This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search redirects. Hijackthis log + startuplist

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I think this is where my Hijack logs go:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:54:41 PM, on 7/10/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\RarSFX1\AutoInstallEJCDSVC.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\RarSFX1\AutoEJCD.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\0.32712949222944365.exe
C:\Documents and Settings\Sylvia\Application Data\dwm.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\csrss.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:61697
F3 - REG:win.ini: load=C:\DOCUME~1\Sylvia\LOCALS~1\Temp\csrss.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Qwest 11n Wireless WPS Tool] C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [conhost] C:\Documents and Settings\Sylvia\Application Data\Microsoft\conhost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Documents and Settings\Sylvia\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Documents and Settings\Sylvia\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra button: Lock Poker - {7000ccff-ab59-4eab-a7ae-a502e91a89e8} - C:\Documents and Settings\Sylvia\Start Menu\Programs\Lock Poker\Lock Poker.lnk (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Auto Install Eject CD Service (AutoInstallEJCD) - Unknown owner - C:\DOCUME~1\Sylvia\LOCALS~1\Temp\RarSFX1\AutoInstallEJCDSVC.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O24 - Desktop Component 0: (no name) - http://image50.webshots.com/50/4/37/85/456…85ZEPNKD_ph.jpg

–
End of file - 5676 bytes

StartupList report, 7/10/2011, 9:54:52 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HiJackThis\HiJackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v8.00 (8.00.6001.18702)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\RarSFX1\AutoInstallEJCDSVC.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\RarSFX1\AutoEJCD.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\0.32712949222944365.exe
C:\Documents and Settings\Sylvia\Application Data\dwm.exe
C:\DOCUME~1\Sylvia\LOCALS~1\Temp\csrss.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

AVG9_TRAY = C:\PROGRA~1\AVG\AVG9\avgtray.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
SunJavaUpdateSched = "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
DivXUpdate = "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
Qwest 11n Wireless WPS Tool = C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM = "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
conhost = C:\Documents and Settings\Sylvia\Application Data\Microsoft\conhost.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=C:\DOCUME~1\Sylvia\LOCALS~1\Temp\csrss.exe
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG9\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
(no name) - (no file) - {9D425283-D487-4337-BAB6-AB8354A81457}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}

————————————————–

Enumerating Download Program Files:

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10e.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\Sylvia\LOCALS~1\Temp\~nsu.tmp\Au_.exe||C:\DOCUME~1\Sylvia\LOCALS~1\Temp\~nsu.tmp


————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

————————————————–
End of report, 7,069 bytes
Report generated in 0.040 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

Please help and thanks! -AgentCaviar
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)










  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Here are the 3 logs: TDSSKILLER: 2011/07/11 05:29:40.0206 2592 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21 2011/07/11 05:29:40.0266 2592 ================================================================================ 2011/07/11 05:29:40.0266 2592 SystemInfo: 2011/07/11 05:29:40.0266 2592 2011/07/11 05:29:40.0266 2592 OS Version: 5.1.2600 ServicePack: 2.0 2011/07/11 05:29:40.0266 2592 Product type: Workstation 2011/07/11 05:29:40.0266 2592 ComputerName: SYLVIASPC 2011/07/11 05:29:40.0266 2592 UserName: Sylvia 2011/07/11 05:29:40.0266 2592 Windows directory: C:\WINDOWS 2011/07/11 05:29:40.0266 2592 System windows directory: C:\WINDOWS 2011/07/11 05:29:40.0266 2592 Processor architecture: Intel x86 2011/07/11 05:29:40.0266 2592 Number of processors: 1 2011/07/11 05:29:40.0266 2592 Page size: 0x1000 2011/07/11 05:29:40.0266 2592 Boot type: Normal boot 2011/07/11 05:29:40.0266 2592 ================================================================================ 2011/07/11 05:29:43.0470 2592 Initialize success 2011/07/11 05:29:56.0699 3384 ================================================================================ 2011/07/11 05:29:56.0699 3384 Scan started 2011/07/11 05:29:56.0699 3384 Mode: Manual; 2011/07/11 05:29:56.0699 3384 ================================================================================ 2011/07/11 05:29:58.0642 3384 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/07/11 05:29:58.0973 3384 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/07/11 05:29:59.0513 3384 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 2011/07/11 05:29:59.0904 3384 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 2011/07/11 05:30:00.0274 3384 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys 2011/07/11 05:30:02.0317 3384 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/07/11 05:30:02.0598 3384 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/07/11 05:30:03.0058 3384 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/07/11 05:30:03.0359 3384 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/07/11 05:30:03.0729 3384 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\System32\Drivers\avgldx86.sys 2011/07/11 05:30:04.0080 3384 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\WINDOWS\System32\Drivers\avgmfx86.sys 2011/07/11 05:30:04.0440 3384 AvgTdiX (9a7a93388f503a34e7339ae7f9997449) C:\WINDOWS\System32\Drivers\avgtdix.sys 2011/07/11 05:30:04.0781 3384 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/07/11 05:30:05.0061 3384 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/07/11 05:30:05.0492 3384 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/07/11 05:30:05.0792 3384 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/07/11 05:30:06.0083 3384 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/07/11 05:30:06.0343 3384 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 2011/07/11 05:30:07.0335 3384 ctljystk (71007bd2e1e26927fe3e4eb00c0beedf) C:\WINDOWS\system32\DRIVERS\ctljystk.sys 2011/07/11 05:30:08.0136 3384 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/07/11 05:30:08.0747 3384 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 2011/07/11 05:30:09.0448 3384 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 2011/07/11 05:30:09.0768 3384 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/07/11 05:30:10.0068 3384 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2011/07/11 05:30:10.0529 3384 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/07/11 05:30:10.0880 3384 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys 2011/07/11 05:30:11.0260 3384 emu10k (01f83e1b5dce05f5cb7d99113ca9e890) C:\WINDOWS\system32\drivers\emu10k1m.sys 2011/07/11 05:30:11.0691 3384 emu10k1 (7ffa171cce6a8bfc774862a578ba39a2) C:\WINDOWS\system32\drivers\ctlfacem.sys 2011/07/11 05:30:12.0051 3384 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/07/11 05:30:12.0412 3384 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/07/11 05:30:12.0682 3384 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 2011/07/11 05:30:12.0933 3384 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/07/11 05:30:13.0233 3384 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2011/07/11 05:30:13.0574 3384 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/07/11 05:30:13.0894 3384 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/07/11 05:30:14.0164 3384 gameenum (5f92fd09e5610a5995da7d775eadcd12) C:\WINDOWS\system32\DRIVERS\gameenum.sys 2011/07/11 05:30:14.0435 3384 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/07/11 05:30:15.0006 3384 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/07/11 05:30:15.0807 3384 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/07/11 05:30:16.0177 3384 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/07/11 05:30:16.0718 3384 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/07/11 05:30:17.0018 3384 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2011/07/11 05:30:17.0349 3384 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/07/11 05:30:17.0629 3384 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/07/11 05:30:17.0920 3384 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/07/11 05:30:18.0250 3384 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/07/11 05:30:18.0601 3384 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/07/11 05:30:19.0001 3384 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/07/11 05:30:19.0262 3384 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/07/11 05:30:19.0592 3384 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 2011/07/11 05:30:19.0943 3384 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/07/11 05:30:20.0473 3384 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/07/11 05:30:20.0734 3384 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 2011/07/11 05:30:21.0425 3384 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/07/11 05:30:21.0865 3384 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/07/11 05:30:22.0356 3384 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/07/11 05:30:22.0847 3384 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/07/11 05:30:23.0338 3384 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2011/07/11 05:30:23.0668 3384 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/07/11 05:30:23.0938 3384 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/07/11 05:30:24.0199 3384 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/07/11 05:30:24.0489 3384 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/07/11 05:30:24.0790 3384 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2011/07/11 05:30:25.0120 3384 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2011/07/11 05:30:25.0421 3384 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/07/11 05:30:25.0741 3384 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/07/11 05:30:26.0061 3384 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/07/11 05:30:26.0362 3384 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/07/11 05:30:26.0652 3384 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/07/11 05:30:27.0053 3384 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/07/11 05:30:27.0453 3384 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2011/07/11 05:30:28.0014 3384 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/07/11 05:30:28.0465 3384 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/07/11 05:30:29.0386 3384 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/07/11 05:30:30.0348 3384 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/07/11 05:30:30.0598 3384 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/07/11 05:30:30.0918 3384 NwlnkIpx (79ea3fcda7067977625b3363a2657c80) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys 2011/07/11 05:30:31.0209 3384 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys 2011/07/11 05:30:31.0469 3384 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys 2011/07/11 05:30:31.0920 3384 NWRDR (03373a79440473062c6f3aedec6a49c8) C:\WINDOWS\system32\DRIVERS\nwrdr.sys 2011/07/11 05:30:32.0300 3384 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/07/11 05:30:32.0591 3384 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/07/11 05:30:32.0831 3384 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/07/11 05:30:33.0082 3384 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/07/11 05:30:33.0763 3384 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/07/11 05:30:35.0255 3384 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/07/11 05:30:35.0515 3384 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/07/11 05:30:35.0805 3384 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/07/11 05:30:36.0076 3384 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/07/11 05:30:36.0346 3384 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/07/11 05:30:37.0728 3384 QWXN720 (93ea7d94959bef66d0e4adbc8ce4e073) C:\WINDOWS\system32\DRIVERS\WLANUHN.sys 2011/07/11 05:30:38.0269 3384 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/07/11 05:30:38.0519 3384 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/07/11 05:30:38.0790 3384 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/07/11 05:30:39.0100 3384 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/07/11 05:30:39.0441 3384 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/07/11 05:30:39.0771 3384 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/07/11 05:30:40.0142 3384 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/07/11 05:30:40.0522 3384 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/07/11 05:30:40.0903 3384 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/07/11 05:30:41.0303 3384 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/07/11 05:30:41.0574 3384 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/07/11 05:30:41.0854 3384 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/07/11 05:30:42.0135 3384 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/07/11 05:30:42.0395 3384 sfman (0b1a5e9cacb5cdd54a2815107bd7c772) C:\WINDOWS\system32\drivers\sfmanm.sys 2011/07/11 05:30:43.0106 3384 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 2011/07/11 05:30:43.0396 3384 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/07/11 05:30:43.0807 3384 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/07/11 05:30:44.0218 3384 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/07/11 05:30:44.0488 3384 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2011/07/11 05:30:45.0529 3384 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/07/11 05:30:45.0960 3384 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/07/11 05:30:46.0381 3384 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/07/11 05:30:46.0661 3384 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/07/11 05:30:47.0052 3384 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/07/11 05:30:47.0612 3384 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2011/07/11 05:30:48.0223 3384 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 2011/07/11 05:30:48.0544 3384 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/07/11 05:30:48.0844 3384 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/07/11 05:30:49.0115 3384 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/07/11 05:30:49.0385 3384 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/07/11 05:30:49.0645 3384 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2011/07/11 05:30:50.0116 3384 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/07/11 05:30:50.0416 3384 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/07/11 05:30:50.0897 3384 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/07/11 05:30:51.0378 3384 ZDCNDIS5 (ea93196f0c92c1d9495966ca70fe1ed6) C:\WINDOWS\system32\ZDCNDIS5.sys 2011/07/11 05:30:51.0538 3384 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 2011/07/11 05:30:51.0919 3384 Boot (0x1200) (053b963a350cf3775435306afacf8fa3) \Device\Harddisk0\DR0\Partition0 2011/07/11 05:30:51.0949 3384 ================================================================================ 2011/07/11 05:30:51.0949 3384 Scan finished 2011/07/11 05:30:51.0949 3384 ================================================================================ 2011/07/11 05:30:51.0999 2780 Detected object count: 0 2011/07/11 05:30:51.0999 2780 Actual detected object count: 0 OTL txt: netsvcs drivers32 %SYSTEMDRIVE%\*.* %systemroot%\Fonts\*.com %systemroot%\Fonts\*.dll %systemroot%\Fonts\*.ini %systemroot%\Fonts\*.ini2 %systemroot%\Fonts\*.exe %systemroot%\system32\spool\prtprocs\w32x86\*.* %systemroot%\REPAIR\*.bak1 %systemroot%\REPAIR\*.ini %systemroot%\system32\*.jpg %systemroot%\*.jpg %systemroot%\*.png %systemroot%\*.scr %systemroot%\*._sy %APPDATA%\Adobe\Update\*.* %ALLUSERSPROFILE%\Favorites\*.* %APPDATA%\Microsoft\*.* %PROGRAMFILES%\*.* %APPDATA%\Update\*.* %systemroot%\*. /mp /s CREATERESTOREPOINT %systemroot%\System32\config\*.sav %PROGRAMFILES%\bak. /s %systemroot%\system32\bak. /s %ALLUSERSPROFILE%\Start Menu\*.lnk /x %systemroot%\system32\config\systemprofile\*.dat /x %systemroot%\*.config %systemroot%\system32\*.db %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x %USERPROFILE%\Desktop\*.exe %PROGRAMFILES%\Common Files\*.* %systemroot%\*.src %systemroot%\install\*.* %systemroot%\system32\DLL\*.* %systemroot%\system32\HelpFiles\*.* %systemroot%\system32\rundll\*.* %systemroot%\winn32\*.* %systemroot%\Java\*.* %systemroot%\system32\test\*.* %systemroot%\system32\Rundll32\*.* %systemroot%\AppPatch\Custom\*.* %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x %PROGRAMFILES%\PC-Doctor\Downloads\*.* %PROGRAMFILES%\Internet Explorer\*.tmp %PROGRAMFILES%\Internet Explorer\*.dat %USERPROFILE%\My Documents\*.exe %USERPROFILE%\*.exe %systemroot%\ADDINS\*.* %systemroot%\assembly\*.bak2 %systemroot%\Config\*.* %systemroot%\REPAIR\*.bak2 %systemroot%\SECURITY\Database\*.sdb /x %systemroot%\SYSTEM\*.bak2 %systemroot%\Web\*.bak2 %systemroot%\Driver Cache\*.* %PROGRAMFILES%\Mozilla Firefox\0*.exe %ProgramFiles%\Microsoft Common\*.* %ProgramFiles%\TinyProxy. %USERPROFILE%\Favorites\*.url /x %systemroot%\system32\*.bk %systemroot%\*.te %systemroot%\system32\system32\*.* %ALLUSERSPROFILE%\*.dat /x %systemroot%\system32\drivers\*.rmv dir /b "%systemroot%\system32\*.exe" | find /i " " /c dir /b "%systemroot%\*.exe" | find /i " " /c %PROGRAMFILES%\Microsoft\*.* %systemroot%\System32\Wbem\proquota.exe %PROGRAMFILES%\Mozilla Firefox\*.dat %USERPROFILE%\Cookies\*.txt /x %SystemRoot%\system32\fonts\*.* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs EXTRAS txt: netsvcs drivers32 %SYSTEMDRIVE%\*.* %systemroot%\Fonts\*.com %systemroot%\Fonts\*.dll %systemroot%\Fonts\*.ini %systemroot%\Fonts\*.ini2 %systemroot%\Fonts\*.exe %systemroot%\system32\spool\prtprocs\w32x86\*.* %systemroot%\REPAIR\*.bak1 %systemroot%\REPAIR\*.ini %systemroot%\system32\*.jpg %systemroot%\*.jpg %systemroot%\*.png %systemroot%\*.scr %systemroot%\*._sy %APPDATA%\Adobe\Update\*.* %ALLUSERSPROFILE%\Favorites\*.* %APPDATA%\Microsoft\*.* %PROGRAMFILES%\*.* %APPDATA%\Update\*.* %systemroot%\*. /mp /s CREATERESTOREPOINT %systemroot%\System32\config\*.sav %PROGRAMFILES%\bak. /s %systemroot%\system32\bak. /s %ALLUSERSPROFILE%\Start Menu\*.lnk /x %systemroot%\system32\config\systemprofile\*.dat /x %systemroot%\*.config %systemroot%\system32\*.db %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x %USERPROFILE%\Desktop\*.exe %PROGRAMFILES%\Common Files\*.* %systemroot%\*.src %systemroot%\install\*.* %systemroot%\system32\DLL\*.* %systemroot%\system32\HelpFiles\*.* %systemroot%\system32\rundll\*.* %systemroot%\winn32\*.* %systemroot%\Java\*.* %systemroot%\system32\test\*.* %systemroot%\system32\Rundll32\*.* %systemroot%\AppPatch\Custom\*.* %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x %PROGRAMFILES%\PC-Doctor\Downloads\*.* %PROGRAMFILES%\Internet Explorer\*.tmp %PROGRAMFILES%\Internet Explorer\*.dat %USERPROFILE%\My Documents\*.exe %USERPROFILE%\*.exe %systemroot%\ADDINS\*.* %systemroot%\assembly\*.bak2 %systemroot%\Config\*.* %systemroot%\REPAIR\*.bak2 %systemroot%\SECURITY\Database\*.sdb /x %systemroot%\SYSTEM\*.bak2 %systemroot%\Web\*.bak2 %systemroot%\Driver Cache\*.* %PROGRAMFILES%\Mozilla Firefox\0*.exe %ProgramFiles%\Microsoft Common\*.* %ProgramFiles%\TinyProxy. %USERPROFILE%\Favorites\*.url /x %systemroot%\system32\*.bk %systemroot%\*.te %systemroot%\system32\system32\*.* %ALLUSERSPROFILE%\*.dat /x %systemroot%\system32\drivers\*.rmv dir /b "%systemroot%\system32\*.exe" | find /i " " /c dir /b "%systemroot%\*.exe" | find /i " " /c %PROGRAMFILES%\Microsoft\*.* %systemroot%\System32\Wbem\proquota.exe %PROGRAMFILES%\Mozilla Firefox\*.dat %USERPROFILE%\Cookies\*.txt /x %SystemRoot%\system32\fonts\*.* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
The OTL scan was not done right,you need to copy/paste the text below into the custom scan/fixes box and click run scan


netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
2nd attempt OTL log: netsvcs drivers32 %SYSTEMDRIVE%\*.* %systemroot%\Fonts\*.com %systemroot%\Fonts\*.dll %systemroot%\Fonts\*.ini %systemroot%\Fonts\*.ini2 %systemroot%\Fonts\*.exe %systemroot%\system32\spool\prtprocs\w32x86\*.* %systemroot%\REPAIR\*.bak1 %systemroot%\REPAIR\*.ini %systemroot%\system32\*.jpg %systemroot%\*.jpg %systemroot%\*.png %systemroot%\*.scr %systemroot%\*._sy %APPDATA%\Adobe\Update\*.* %ALLUSERSPROFILE%\Favorites\*.* %APPDATA%\Microsoft\*.* %PROGRAMFILES%\*.* %APPDATA%\Update\*.* %systemroot%\*. /mp /s CREATERESTOREPOINT %systemroot%\System32\config\*.sav %PROGRAMFILES%\bak. /s %systemroot%\system32\bak. /s %ALLUSERSPROFILE%\Start Menu\*.lnk /x %systemroot%\system32\config\systemprofile\*.dat /x %systemroot%\*.config %systemroot%\system32\*.db %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x %USERPROFILE%\Desktop\*.exe %PROGRAMFILES%\Common Files\*.* %systemroot%\*.src %systemroot%\install\*.* %systemroot%\system32\DLL\*.* %systemroot%\system32\HelpFiles\*.* %systemroot%\system32\rundll\*.* %systemroot%\winn32\*.* %systemroot%\Java\*.* %systemroot%\system32\test\*.* %systemroot%\system32\Rundll32\*.* %systemroot%\AppPatch\Custom\*.* %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x %PROGRAMFILES%\PC-Doctor\Downloads\*.* %PROGRAMFILES%\Internet Explorer\*.tmp %PROGRAMFILES%\Internet Explorer\*.dat %USERPROFILE%\My Documents\*.exe %USERPROFILE%\*.exe %systemroot%\ADDINS\*.* %systemroot%\assembly\*.bak2 %systemroot%\Config\*.* %systemroot%\REPAIR\*.bak2 %systemroot%\SECURITY\Database\*.sdb /x %systemroot%\SYSTEM\*.bak2 %systemroot%\Web\*.bak2 %systemroot%\Driver Cache\*.* %PROGRAMFILES%\Mozilla Firefox\0*.exe %ProgramFiles%\Microsoft Common\*.* %ProgramFiles%\TinyProxy. %USERPROFILE%\Favorites\*.url /x %systemroot%\system32\*.bk %systemroot%\*.te %systemroot%\system32\system32\*.* %ALLUSERSPROFILE%\*.dat /x %systemroot%\system32\drivers\*.rmv dir /b "%systemroot%\system32\*.exe" | find /i " " /c dir /b "%systemroot%\*.exe" | find /i " " /c %PROGRAMFILES%\Microsoft\*.* %systemroot%\System32\Wbem\proquota.exe %PROGRAMFILES%\Mozilla Firefox\*.dat %USERPROFILE%\Cookies\*.txt /x %SystemRoot%\system32\fonts\*.* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
3rd attempt OTL log (minimal output):

OTL logfile created on: 7/11/2011 3:19:55 PM - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Sylvia\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.07 Mb Total Physical Memory | 332.66 Mb Available Physical Memory | 65.09% Memory free
1.22 Gb Paging File | 0.65 Gb Available in Paging File | 53.12% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 66.09 Gb Free Space | 86.59% Space Free | Partition Type: NTFS
Drive D: | 101.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SYLVIASPC | User Name: Sylvia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Sylvia\Application Data\Microsoft\conhost.exe ()
PRC - C:\Documents and Settings\Sylvia\Local Settings\Temp\csrss.exe ()
PRC - C:\Documents and Settings\Sylvia\Application Data\dwm.exe ()
PRC - C:\Documents and Settings\Sylvia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe ()
PRC - C:\Documents and Settings\Sylvia\Local Settings\Temp\RarSFX1\AutoEJCD.exe ()
PRC - C:\Documents and Settings\Sylvia\Local Settings\Temp\RarSFX1\AutoInstallEJCDSvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Sylvia\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AutoInstallEJCD) – C:\Documents and Settings\Sylvia\Local Settings\Temp\RarSFX1\AutoInstallEJCDSvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (ZDCNDIS5) – C:\WINDOWS\system32\ZDCndis5.sys (ZDC., Inc. (ZDC))
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (QWXN720) – C:\WINDOWS\system32\drivers\WLANUHN.sys (Atheros Communications, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (EL90XBC) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61697

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)


[2011/07/10 21:26:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/06 13:29:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/06 13:28:51 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2004/08/04 03:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Sylvia\Application Data\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Qwest 11n Wireless WPS Tool] C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe ()
F3 - HKCU WinNT: Load - (C:\DOCUME~1\Sylvia\LOCALS~1\Temp\csrss.exe) - C:\Documents and Settings\Sylvia\Local Settings\Temp\csrss.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Sylvia\Application Data\dwm.exe) - C:\Documents and Settings\Sylvia\Application Data\dwm.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 () - http://image50.webshots.com/50/4/37/85/456…85ZEPNKD_ph.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Sylvia\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sylvia\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/05 16:14:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/09/03 16:47:14 | 000,000,037 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{33eaee3f-73f9-11df-969a-00b0d0e50e10}\Shell\Auto\command - "" = F:\launcher.exe
O33 - MountPoints2\{33eaee3f-73f9-11df-969a-00b0d0e50e10}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{33eaee3f-73f9-11df-969a-00b0d0e50e10}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL launcher.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/11 05:32:27 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Sylvia\Desktop\OTL.exe
[2011/07/10 21:53:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/07/10 21:50:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Sylvia\Start Menu\Programs\HiJackThis
[2011/07/10 21:32:07 | 000,000,000 | —D | C] – C:\Program Files\HijackThis
[2011/06/29 21:44:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Magic Workstation
[2011/06/29 21:44:38 | 000,000,000 | —D | C] – C:\Program Files\Magic Workstation
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/11 11:15:49 | 000,021,681 | —- | M] () – C:\Documents and Settings\Sylvia\Application Data\A75A.3B0
[2011/07/11 10:10:32 | 000,001,252 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.mwDeck
[2011/07/11 10:05:15 | 000,001,063 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.dec
[2011/07/11 09:36:04 | 000,001,367 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.mwDeck
[2011/07/11 09:18:51 | 000,001,198 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.dec
[2011/07/11 08:31:07 | 000,199,680 | —- | M] () – C:\Documents and Settings\Sylvia\Application Data\dwm.exe
[2011/07/11 08:22:16 | 079,734,956 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/07/11 05:32:29 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sylvia\Desktop\OTL.exe
[2011/07/10 21:53:35 | 000,002,809 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\HiJackThis.lnk
[2011/07/10 17:43:04 | 000,000,067 | —- | M] () – C:\WINDOWS\WpsCenter.INI
[2011/07/10 17:42:14 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/10 17:39:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/10 17:39:21 | 535,969,792 | -HS- | M] () – C:\hiberfil.sys
[2011/07/09 21:37:11 | 000,000,213 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Greg's Ugly but Fast Page.url
[2011/07/09 17:01:08 | 000,000,381 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Microsoft Exchange - Outlook Web Access.url
[2011/07/06 13:58:57 | 000,001,116 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\BLUE WHITE ZENITH.mwDeck
[2011/06/29 21:45:07 | 000,000,733 | —- | M] () – C:\Documents and Settings\Sylvia\Application Data\Microsoft\Internet Explorer\Quick Launch\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,715 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,668 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\MWS Online Play.lnk
[2011/06/29 16:32:11 | 000,000,723 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\RED GREEN BEATS.mwDeck
[2011/06/29 15:55:31 | 000,000,848 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\JINXED IDOL.mwDeck
[2011/06/28 03:01:39 | 000,000,723 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\RATCHET.mwDeck
[2011/06/26 04:24:11 | 000,000,787 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\TEMPO.mwDeck
[2011/06/23 14:00:45 | 000,000,783 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\MONO GREEN.mwDeck
[2011/06/22 02:34:31 | 000,000,801 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\GREEN WHITE.mwDeck
[2011/06/22 00:15:56 | 000,000,644 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\RED DECK WINS.mwDeck
[2011/06/21 05:19:08 | 000,000,932 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\GRIXIS KOTH.mwDeck
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/11 10:06:44 | 000,001,252 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.mwDeck
[2011/07/11 10:05:15 | 000,001,063 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.dec
[2011/07/11 09:22:37 | 000,001,367 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.mwDeck
[2011/07/11 09:18:51 | 000,001,198 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.dec
[2011/07/10 21:50:58 | 000,002,809 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\HiJackThis.lnk
[2011/07/10 20:23:54 | 000,199,680 | —- | C] () – C:\Documents and Settings\Sylvia\Application Data\dwm.exe
[2011/07/10 20:23:30 | 000,021,681 | —- | C] () – C:\Documents and Settings\Sylvia\Application Data\A75A.3B0
[2011/07/09 17:01:08 | 000,000,381 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Microsoft Exchange - Outlook Web Access.url
[2011/06/29 21:45:07 | 000,000,733 | —- | C] () – C:\Documents and Settings\Sylvia\Application Data\Microsoft\Internet Explorer\Quick Launch\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,715 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,668 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\MWS Online Play.lnk
[2011/06/27 18:09:49 | 000,000,723 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\RATCHET.mwDeck
[2011/06/21 06:17:43 | 000,000,848 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\JINXED IDOL.mwDeck
[2011/06/17 12:50:31 | 000,001,116 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\BLUE WHITE ZENITH.mwDeck
[2010/10/21 15:48:41 | 000,000,067 | —- | C] () – C:\WINDOWS\WpsCenter.INI
[2010/06/13 00:11:39 | 000,003,584 | —- | C] () – C:\Documents and Settings\Sylvia\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/05 16:19:18 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/01/05 16:09:25 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/01/05 15:43:12 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/01/05 07:48:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/01/05 07:46:44 | 000,117,360 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/21 16:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 16:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 03:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 03:00:00 | 000,432,356 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 03:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 03:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 03:00:00 | 000,067,312 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 03:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 03:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 03:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 03:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 03:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 03:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

< End of report >
3rd attempt OTL log (minimal output):

OTL logfile created on: 7/11/2011 3:19:55 PM - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Sylvia\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.07 Mb Total Physical Memory | 332.66 Mb Available Physical Memory | 65.09% Memory free
1.22 Gb Paging File | 0.65 Gb Available in Paging File | 53.12% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 66.09 Gb Free Space | 86.59% Space Free | Partition Type: NTFS
Drive D: | 101.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SYLVIASPC | User Name: Sylvia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Sylvia\Application Data\Microsoft\conhost.exe ()
PRC - C:\Documents and Settings\Sylvia\Local Settings\Temp\csrss.exe ()
PRC - C:\Documents and Settings\Sylvia\Application Data\dwm.exe ()
PRC - C:\Documents and Settings\Sylvia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe ()
PRC - C:\Documents and Settings\Sylvia\Local Settings\Temp\RarSFX1\AutoEJCD.exe ()
PRC - C:\Documents and Settings\Sylvia\Local Settings\Temp\RarSFX1\AutoInstallEJCDSvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Sylvia\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AutoInstallEJCD) – C:\Documents and Settings\Sylvia\Local Settings\Temp\RarSFX1\AutoInstallEJCDSvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (ZDCNDIS5) – C:\WINDOWS\system32\ZDCndis5.sys (ZDC., Inc. (ZDC))
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (QWXN720) – C:\WINDOWS\system32\drivers\WLANUHN.sys (Atheros Communications, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (EL90XBC) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61697

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)


[2011/07/10 21:26:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/06 13:29:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/06 13:28:51 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2004/08/04 03:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Sylvia\Application Data\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Qwest 11n Wireless WPS Tool] C:\Program Files\Qwest 11n Wireless WPS Tool\WpsCenter.exe ()
F3 - HKCU WinNT: Load - (C:\DOCUME~1\Sylvia\LOCALS~1\Temp\csrss.exe) - C:\Documents and Settings\Sylvia\Local Settings\Temp\csrss.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Sylvia\Application Data\dwm.exe) - C:\Documents and Settings\Sylvia\Application Data\dwm.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 () - http://image50.webshots.com/50/4/37/85/456…85ZEPNKD_ph.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Sylvia\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sylvia\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/05 16:14:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/09/03 16:47:14 | 000,000,037 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{33eaee3f-73f9-11df-969a-00b0d0e50e10}\Shell\Auto\command - "" = F:\launcher.exe
O33 - MountPoints2\{33eaee3f-73f9-11df-969a-00b0d0e50e10}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{33eaee3f-73f9-11df-969a-00b0d0e50e10}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL launcher.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/11 05:32:27 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Sylvia\Desktop\OTL.exe
[2011/07/10 21:53:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/07/10 21:50:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Sylvia\Start Menu\Programs\HiJackThis
[2011/07/10 21:32:07 | 000,000,000 | —D | C] – C:\Program Files\HijackThis
[2011/06/29 21:44:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Magic Workstation
[2011/06/29 21:44:38 | 000,000,000 | —D | C] – C:\Program Files\Magic Workstation
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/11 11:15:49 | 000,021,681 | —- | M] () – C:\Documents and Settings\Sylvia\Application Data\A75A.3B0
[2011/07/11 10:10:32 | 000,001,252 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.mwDeck
[2011/07/11 10:05:15 | 000,001,063 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.dec
[2011/07/11 09:36:04 | 000,001,367 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.mwDeck
[2011/07/11 09:18:51 | 000,001,198 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.dec
[2011/07/11 08:31:07 | 000,199,680 | —- | M] () – C:\Documents and Settings\Sylvia\Application Data\dwm.exe
[2011/07/11 08:22:16 | 079,734,956 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/07/11 05:32:29 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sylvia\Desktop\OTL.exe
[2011/07/10 21:53:35 | 000,002,809 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\HiJackThis.lnk
[2011/07/10 17:43:04 | 000,000,067 | —- | M] () – C:\WINDOWS\WpsCenter.INI
[2011/07/10 17:42:14 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/10 17:39:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/10 17:39:21 | 535,969,792 | -HS- | M] () – C:\hiberfil.sys
[2011/07/09 21:37:11 | 000,000,213 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Greg's Ugly but Fast Page.url
[2011/07/09 17:01:08 | 000,000,381 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Microsoft Exchange - Outlook Web Access.url
[2011/07/06 13:58:57 | 000,001,116 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\BLUE WHITE ZENITH.mwDeck
[2011/06/29 21:45:07 | 000,000,733 | —- | M] () – C:\Documents and Settings\Sylvia\Application Data\Microsoft\Internet Explorer\Quick Launch\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,715 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,668 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\MWS Online Play.lnk
[2011/06/29 16:32:11 | 000,000,723 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\RED GREEN BEATS.mwDeck
[2011/06/29 15:55:31 | 000,000,848 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\JINXED IDOL.mwDeck
[2011/06/28 03:01:39 | 000,000,723 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\RATCHET.mwDeck
[2011/06/26 04:24:11 | 000,000,787 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\TEMPO.mwDeck
[2011/06/23 14:00:45 | 000,000,783 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\MONO GREEN.mwDeck
[2011/06/22 02:34:31 | 000,000,801 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\GREEN WHITE.mwDeck
[2011/06/22 00:15:56 | 000,000,644 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\RED DECK WINS.mwDeck
[2011/06/21 05:19:08 | 000,000,932 | —- | M] () – C:\Documents and Settings\Sylvia\Desktop\GRIXIS KOTH.mwDeck
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/11 10:06:44 | 000,001,252 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.mwDeck
[2011/07/11 10:05:15 | 000,001,063 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233701 deck.dec
[2011/07/11 09:22:37 | 000,001,367 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.mwDeck
[2011/07/11 09:18:51 | 000,001,198 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Draft _1233667 deck.dec
[2011/07/10 21:50:58 | 000,002,809 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\HiJackThis.lnk
[2011/07/10 20:23:54 | 000,199,680 | —- | C] () – C:\Documents and Settings\Sylvia\Application Data\dwm.exe
[2011/07/10 20:23:30 | 000,021,681 | —- | C] () – C:\Documents and Settings\Sylvia\Application Data\A75A.3B0
[2011/07/09 17:01:08 | 000,000,381 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Microsoft Exchange - Outlook Web Access.url
[2011/06/29 21:45:07 | 000,000,733 | —- | C] () – C:\Documents and Settings\Sylvia\Application Data\Microsoft\Internet Explorer\Quick Launch\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,715 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\Magic Workstation.lnk
[2011/06/29 21:45:07 | 000,000,668 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\MWS Online Play.lnk
[2011/06/27 18:09:49 | 000,000,723 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\RATCHET.mwDeck
[2011/06/21 06:17:43 | 000,000,848 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\JINXED IDOL.mwDeck
[2011/06/17 12:50:31 | 000,001,116 | —- | C] () – C:\Documents and Settings\Sylvia\Desktop\BLUE WHITE ZENITH.mwDeck
[2010/10/21 15:48:41 | 000,000,067 | —- | C] () – C:\WINDOWS\WpsCenter.INI
[2010/06/13 00:11:39 | 000,003,584 | —- | C] () – C:\Documents and Settings\Sylvia\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/05 16:19:18 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/01/05 16:09:25 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/01/05 15:43:12 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/01/05 07:48:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/01/05 07:46:44 | 000,117,360 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/21 16:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 16:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 03:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 03:00:00 | 000,432,356 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 03:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 03:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 03:00:00 | 000,067,312 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 03:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 03:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 03:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 03:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 03:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 03:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

< End of report >
Please follow these instructions very carefully as it needs to be done right for the fix to work.



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61697
    O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Sylvia\Application Data\Microsoft\conhost.exe ()
    F3 - HKCU WinNT: Load - (C:\DOCUME~1\Sylvia\LOCALS~1\Temp\csrss.exe) - C:\Documents and Settings\Sylvia\Local Settings\Temp\csrss.exe ()
    O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Sylvia\Application Data\dwm.exe) - C:\Documents and Settings\Sylvia\Application Data\dwm.exe ()
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )







Next


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI