zafar Jhoom Remix.mp3
[2011/06/25 15:56:56 | 001,287,909 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Saira Rashid G1 License.JPG
[2011/06/25 15:53:51 | 002,031,863 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\DSC01473.JPG
[2011/06/12 17:17:55 | 000,000,783 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\.drjava
[2011/06/10 06:58:12 | 000,001,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Rogers Connection Manager.lnk
[2011/06/07 22:54:32 | 003,750,641 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\bol02(www.songs.pk).mp3
[2011/06/07 22:32:38 | 005,814,208 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Kirkir Kirkir.mp3
[2011/06/06 20:49:39 | 000,001,492 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Desktop\Athan.lnk
[2011/06/03 22:26:51 | 002,205,064 | —- | C] () – C:\Documents and Settings\All Users\Application Data\shs_setup_4059-354328.exe
[2011/06/03 22:26:28 | 000,000,653 | —- | C] () – C:\Documents and Settings\All Users\Application Data\SHSupdates.xml
[2011/05/27 08:40:50 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/25 23:14:18 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/06/25 17:16:44 | 000,000,318 | —- | C] () – C:\WINDOWS\WPE PRO.INI
[2010/05/26 18:27:52 | 000,000,025 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/03/15 12:00:49 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2010/03/15 12:00:49 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2010/03/15 12:00:29 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2010/03/15 12:00:28 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2010/03/15 12:00:26 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2010/01/30 19:17:56 | 000,103,936 | —- | C] () – C:\Documents and Settings\SAIRA RASHID\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/28 10:12:33 | 000,000,114 | —- | C] () – C:\WINDOWS\tokdet5.dat
[2010/01/28 08:43:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/26 19:30:06 | 000,082,289 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/01/26 19:20:43 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/01/26 19:01:16 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\AegisI5Installer.exe
[2010/01/26 18:56:34 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4814.dll
[2010/01/26 18:33:37 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/01/26 18:03:49 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2010/01/26 18:03:48 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2010/01/26 18:03:48 | 000,018,944 | —- | C] () – C:\WINDOWS\System32\WLTRYSVC.EXE
[2010/01/26 17:23:51 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/01/26 17:16:47 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/01/26 15:27:49 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2010/01/26 12:06:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/01/26 12:05:26 | 000,269,392 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/21 14:20:08 | 000,005,504 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen_x86.sys
[2009/09/16 18:27:58 | 000,508,224 | —- | C] () – C:\WINDOWS\System32\ICCProfiles.dll
[2008/04/14 08:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 08:00:00 | 000,568,310 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 08:00:00 | 000,112,624 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 08:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/05/24 19:16:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2011/07/04 21:35:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Easybits GO
[2010/04/25 14:21:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010/08/14 21:46:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2011/04/10 18:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2010/04/25 14:27:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/05/26 17:31:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/07/01 12:55:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radialpoint
[2011/07/01 13:12:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rogers Online Protection
[2010/08/29 23:02:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2011/07/04 06:27:11 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Dropbox
[2011/07/04 21:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\go
[2010/05/02 19:59:26 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\InfraRecorder
[2010/01/26 19:30:25 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Leadertech
[2011/05/28 16:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Logia
[2010/04/25 14:27:13 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\PC Suite
[2011/07/01 14:36:58 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Rogers Online Protection
[2010/04/25 14:27:20 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\Samsung
[2011/03/06 22:38:32 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\uPlayer
[2010/11/19 03:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\SAIRA RASHID\Application Data\ZTEEVDO

========== Purity Check ==========



< End of report >





————————————————————————————–
——————————————————————————————-


aswMBR Log:

——————————————————-




aswMBR version 0.9.7.675 Copyright© 2011 AVAST Software
Run date: 2011-07-04 22:02:24
—————————–
22:02:24.937 OS Version: Windows 5.1.2600 Service Pack 3
22:02:24.937 Number of processors: 2 586 0xE08
22:02:24.937 ComputerName: SAIRA UserName:
22:02:30.671 Initialize success
22:03:11.609 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
22:03:11.609 Disk 0 Vendor: FUJITSU_MHW2080BH 00850012 Size: 76319MB BusType: 3
22:03:13.640 Disk 0 MBR read successfully
22:03:13.656 Disk 0 MBR scan
22:03:13.656 Disk 0 Windows XP default MBR code
22:03:15.656 Disk 0 scanning sectors +148794030
22:03:15.703 Disk 0 scanning C:\WINDOWS\system32\drivers
22:03:25.234 Service scanning
22:03:27.468 Disk 0 trace - called modules:
22:03:27.500 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
22:03:27.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x829d3ab8]
22:03:27.500 3 CLASSPNP.SYS[f8514fd7] -> nt!IofCallDriver -> \Device\00000071[0x829d6f18]
22:03:27.500 5 ACPI.sys[f838b620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82977300]
22:03:27.500 Scan finished successfully
22:03:59.750 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\SAIRA RASHID\Desktop\MBR.dat"
22:03:59.812 The log file has been saved successfully to "C:\Documents and Settings\SAIRA RASHID\Desktop\aswMBR.txt"




thanks for all your help!!
OK nothing visible there so lets up the ante

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI