This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Avira and Malwarebytes detect nothing

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
Would someone look at my HJT Log and tell me if a virus is present that is undetectable by my scanner. I have tried Avira and Malwarebytes.
Thank you so much for your help.

Regards,
Marcel Dunn

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:50:35 PM, on 7/27/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\hMailServer\Bin\hMailServer.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe
C:\WINDOWS\system32\CAP2RSK.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP2SWK.EXE
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=vv…nJDExKw3G0puwPM
O1 - Hosts: 50.22.144.221 telstarjamaica.com www.telstarjamaica.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [CAP2ON] C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAP2ONN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: OneNote Table Of Contents.onetoc2
O4 - Global Startup: Canon LASER SHOT LBP-1210 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE
O4 - Global Startup: Dell Network Assistant.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F69B5ADA-B175-432E-848D-F6937503D6B4}: NameServer = 192.168.1.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: hMailServer - hMailServer - C:\Program Files\hMailServer\Bin\hMailServer.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Upgrade Manager (UpgradeManager) - Great Lakes Data Systems, Inc. - C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe

–
End of file - 9922 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Marcel

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hi there,

Although there are undesirable entries present in HJT, more information is needed for me to get a better picture of what is going on in your computer. Would you describe how it behaves and symptoms? Probably a small detail would help too. :)

Please re-open HijackThis and click on Do a system scan only. Check the boxes next to all the entries listed below.(If exist)
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=vv…nJDExKw3G0puwPM


Note : Do not worry if you are unable to find any of these entries, continue with the ones that you discovered. Now close all windows other than HijackThis, then click Fix checked. Close HijackThis. Then reboot.

===================================================

Hello there,

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hello There, Thank you for your reply. I will be away from the computer till Thursday this week. Please do not close my thread. Thank you again for your help with this. Regards, elmkd
Hello,
Thanks for your patience. Here is the information you requested.

OTL Logs

OTL logfile created on: 8/4/2011 8:06:36 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\TelStar\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.10 Mb Total Physical Memory | 557.42 Mb Available Physical Memory | 55.02% Memory free
2.38 Gb Paging File | 1.98 Gb Available in Paging File | 83.09% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 133.66 Gb Free Space | 89.73% Space Free | Partition Type: NTFS

Computer Name: CONFERENCE1 | User Name: TelStar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\TelStar\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\hMailServer\Bin\hMailServer.exe (hMailServer)
PRC - C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe (Great Lakes Data Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell Network Assistant\ezi_hnm2.exe (SingleClick Systems)
PRC - C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
PRC - C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2SWK.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
PRC - C:\WINDOWS\system32\CAP2RSK.EXE (CANON INC.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\TelStar\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.dll (Adobe Systems, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (hMailServer) – C:\Program Files\hMailServer\Bin\hMailServer.exe (hMailServer)
SRV - (UpgradeManager) – C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe (Great Lakes Data Systems, Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (hnmsvc) – C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
SRV - (awhost32) – C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Packet) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (AW_HOST) – C:\WINDOWS\system32\drivers\AW_HOST5.sys (Symantec Corporation)
DRV - (awecho) – C:\WINDOWS\system32\drivers\awechomd.sys (Symantec Corporation)
DRV - (awlegacy) – C:\WINDOWS\System32\Drivers\awlegacy.sys (Symantec Corporation)
DRV - (Gernuwa) – C:\WINDOWS\System32\drivers\GERNUWA.sys (Symantec Corporation)
DRV - (RapidPort2) – C:\WINDOWS\system32\drivers\CAP2LPT.SYS (CANON INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=1080403
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=1080403

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=1080403
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 88 66 6E 62 F7 4D CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {8b86149f-01fb-4842-9dd8-4d7eb02fd055}:0.21.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/29 09:32:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/29 09:32:14 | 000,000,000 | —D | M]

[2008/07/17 09:49:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Extensions
[2011/08/04 08:03:27 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions
[2009/08/12 14:29:13 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/24 09:16:57 | 000,000,000 | —D | M] (Unhide Passwords) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{2e17e2b2-b8d4-4a67-8d7b-fafa6cc9d1d0}
[2009/11/26 09:02:29 | 000,000,000 | —D | M] (IE Tab) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2010/12/10 13:53:02 | 000,000,000 | —D | M] (All-in-One Gestures) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2009/11/26 09:02:31 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/01/14 10:06:12 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/11/29 10:28:13 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\[removed]
[2009/08/10 09:28:27 | 000,000,000 | —D | M] (Qip.Bar) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\[removed]
[2010/03/31 17:48:23 | 000,001,827 | —- | M] () – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\searchplugins\bing.xml
[2011/08/04 07:53:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/26 16:59:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/16 07:21:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/11 15:27:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2008/12/23 09:54:38 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/12/31 14:41:21 | 000,000,793 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 50.22.144.221 telstarjamaica.com www.telstarjamaica.com
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (PDFCreator Toolbar Helper) - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CAP2ON] C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2ONN.EXE (CANON INC.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKCU..\Run: [ares] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Canon LASER SHOT LBP-1210 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE (CANON INC.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk = C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe ()
O4 - Startup: C:\Documents and Settings\TelStar\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\PCANotify: DllName - PCANotify.dll - C:\WINDOWS\System32\PCANotify.dll (Symantec Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\TelStar\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell - "" = AutoRun
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell - "" = AutoRun
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\Auto\command - "" = Cn911.exe
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/04 08:03:02 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\TelStar\Desktop\OTL.exe
[2011/07/29 10:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\.zenmap
[2011/07/29 10:22:03 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Start Menu\Programs\Nmap
[2011/07/29 10:21:18 | 000,000,000 | —D | C] – C:\Program Files\Nmap
[2011/07/27 12:47:25 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Start Menu\Programs\HiJackThis
[2011/07/20 11:19:25 | 000,000,000 | –SD | C] – C:\Documents and Settings\TelStar\My Documents\My Shapes
[2011/07/20 11:18:33 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Application Data\Thinstall
[2011/07/20 11:18:32 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Local Settings\Application Data\Thinstall
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/04 08:03:02 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\TelStar\Desktop\OTL.exe
[2011/08/04 07:56:53 | 000,002,451 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\HiJackThis.lnk
[2011/08/04 07:53:45 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/04 07:52:51 | 000,002,333 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk
[2011/08/04 07:52:32 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/04 07:52:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/29 10:22:03 | 000,000,638 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\Nmap - Zenmap GUI.lnk
[2011/07/22 16:48:31 | 000,000,784 | -HS- | M] () – C:\WINDOWS\System\actualspystart.lnk
[2011/07/22 11:53:41 | 000,000,802 | —- | M] () – C:\Documents and Settings\TelStar\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/22 11:53:41 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/20 13:45:46 | 000,001,328 | —- | M] () – C:\bar.emf
[2011/07/20 10:42:39 | 000,302,592 | —- | M] () – C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe
[2011/07/18 08:51:28 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2011/07/14 07:56:29 | 000,270,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/13 17:18:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/29 10:22:03 | 000,000,638 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\Nmap - Zenmap GUI.lnk
[2011/07/27 12:47:25 | 000,002,451 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\HiJackThis.lnk
[2011/07/20 13:45:46 | 000,001,328 | —- | C] () – C:\bar.emf
[2011/07/20 10:42:39 | 000,302,592 | —- | C] () – C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe
[2011/06/28 14:15:30 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\hpsfs.dll
[2011/02/23 17:02:24 | 000,004,608 | —- | C] () – C:\Documents and Settings\TelStar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/11 12:45:33 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2010/06/25 12:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/06/08 12:40:06 | 000,000,019 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2009/06/08 12:40:06 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2008/11/29 10:35:35 | 000,055,808 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2008/10/26 13:57:02 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/10/14 13:48:32 | 000,025,177 | —- | C] () – C:\Documents and Settings\TelStar\Application Data\Microsoft Access 97-2003.ADR
[2008/10/14 13:22:27 | 000,000,028 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/14 10:46:29 | 000,002,861 | —- | C] () – C:\WINDOWS\RBuilder.ini
[2008/10/13 08:54:17 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/09/17 12:44:37 | 000,014,290 | —- | C] () – C:\Program Files\settings.dat
[2008/05/07 15:51:51 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/05/07 15:06:06 | 000,696,320 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2008/05/07 15:06:06 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/04/09 17:00:30 | 000,053,478 | —- | C] () – C:\WINDOWS\mvtcpui.ini
[2008/04/03 11:10:26 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/03 11:07:39 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/04/03 11:06:14 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/04/03 11:06:14 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/03 10:46:52 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2008/04/03 10:46:43 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/04/03 10:45:21 | 000,001,124 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 000,270,192 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,446,122 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,073,202 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/19 17:30:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\PowerCalc.exe
[2002/03/19 17:30:00 | 000,045,632 | —- | C] () – C:\WINDOWS\System32\TaskSwitch.exe

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2011/01/14 14:22:38 | 000,020,480 | —- | M] () – C:\ Cherry Gardens2.xls
[2008/11/01 16:45:38 | 009,409,224 | —- | M] (Microsoft Corporation) – C:\40_Install_MSN_Messenger.exe
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/20 13:45:46 | 000,001,328 | —- | M] () – C:\bar.emf
[2008/05/02 15:09:20 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/01/14 13:15:10 | 000,108,032 | —- | M] () – C:\Cherry Gardens.xls
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/04/03 10:47:56 | 000,006,942 | RH– | M] () – C:\dell.sdr
[2009/11/25 15:16:22 | 000,002,301 | —- | M] () – C:\exceptions_backup_20091125.txt
[2011/06/29 09:50:12 | 000,002,104 | —- | M] () – C:\fwdownload.log
[2008/05/06 10:14:11 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2008/11/01 16:42:27 | 018,895,728 | —- | M] (Microsoft Corporation) – C:\Install_Messenger.exe
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/08/19 15:25:14 | 000,000,000 | —- | M] () – C:\lockbox_20090819.txt
[2009/11/25 15:17:15 | 000,000,194 | —- | M] () – C:\lockbox_20091125.txt
[2009/11/26 13:07:59 | 000,000,110 | —- | M] () – C:\lockbox_20091126.txt
[2011/07/13 13:18:13 | 000,000,166 | —- | M] () – C:\lockbox_20110713.txt
[2011/07/14 09:52:57 | 000,000,110 | —- | M] () – C:\lockbox_20110714.txt
[2011/07/15 09:26:54 | 000,000,054 | —- | M] () – C:\lockbox_20110715.txt
[2009/11/25 15:16:22 | 000,000,194 | —- | M] () – C:\lockbox_backup_20091125.txt
[2010/08/11 12:46:19 | 000,013,844 | —- | M] () – C:\M1319.log
[2010/04/19 08:11:41 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2011/06/29 09:49:21 | 000,209,198 | —- | M] () – C:\NetworkWizardInstaller.log
[2011/01/14 13:20:36 | 000,035,328 | —- | M] () – C:\Norbrook.xls
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/25 09:13:52 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/25 11:46:53 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2011/07/25 11:46:53 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2011/08/04 07:52:28 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2011/07/18 08:51:28 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2009/08/19 15:25:14 | 000,000,000 | —- | M] () – C:\RBTT_Exceptions_20090819.txt
[2009/11/25 15:17:15 | 000,000,000 | —- | M] () – C:\RBTT_Exceptions_20091125.txt
[2009/11/26 13:07:59 | 000,000,000 | —- | M] () – C:\RBTT_Exceptions_20091126.txt
[2011/07/13 13:18:13 | 000,000,000 | —- | M] () – C:\RBTT_Exceptions_20110713.txt
[2011/07/14 09:52:57 | 000,000,000 | —- | M] () – C:\RBTT_Exceptions_20110714.txt
[2011/07/15 09:26:54 | 000,000,000 | —- | M] () – C:\RBTT_Exceptions_20110715.txt
[2008/11/01 18:36:04 | 000,056,465 | —- | M] () – C:\Sp08_Mercurial_Vapour_02.jpg
[2010/01/07 11:57:41 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2010/01/07 13:15:35 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2010/01/09 17:03:13 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2010/01/11 18:05:09 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2010/01/12 16:05:54 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/01/12 17:12:53 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2010/01/13 13:05:32 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2010/01/18 09:24:28 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/01/20 15:19:50 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2010/03/06 17:10:07 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2010/03/20 17:05:46 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/12/21 17:06:49 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/12/22 13:18:09 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/12/22 17:36:28 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/12/30 13:08:29 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/12/30 15:57:47 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/12/31 11:23:42 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/12/31 15:04:02 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/12/31 17:00:01 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2010/01/04 13:15:26 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2010/01/07 11:57:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/01/07 13:15:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/01/09 17:03:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/01/11 18:05:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/01/12 16:05:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/01/12 17:12:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/01/13 13:05:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/01/18 09:24:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/01/20 15:19:50 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/03/06 17:10:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/03/20 17:05:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/12/21 17:06:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/12/22 13:18:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/12/22 17:36:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/12/30 13:08:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/12/30 15:57:47 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/12/31 11:23:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/12/31 15:04:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/12/31 17:00:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/01/04 13:15:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2008/11/01 16:35:42 | 002,400,784 | —- | M] (Microsoft Corporation) – C:\WLinstaller.exe
[2008/05/02 15:22:19 | 000,001,014 | —- | M] () – C:\WPI_Log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/12/09 19:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ZIMFPRNT.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/09/17 12:44:37 | 000,014,290 | —- | M] () – C:\Program Files\settings.dat

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/25 09:18:40 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/05/02 15:09:42 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\TelStar\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2009/08/10 10:12:27 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\TelStar\Desktop\ATF_Cleaner.exe
[2011/08/04 08:03:02 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\TelStar\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794

< End of report >


OTL Extras logfile created on: 8/4/2011 8:06:36 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\TelStar\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.10 Mb Total Physical Memory | 557.42 Mb Available Physical Memory | 55.02% Memory free
2.38 Gb Paging File | 1.98 Gb Available in Paging File | 83.09% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 133.66 Gb Free Space | 89.73% Space Free | Partition Type: NTFS

Computer Name: CONFERENCE1 | User Name: TelStar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"113:TCP" = 113:TCP:*:Enabled:auth
"25:TCP" = 25:TCP:*:Enabled:hMailServer
"9100:TCP" = 9100:TCP:*:Enabled:Printer
"427:UDP" = 427:UDP:*:Enabled:SLP
"161:TCP" = 161:TCP:*:Enabled:SNMP

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX – (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" = C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program – (CyberLink Corp.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX – (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" = C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program – (CyberLink Corp.)
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant – (SingleClick Systems)
"C:\Program Files\Symantec\pcAnywhere\awhost32.exe" = C:\Program Files\Symantec\pcAnywhere\awhost32.exe:*:Enabled:pcAnywhere Host – (Symantec Corporation)
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Disabled:Ares p2p for windows
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Cain\Cain.exe" = C:\Program Files\Cain\Cain.exe:*:Disabled:Cain - Password Recovery Utility
"C:\Program Files\SJphone 1.65\SJphone.exe" = C:\Program Files\SJphone 1.65\SJphone.exe:*:Enabled:SJphone 1.65
"C:\Program Files\HP\HP LaserJet P2030 Series\HPMSetup.exe" = C:\Program Files\HP\HP LaserJet P2030 Series\HPMSetup.exe:*:Enabled:Network Installer Wizard – (Marvell)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{12018183-866A-11D3-97DF-0000F8D8F2E9}" = Symantec pcAnywhere
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 24
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D3C9F4B-4B7D-4E5D-99B9-0123AB0D51ED}" = Dell DataSafe Online
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections [removed]
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{471159EB-BECC-453C-B6F2-FE4FAB29B3F3}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}" = Alt-Tab Task Switcher Powertoy for Windows XP
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B37C842A-B624-46B8-A727-654E72F1C91A}" = Calculator Powertoy for Windows XP
"{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}" = Microsoft SQL Server Compact 3.5 ENU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FD025150-EEA0-4CAC-BED1-B9837783FCC8}" = ActivePerl 5.10.0 Build 1005
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Canon LASER SHOT LBP-1210" = Canon LASER SHOT LBP-1210
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EssentialPIM" = EssentialPIM
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"hMailServer_is1" = hMailServer 5.2-B356
"HP LaserJet P2030 Series" = HP LaserJet P2030 Series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Magic ISO Maker v5.5 (build 0273)" = Magic ISO Maker v5.5 (build 0273)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.18)" = Mozilla Firefox (3.6.18)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nmap" = Nmap 5.51
"PDFCreator Toolbar" = PDFCreator Toolbar
"SearchAssist" = SearchAssist
"Tweak UI 2.10" = Tweak UI
"VLC media player" = VLC media player 1.1.7
"WinCable Client [removed]" = WinCable Client [removed]
"WinCable Client [removed]" = WinCable Client [removed]
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.2
"Wireshark" = Wireshark 1.4.3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ OSession Events ]
Error - 6/30/2009 4:51:23 PM | Computer Name = CONFERENCE1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/30/2009 4:51:46 PM | Computer Name = CONFERENCE1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/30/2009 4:51:51 PM | Computer Name = CONFERENCE1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 8/4/2011 8:54:56 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "DARBY-01 :0" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.42 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 8:54:56 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "WINCABLESERVER :0" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.44 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 8:55:22 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "TELSTAR :1d" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.45 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 8:56:16 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "SERVERA :0" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.45 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 8:56:17 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "SUPERCONTROLLER:0" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.48 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 8:56:21 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "GILBERT :0" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.53 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 9:00:32 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "TELSTAR :1d" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.45 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 9:05:42 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "TELSTAR :1d" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.45 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 9:07:35 AM | Computer Name = CONFERENCE1 | Source = NetBT | ID = 4321
Description = The name "TELSTAR :1d" could not be registered on the Interface
with IP address 192.168.1.24. The machine with the IP address 192.168.1.45 did not
allow the name to be claimed by this machine.

Error - 8/4/2011 9:07:35 AM | Computer Name = CONFERENCE1 | Source = BROWSER | ID = 8009
Description = The browser was unable to promote itself to master browser. The computer
that currently believes it is the master browser is SERVERA.


< End of report >


Security Check

Results of screen317's Security Check version 0.99.18
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Avira AntiVir Personal - Free Antivirus
Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

Out of date HijackThis installed!
Malwarebytes' Anti-Malware
Hijackthis 1.99.1
HijackThis 2.0.2
Java™ 6 Update 24
Java™ 6 Update 7
Out of date Java installed!
Adobe Flash Player 10.3.181.26
Mozilla Firefox (3.6.18) Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Avira Antivir avgnt.exe
Avira Antivir avguard.exe
``````````End of Log````````````

Attachments:

Hi,

You have ( Ares ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

Do you recognize the following file?
[2011/07/20 10:42:39 | 000,302,592 | —- | M] () – C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe

If not, please upload it for scan.

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan


click on Browse, and upload the following file for analysis:
C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results link(for Virus Total) here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

===================================================

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2011/07/22 16:48:31 | 000,000,784 | -HS- | M] () – C:\WINDOWS\System\actualspystart.lnk
    
    :Commands
    [REBOOT]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script and( don't check the boxes beside LOP Check or Purity this time )
===================================================

On your next reply please post :
File scanner report
Fresh OTL log
OTL fix log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hello,
I do recognize the file. It is GMER with a random name. I had downloaded GMER in the past in an attempt to figure out if something was on the PC. The OTL Fix did not generate a Log file to save. You mentioned the following: "don't check the boxes beside LOP Check or Purity this time"
Your previous instructions did not mention checking these boxes. Should I have done this before running the Fix? In any event, I have included the OTL Fresh Scan Log below.

I would like to un-install Ares, but it does not appear in add or remove programs. Do you have any advice?

Thank you for your help.
Regards,
elmkd

OTL Fresh Scan Log
=================

OTL logfile created on: 8/5/2011 10:02:06 AM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\TelStar\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.10 Mb Total Physical Memory | 417.01 Mb Available Physical Memory | 41.16% Memory free
2.38 Gb Paging File | 1.90 Gb Available in Paging File | 79.76% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 133.62 Gb Free Space | 89.70% Space Free | Partition Type: NTFS

Computer Name: CONFERENCE1 | User Name: TelStar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\TelStar\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\hMailServer\Bin\hMailServer.exe (hMailServer)
PRC - C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe (Great Lakes Data Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell Network Assistant\ezi_hnm2.exe (SingleClick Systems)
PRC - C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
PRC - C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2SWK.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
PRC - C:\WINDOWS\system32\CAP2RSK.EXE (CANON INC.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\TelStar\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (hMailServer) – C:\Program Files\hMailServer\Bin\hMailServer.exe (hMailServer)
SRV - (UpgradeManager) – C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe (Great Lakes Data Systems, Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (hnmsvc) – C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
SRV - (awhost32) – C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Packet) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (AW_HOST) – C:\WINDOWS\system32\drivers\AW_HOST5.sys (Symantec Corporation)
DRV - (awecho) – C:\WINDOWS\system32\drivers\awechomd.sys (Symantec Corporation)
DRV - (awlegacy) – C:\WINDOWS\System32\Drivers\awlegacy.sys (Symantec Corporation)
DRV - (Gernuwa) – C:\WINDOWS\System32\drivers\GERNUWA.sys (Symantec Corporation)
DRV - (RapidPort2) – C:\WINDOWS\system32\drivers\CAP2LPT.SYS (CANON INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 88 66 6E 62 F7 4D CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {8b86149f-01fb-4842-9dd8-4d7eb02fd055}:0.21.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/29 09:32:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/29 09:32:14 | 000,000,000 | —D | M]

[2008/07/17 09:49:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Extensions
[2011/08/05 09:53:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions
[2009/08/12 14:29:13 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/24 09:16:57 | 000,000,000 | —D | M] (Unhide Passwords) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{2e17e2b2-b8d4-4a67-8d7b-fafa6cc9d1d0}
[2009/11/26 09:02:29 | 000,000,000 | —D | M] (IE Tab) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2010/12/10 13:53:02 | 000,000,000 | —D | M] (All-in-One Gestures) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2009/11/26 09:02:31 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/01/14 10:06:12 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/11/29 10:28:13 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\[removed]
[2009/08/10 09:28:27 | 000,000,000 | —D | M] (Qip.Bar) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\[removed]
[2010/03/31 17:48:23 | 000,001,827 | —- | M] () – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\searchplugins\bing.xml
[2011/08/05 09:58:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/26 16:59:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/16 07:21:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/11 15:27:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2008/12/23 09:54:38 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/12/31 14:41:21 | 000,000,793 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 50.22.144.221 telstarjamaica.com www.telstarjamaica.com
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (PDFCreator Toolbar Helper) - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CAP2ON] C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2ONN.EXE (CANON INC.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKCU..\Run: [ares] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Canon LASER SHOT LBP-1210 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE (CANON INC.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk = C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe ()
O4 - Startup: C:\Documents and Settings\TelStar\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\PCANotify: DllName - PCANotify.dll - C:\WINDOWS\System32\PCANotify.dll (Symantec Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\TelStar\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell - "" = AutoRun
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell - "" = AutoRun
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\Auto\command - "" = Cn911.exe
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/05 09:51:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/08/04 08:03:02 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\TelStar\Desktop\OTL.exe
[2011/07/29 10:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\.zenmap
[2011/07/29 10:22:03 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Start Menu\Programs\Nmap
[2011/07/29 10:21:18 | 000,000,000 | —D | C] – C:\Program Files\Nmap
[2011/07/27 12:47:25 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Start Menu\Programs\HiJackThis
[2011/07/20 11:19:25 | 000,000,000 | –SD | C] – C:\Documents and Settings\TelStar\My Documents\My Shapes
[2011/07/20 11:18:33 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Application Data\Thinstall
[2011/07/20 11:18:32 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Local Settings\Application Data\Thinstall
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/05 09:57:29 | 000,002,333 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk
[2011/08/05 09:57:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/05 09:42:58 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/04 09:32:58 | 000,879,225 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\SecurityCheck.exe
[2011/08/04 08:11:46 | 000,302,592 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\el94i6e0.exe
[2011/08/04 08:03:02 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\TelStar\Desktop\OTL.exe
[2011/08/04 07:56:53 | 000,002,451 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\HiJackThis.lnk
[2011/08/04 07:53:45 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/07/29 10:22:03 | 000,000,638 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\Nmap - Zenmap GUI.lnk
[2011/07/22 11:53:41 | 000,000,802 | —- | M] () – C:\Documents and Settings\TelStar\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/22 11:53:41 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/20 13:45:46 | 000,001,328 | —- | M] () – C:\bar.emf
[2011/07/20 10:42:39 | 000,302,592 | —- | M] () – C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe
[2011/07/18 08:51:28 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2011/07/14 07:56:29 | 000,270,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/13 17:18:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/04 09:32:57 | 000,879,225 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\SecurityCheck.exe
[2011/08/04 08:11:46 | 000,302,592 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\el94i6e0.exe
[2011/07/29 10:22:03 | 000,000,638 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\Nmap - Zenmap GUI.lnk
[2011/07/27 12:47:25 | 000,002,451 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\HiJackThis.lnk
[2011/07/20 13:45:46 | 000,001,328 | —- | C] () – C:\bar.emf
[2011/07/20 10:42:39 | 000,302,592 | —- | C] () – C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe
[2011/06/28 14:15:30 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\hpsfs.dll
[2011/02/23 17:02:24 | 000,004,608 | —- | C] () – C:\Documents and Settings\TelStar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/11 12:45:33 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2010/06/25 12:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/06/08 12:40:06 | 000,000,019 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2009/06/08 12:40:06 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2008/11/29 10:35:35 | 000,055,808 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2008/10/26 13:57:02 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/10/14 13:48:32 | 000,025,177 | —- | C] () – C:\Documents and Settings\TelStar\Application Data\Microsoft Access 97-2003.ADR
[2008/10/14 13:22:27 | 000,000,028 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/14 10:46:29 | 000,002,861 | —- | C] () – C:\WINDOWS\RBuilder.ini
[2008/10/13 08:54:17 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/09/17 12:44:37 | 000,014,290 | —- | C] () – C:\Program Files\settings.dat
[2008/05/07 15:51:51 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/05/07 15:06:06 | 000,696,320 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2008/05/07 15:06:06 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/04/09 17:00:30 | 000,053,478 | —- | C] () – C:\WINDOWS\mvtcpui.ini
[2008/04/03 11:10:26 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/03 11:07:39 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/04/03 11:06:14 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/04/03 11:06:14 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/03 10:46:52 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2008/04/03 10:46:43 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/04/03 10:45:21 | 000,001,124 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 000,270,192 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,446,122 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,073,202 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/19 17:30:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\PowerCalc.exe
[2002/03/19 17:30:00 | 000,045,632 | —- | C] () – C:\WINDOWS\System32\TaskSwitch.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794

< End of report >
Hi there,

I do recognize the file. It is GMER with a random name. I had downloaded GMER in the past in an attempt to figure out if something was on the PC. The OTL Fix did not generate a Log file to save. You mentioned the following: "don't check the boxes beside LOP Check or Purity this time"

Your previous instructions did not mention checking these boxes. Should I have done this before running the Fix? In any event, I have included the OTL Fresh Scan Log below.

That explains a lot; the GMER log you ran was different than the one I was asking you but nevermind about that now. - No need to check the boxes in future. Don't worry about it. :)

I would like to un-install Ares, but it does not appear in add or remove programs. Do you have any advice?

We will take care of it through OTL.

Other than that, there is one more thing I need to clarify with you just to be on the safe side. Did you add the following entry?
O1 - Hosts: 50.22.144.221 telstarjamaica.com www.telstarjamaica.com

===================================================

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O4 - HKCU..\Run: [ares] File not found
    
    :Commands
    [EMPTYFLASH]
    [EMPTYTEMP]
    [REBOOT]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
Please forgive the delay. I am dealing with an unrelated, but serious problem. I will run OTL tomorrow and post the logs as requested. Thanks for your patience. Regards, elmkd
Hello,
Thanks again for your patience. I have included the Fix Log and the OTL Log as requested. I did have one other question; if I have a problem with another computer in the future, is it okay to include HJT, OTL, and GMER logs in my first post? Is that useful and would it save time for an analyst such as yourself?
Regards,
elmkd

Fix Log
========

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ares deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: TelStar
->Flash cache emptied: 59834 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 211537 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: TelStar
->Temp folder emptied: 28239352 bytes
->Temporary Internet Files folder emptied: 94308572 bytes
->Java cache emptied: 77312431 bytes
->FireFox cache emptied: 116432712 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 1162769 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 911776 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 130040736 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 9923 bytes

Total Files Cleaned = 428.00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.26.1 log created on 08092011_075629

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…



OTL Log
=======

OTL logfile created on: 8/9/2011 8:03:15 AM - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\TelStar\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.10 Mb Total Physical Memory | 413.21 Mb Available Physical Memory | 40.79% Memory free
2.38 Gb Paging File | 1.89 Gb Available in Paging File | 79.43% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 133.88 Gb Free Space | 89.87% Space Free | Partition Type: NTFS

Computer Name: CONFERENCE1 | User Name: TelStar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\TelStar\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\hMailServer\Bin\hMailServer.exe (hMailServer)
PRC - C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe (Great Lakes Data Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell Network Assistant\ezi_hnm2.exe (SingleClick Systems)
PRC - C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
PRC - C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2SWK.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
PRC - C:\WINDOWS\system32\CAP2RSK.EXE (CANON INC.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\TelStar\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (hMailServer) – C:\Program Files\hMailServer\Bin\hMailServer.exe (hMailServer)
SRV - (UpgradeManager) – C:\Program Files\GLDS\UpgradeManager\UpgradeManagerSvc.exe (Great Lakes Data Systems, Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (hnmsvc) – C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
SRV - (awhost32) – C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Packet) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (AW_HOST) – C:\WINDOWS\system32\drivers\AW_HOST5.sys (Symantec Corporation)
DRV - (awecho) – C:\WINDOWS\system32\drivers\awechomd.sys (Symantec Corporation)
DRV - (awlegacy) – C:\WINDOWS\System32\Drivers\awlegacy.sys (Symantec Corporation)
DRV - (Gernuwa) – C:\WINDOWS\System32\drivers\GERNUWA.sys (Symantec Corporation)
DRV - (RapidPort2) – C:\WINDOWS\system32\drivers\CAP2LPT.SYS (CANON INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080403
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk/en/…?channel=us-smb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 88 66 6E 62 F7 4D CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {8b86149f-01fb-4842-9dd8-4d7eb02fd055}:0.21.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/29 09:32:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/29 09:32:14 | 000,000,000 | —D | M]

[2008/07/17 09:49:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Extensions
[2011/08/05 09:53:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions
[2009/08/12 14:29:13 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/24 09:16:57 | 000,000,000 | —D | M] (Unhide Passwords) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{2e17e2b2-b8d4-4a67-8d7b-fafa6cc9d1d0}
[2009/11/26 09:02:29 | 000,000,000 | —D | M] (IE Tab) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2010/12/10 13:53:02 | 000,000,000 | —D | M] (All-in-One Gestures) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2009/11/26 09:02:31 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/01/14 10:06:12 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/11/29 10:28:13 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\[removed]
[2009/08/10 09:28:27 | 000,000,000 | —D | M] (Qip.Bar) – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\extensions\[removed]
[2010/03/31 17:48:23 | 000,001,827 | —- | M] () – C:\Documents and Settings\TelStar\Application Data\Mozilla\Firefox\Profiles\3mpljlwk.default\searchplugins\bing.xml
[2011/08/09 08:00:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/26 16:59:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/16 07:21:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/11 15:27:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2008/12/23 09:54:38 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/12/31 14:41:21 | 000,000,793 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 50.22.144.221 telstarjamaica.com www.telstarjamaica.com
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (PDFCreator Toolbar Helper) - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll ()
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CAP2ON] C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2ONN.EXE (CANON INC.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Canon LASER SHOT LBP-1210 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE (CANON INC.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk = C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe ()
O4 - Startup: C:\Documents and Settings\TelStar\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\PCANotify: DllName - PCANotify.dll - C:\WINDOWS\System32\PCANotify.dll (Symantec Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\TelStar\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell - "" = AutoRun
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4738b031-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell - "" = AutoRun
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\Auto\command - "" = Cn911.exe
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4738b032-7eb7-11dd-92ee-001d0991071c}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/05 09:51:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/08/04 08:03:02 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\TelStar\Desktop\OTL.exe
[2011/07/29 10:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\.zenmap
[2011/07/29 10:22:03 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Start Menu\Programs\Nmap
[2011/07/29 10:21:18 | 000,000,000 | —D | C] – C:\Program Files\Nmap
[2011/07/27 12:47:25 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Start Menu\Programs\HiJackThis
[2011/07/20 11:19:25 | 000,000,000 | –SD | C] – C:\Documents and Settings\TelStar\My Documents\My Shapes
[2011/07/20 11:18:33 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Application Data\Thinstall
[2011/07/20 11:18:32 | 000,000,000 | —D | C] – C:\Documents and Settings\TelStar\Local Settings\Application Data\Thinstall

========== Files - Modified Within 30 Days ==========

[2011/08/09 07:58:57 | 000,002,333 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk
[2011/08/09 07:58:09 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/09 07:58:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/04 09:32:58 | 000,879,225 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\SecurityCheck.exe
[2011/08/04 08:11:46 | 000,302,592 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\el94i6e0.exe
[2011/08/04 08:03:02 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\TelStar\Desktop\OTL.exe
[2011/08/04 07:56:53 | 000,002,451 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\HiJackThis.lnk
[2011/08/04 07:53:45 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/07/29 10:22:03 | 000,000,638 | —- | M] () – C:\Documents and Settings\TelStar\Desktop\Nmap - Zenmap GUI.lnk
[2011/07/22 11:53:41 | 000,000,802 | —- | M] () – C:\Documents and Settings\TelStar\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/22 11:53:41 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/20 13:45:46 | 000,001,328 | —- | M] () – C:\bar.emf
[2011/07/20 10:42:39 | 000,302,592 | —- | M] () – C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe
[2011/07/18 08:51:28 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2011/07/14 07:56:29 | 000,270,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/13 17:18:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== Files Created - No Company Name ==========

[2011/08/04 09:32:57 | 000,879,225 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\SecurityCheck.exe
[2011/08/04 08:11:46 | 000,302,592 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\el94i6e0.exe
[2011/07/29 10:22:03 | 000,000,638 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\Nmap - Zenmap GUI.lnk
[2011/07/27 12:47:25 | 000,002,451 | —- | C] () – C:\Documents and Settings\TelStar\Desktop\HiJackThis.lnk
[2011/07/20 13:45:46 | 000,001,328 | —- | C] () – C:\bar.emf
[2011/07/20 10:42:39 | 000,302,592 | —- | C] () – C:\Documents and Settings\TelStar\My Documents\boov1z0f.exe
[2011/06/28 14:15:30 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\hpsfs.dll
[2011/02/23 17:02:24 | 000,004,608 | —- | C] () – C:\Documents and Settings\TelStar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/11 12:45:33 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2010/06/25 12:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/06/08 12:40:06 | 000,000,019 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2009/06/08 12:40:06 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2008/11/29 10:35:35 | 000,055,808 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2008/10/26 13:57:02 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/10/14 13:48:32 | 000,025,177 | —- | C] () – C:\Documents and Settings\TelStar\Application Data\Microsoft Access 97-2003.ADR
[2008/10/14 13:22:27 | 000,000,028 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/14 10:46:29 | 000,002,861 | —- | C] () – C:\WINDOWS\RBuilder.ini
[2008/10/13 08:54:17 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/09/17 12:44:37 | 000,014,290 | —- | C] () – C:\Program Files\settings.dat
[2008/05/07 15:51:51 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/05/07 15:06:06 | 000,696,320 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2008/05/07 15:06:06 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/04/09 17:00:30 | 000,053,478 | —- | C] () – C:\WINDOWS\mvtcpui.ini
[2008/04/03 11:10:26 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/03 11:07:39 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/04/03 11:06:14 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/04/03 11:06:14 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/03 10:46:52 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2008/04/03 10:46:43 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/04/03 10:45:21 | 000,001,124 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 000,270,192 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,446,122 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,073,202 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/19 17:30:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\PowerCalc.exe
[2002/03/19 17:30:00 | 000,045,632 | —- | C] () – C:\WINDOWS\System32\TaskSwitch.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794

< End of report >
Hi,

Well yes it will definitely save both the analyst and your time if you post OTL and GMER log in future. However, as HJT only offers a limited depth of analysis, we often ask users to get OTL and GMER log for a better overview before we start our fixing process. So in this case, OTL and GMER is generally sufficient. I hope that answers your question. :)

You need to update your java and firefox.

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK
===================================================

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

I'm pleased to let you know that your log is clean! :thumbup:

Thank you for your patience, and performing all of the procedures requested. I would also like to take this opportunity to apologize for any delay that may have occurred.

————————————————————————————————————–

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.


Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.


SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an add-on available for both Firefox and IE.

  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
  • Download Host.zip and Save it to your Desktop.
  • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
  • Follow the prompts and click 'Finish'.
  • This will open the newly created hosts folder on your Desktop.
  • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
  • Once updated you should see another prompt that the task was completed.
Follow this list and keep your antivirus program and antispyware programs updated and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so.

**Please respond this one more time to ensure it is resolved and close this topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI