This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer freezes when idle

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:welcome:

Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
. DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 22:59:54 on 2011-08-26 Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1386 [GMT 10:00] . AV: Norton AntiVirus *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\dvd43\dvd43_tray.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.abc.net.au/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\17.8.0.5\IPSBHO.DLL BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{870F6699-A3F0-40A8-995A-9655C9FC8163} : DhcpNameServer = [removed] [removed] Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1108000.005\symds.sys [2010-9-24 328752] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1108000.005\symefa.sys [2010-9-24 173104] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\bashdefs\20110812.001\BHDrvx86.sys [2011-8-16 815736] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1108000.005\cchpx86.sys [2010-9-24 501888] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1108000.005\ironx86.sys [2010-9-24 116784] R2 DiskDoctorService;Norton Disk Doctor Service;c:\program files\norton utilities 15\tools\disk doctor\DiskDoctorSrv.exe [2011-4-15 1029480] R2 NAV;Norton AntiVirus;c:\program files\norton antivirus\engine\17.8.0.5\ccsvchst.exe [2010-9-24 126392] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-7-28 105592] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\ipsdefs\20110824.030\IDSXpx86.sys [2011-8-26 356280] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20110825.032\NAVENG.SYS [2011-8-26 86136] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20110825.032\NAVEX15.SYS [2011-8-26 1576312] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-1-19 222976] S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\google\update\GoogleUpdate.exe [2009-5-17 133104] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [2009-5-21 16512] S3 cpuz132;cpuz132;\??\c:\docume~1\user\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\user\locals~1\temp\cpuz132\cpuz132_x32.sys [?] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-5-17 133104] S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?] S3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [2011-4-15 128248] S3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [2011-4-15 108800] S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [2011-5-29 229376] S4 SpeedDiskService;Norton SpeedDisk Service;c:\program files\norton utilities 15\tools\speeddisk\SpeedDiskSrv.exe [2011-4-15 1037672] . =============== Created Last 30 ================ . 2011-08-21 00:19:16 ——– d—–w- c:\program files\Audacity . ==================== Find3M ==================== . 2011-07-15 13:29:31 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys 2011-07-06 09:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-06 09:52:42 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-06-24 14:10:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36:30 916480 —-a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36:30 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05:13 385024 —-a-w- c:\windows\system32\html.iec 2011-06-20 17:44:52 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys 2011-04-15 00:10:31 21460432 —-a-w- c:\program files\15.0.0.122RC5_NUesd_MUI.exe 2008-04-13 14:10:32 96512 —-a-w- c:\program files\atapi.sys . ============= FINISH: 23:01:16.00 =============== 📎attach.zip📎attach.zip
Hi,

I am looking at one possible marker in your log for malware, lets do this.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please





OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7586

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

27/08/2011 8:47:34 PM
mbam-log-2011-08-27 (20-47-34).txt

Scan type: Quick scan
Objects scanned: 173564
Time elapsed: 22 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


OTL logfile created on: 27/08/2011 8:55:49 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 56.89% Memory free
3.84 Gb Paging File | 3.05 Gb Available in Paging File | 79.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 127.80 Gb Free Space | 42.88% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 325.91 Gb Free Space | 69.97% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.69 Gb Free Space | 5.45% Space Free | Partition Type: NTFS
Drive H: | 3.78 Gb Total Space | 3.17 Gb Free Space | 83.85% Space Free | Partition Type: FAT32

Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/08/27 17:31:02 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
PRC - [2010/11/30 02:23:44 | 001,029,480 | —- | M] (Symantec Corporation) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe
PRC - [2010/11/30 02:23:44 | 000,406,888 | —- | M] (Symantec Corporation) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe
PRC - [2010/02/26 10:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe
PRC - [2009/10/23 19:34:36 | 000,827,904 | —- | M] () – C:\Program Files\dvd43\DVD43_Tray.exe
PRC - [2009/10/11 07:07:08 | 000,320,832 | —- | M] (BillP Studios) – C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2008/04/14 22:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/06/13 04:20:00 | 000,127,036 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\DLA\DLACTRLW.EXE


========== Modules (No Company Name) ==========

MOD - [2010/02/06 04:27:45 | 001,291,776 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2009/10/23 19:34:36 | 000,827,904 | —- | M] () – C:\Program Files\dvd43\DVD43_Tray.exe
MOD - [2009/09/15 08:36:08 | 000,506,711 | —- | M] () – C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll
MOD - [2008/04/14 22:00:00 | 000,192,512 | —- | M] () – C:\WINDOWS\system32\qcap.dll
MOD - [2008/04/14 22:00:00 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2008/04/14 22:00:00 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/11/30 02:23:56 | 001,037,672 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe – (SpeedDiskService)
SRV - [2010/11/30 02:23:44 | 001,029,480 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe – (DiskDoctorService)
SRV - [2010/03/04 22:38:00 | 000,071,096 | —- | M] () [Disabled | Stopped] – C:\Program Files\CDBurnerXP\NMSAccessU.exe – (NMSAccess)
SRV - [2010/02/26 10:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe – (NAV)
SRV - [2008/01/29 16:09:02 | 000,394,704 | —- | M] (Symantec, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe – (Symantec RemoteAssist)
SRV - [2002/12/17 16:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 16:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)


========== Driver Services (SafeList) ==========

DRV - [2011/08/23 00:17:32 | 000,356,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110826.030\IDSXpx86.sys – (IDSxpx86)
DRV - [2011/08/04 12:46:24 | 001,576,312 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110826.025\NAVEX15.SYS – (NAVEX15)
DRV - [2011/08/04 12:46:23 | 000,086,136 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110826.025\NAVENG.SYS – (NAVENG)
DRV - [2011/07/28 09:00:04 | 000,374,392 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2011/07/28 09:00:04 | 000,105,592 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/07/23 10:27:23 | 000,815,736 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110812.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2010/11/30 02:24:00 | 000,108,800 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymSpeedDisk.sys – (SYMSpeedDisk)
DRV - [2010/11/30 02:23:58 | 000,128,248 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymDSMon.sys – (SymDSMon)
DRV - [2010/08/19 20:38:35 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/05/06 14:01:59 | 000,361,904 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS – (SYMTDI)
DRV - [2010/04/29 15:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS – (SymIRON)
DRV - [2010/04/22 13:02:20 | 000,173,104 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS – (SymEFA)
DRV - [2010/04/22 12:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS – (SRTSP)
DRV - [2010/04/22 12:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/26 10:22:57 | 000,501,888 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys – (ccHP)
DRV - [2010/02/04 11:40:47 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS – (SymDS)
DRV - [2009/11/12 13:48:56 | 000,007,168 | —- | M] () [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\StarOpen.sys – (StarOpen)
DRV - [2008/04/13 23:16:24 | 000,015,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\MPE.sys – (MPE)
DRV - [2008/03/11 21:37:00 | 000,036,864 | R— | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/03/06 20:42:16 | 000,530,944 | R— | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2008/02/14 16:12:02 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\monfilt.sys – (monfilt)
DRV - [2008/02/14 13:36:34 | 000,222,976 | R— | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2007/04/26 06:42:18 | 000,045,696 | R— | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2006/06/13 04:20:00 | 000,094,460 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/06/13 04:20:00 | 000,088,476 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/06/13 04:20:00 | 000,086,844 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/06/13 04:20:00 | 000,025,724 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/06/13 04:20:00 | 000,014,716 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/06/13 04:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/06/13 04:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2006/03/17 07:35:24 | 000,005,660 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/03/17 07:34:46 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2004/08/13 20:56:20 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2002/07/17 08:05:10 | 000,016,512 | —- | M] (Adaptec) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aspi32.sys – (ASPI32)
DRV - [2002/07/17 08:05:10 | 000,016,512 | —- | M] (Adaptec) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\aspi32.sys – (ASPI)
DRV - [1999/05/21 00:00:00 | 000,015,488 | —- | M] () [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\ScFBPNT2.sys – (ScFBPNT2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.abc.net.au/"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@csi.business.gov.au/CsiPlugin: C:\Program Files\Common-Use Signing Interface\bin\npCsiPlugin.dll (Commonwealth Government of Australia)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2011/07/20 12:42:39 | 000,000,000 | —D | M]

[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions\[removed]
[2010/04/02 16:02:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\[removed]

O1 HOSTS File: ([2011/05/28 15:41:59 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/27 17:30:54 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/08/27 12:24:52 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\TFC.exe
[2011/08/24 20:40:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2011/08/24 13:10:03 | 000,607,017 | R— | C] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/08/21 10:19:16 | 000,000,000 | —D | C] – C:\Program Files\Audacity
[2011/08/20 07:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/04/15 10:10:31 | 021,460,432 | —- | C] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/27 20:56:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/27 19:32:10 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/08/27 17:48:09 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/27 17:37:20 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/08/27 17:36:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/27 17:31:02 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/08/27 17:30:37 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\TFC.exe
[2011/08/26 23:04:31 | 000,005,288 | —- | M] () – C:\Documents and Settings\User\Desktop\attach.zip
[2011/08/24 13:10:08 | 000,607,017 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/08/21 10:19:18 | 000,000,630 | —- | M] () – C:\Documents and Settings\User\Desktop\Audacity.lnk
[2011/08/19 11:04:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/14 23:02:42 | 000,000,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/13 05:34:17 | 000,000,426 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2011/08/12 20:08:35 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/11 20:02:50 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/08/11 13:52:13 | 000,480,116 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/11 13:52:13 | 000,086,298 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/11 13:45:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/06 18:52:38 | 010,104,807 | —- | M] () – C:\Documents and Settings\User\Desktop\Jacks Run.mp4
[2011/08/06 14:49:29 | 000,010,713 | —- | M] () – C:\Documents and Settings\User\Desktop\all.png
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/26 23:04:31 | 000,005,288 | —- | C] () – C:\Documents and Settings\User\Desktop\attach.zip
[2011/08/21 10:19:17 | 000,000,636 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Audacity.lnk
[2011/08/21 10:19:17 | 000,000,630 | —- | C] () – C:\Documents and Settings\User\Desktop\Audacity.lnk
[2011/08/20 07:41:41 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/08/06 18:50:55 | 010,104,807 | —- | C] () – C:\Documents and Settings\User\Desktop\Jacks Run.mp4
[2011/08/06 14:50:21 | 000,010,713 | —- | C] () – C:\Documents and Settings\User\Desktop\all.png
[2011/06/22 11:17:36 | 000,078,820 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/02 16:37:25 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/04/15 10:16:07 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2010/10/15 10:11:16 | 000,001,940 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/15 10:06:11 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/26 23:32:20 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/23 13:04:52 | 000,000,146 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2010/05/23 13:04:52 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2010/05/23 13:04:33 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2010/05/23 13:04:32 | 000,009,853 | —- | C] () – C:\WINDOWS\HL-2170W.INI
[2010/05/23 13:04:28 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/05/23 13:04:28 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2170W.DAT
[2010/05/23 13:03:37 | 000,000,318 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,303,104 | —- | C] () – C:\WINDOWS\emunist.exe
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/07/14 13:15:00 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,610 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:34:52 | 000,020,450 | —- | C] () – C:\WINDOWS\SICALIB2.DAT
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 19:19:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/02/04 10:50:07 | 000,000,323 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 23:50:47 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/19 23:49:51 | 000,331,480 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/19 20:22:52 | 000,115,200 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:08:54 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/19 14:05:27 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 22:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 22:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 22:00:00 | 000,480,116 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 22:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 22:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 22:00:00 | 000,086,298 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 22:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 22:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 22:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 22:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 22:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 22:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/02/09 13:46:30 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll

========== LOP Check ==========

[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/05/18 09:57:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/09/21 12:31:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2010/04/14 12:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2011/07/21 19:40:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Easybits GO
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2010/11/09 15:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/11 13:02:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/09/27 10:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Socusoft
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/08/22 23:02:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/05/22 10:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2011/06/22 11:03:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2010/07/05 20:25:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\4Media
[2010/06/06 14:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aura4You
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/04/06 18:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canon Easy-WebPrint EX
[2010/08/13 10:52:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CD-LabelPrint
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2010/07/28 16:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2011/05/02 16:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FrostWire
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2011/07/21 19:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\go
[2010/11/09 15:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\MyHeritage
[2010/07/22 18:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NCH Swift Sound
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2010/04/16 18:49:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Nvu
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/06/26 16:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2010/08/20 10:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tific
[2010/05/29 22:53:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Desktop Search
[2010/07/06 22:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Search
[2010/04/11 17:50:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\WinPatrol
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A96964
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96D0C06F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D287FACF

OTL Extras logfile created on: 27/08/2011 8:55:49 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 56.89% Memory free
3.84 Gb Paging File | 3.05 Gb Available in Paging File | 79.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 127.80 Gb Free Space | 42.88% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 325.91 Gb Free Space | 69.97% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.69 Gb Free Space | 5.45% Space Free | Partition Type: NTFS
Drive H: | 3.78 Gb Total Space | 3.17 Gb Free Space | 83.85% Space Free | Partition Type: FAT32

Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1233:UDP" = 1233:UDP:*:Enabled:Windows Media Format SDK (svchost.exe)
"1232:UDP" = 1232:UDP:*:Enabled:Windows Media Format SDK (svchost.exe)
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Java\jre6\bin\rmiregistry.exe" = C:\Program Files\Java\jre6\bin\rmiregistry.exe:*:Disabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Disabled:Google Earth – (Google)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{110E7958-3EE1-4684-9168-CD5D73A2CDDD}" = Mirar
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4700_series" = Canon iP4700 series Printer Driver
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic UDF Reader
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{20C53FA2-4307-4671-A93F-9463B29DFCF1}" = Symantec Technical Support Web Controls
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{251C3815-7A55-4607-A82D-C3B98F0FBAB8}" = Sony Vegas 7.0
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 26
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5AE91C01-5906-11D5-A50C-006067797177}" = Cashflow Manager 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69352F8B-66AD-493C-9138-5FE0D300FB17}" = FIFA 09 Demo
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71A41426-C7A4-4DCF-A9ED-C5B4B105ED1D}" = Sony Media Manager 2.2
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9811A185-3D3D-11D6-9E14-00036D172B00}" = Adobe MPEG Encoder
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C897FCB3-2F8B-4185-8035-79E2AF3A92A4}" = iTunes
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Music Transfer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DD1E824B-0A7E-4777-B684-D09330E85C7A}" = Brother HL-2170W
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{FB3BE405-6BF0-490A-84B3-00611385EA0D}" = Common-Use Signing Interface
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"4Media DVD Creator 6" = 4Media DVD Creator 6
"4Videosoft DVD to QuickTime Converter_is1" = 4Videosoft DVD to QuickTime Converter
"Adobe AIR" = Adobe AIR
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Premiere 6.5" = Adobe Premiere 6.5
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"Audacity_is1" = Audacity 1.2.6
"Burn4Free CD & DVD_is1" = Burn4Free CD & DVD [removed]
"CanoCraft CS-P 3.7" = Canon CanoCraft CS-P 3.7
"Canon Setup Utility 2.0" = Canon Setup Utility 2.0
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Common-Use Signing Interface" = Common-Use Signing Interface
"Creative Mass Storage Drivers" = Creative Mass Storage Drivers
"DoremiSoft MPG to FLV Converter" = DoremiSoft MPG to FLV Converter 1.0
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD Shrink_is1" = DVD Shrink 3.2
"DVD43_is1" = DVD43 v4.6.0
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"Ewisoft Website Builder (include eCommerce Builder)_is1" = Ewisoft Website Builder (include eCommerce Builder) Version 5
"Flash Slideshow Maker Pro" = Flash Slideshow Maker Pro 5.00
"Freecorder4.02" = Freecorder 4.02 Application
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MuVo Driver" = Creative Mass Storage Drivers
"NAV" = Norton AntiVirus
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Norton Utilities 15_is1" = Norton Utilities 15
"Puran Defrag Free Edition_is1" = Puran Defrag Free Edition 7.3
"SmartDraw VP" = SmartDraw VP
"SMPlayer" = SMPlayer 0.6.7
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"Speccy" = Speccy
"SpywareBlaster_is1" = SpywareBlaster 4.3
"SysInfo" = Creative System Information
"TVEpaDrv" = Kaiser Baas USB VIDEO TO DVD MAKER Device Driver
"Ulead Photo Express 2.0 SE" = Ulead Photo Express 2.0 SE
"Ultra QuickTime Converter_is1" = Ultra QuickTime Converter 3.2.0104
"Uninstall_is1" = Uninstall 1.0.0.1
"VobSub" = VobSub v2.23 (Remove Only)
"WavePad" = WavePad Sound Editor
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinPatrol" = WinPatrol 2009
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xilisoft Audio Maker" = Xilisoft Audio Maker
"Xvid_is1" = Xvid 1.2.2 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Game Organizer" = EasyBits GO

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21/08/2011 9:31:26 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 21/08/2011 3:38:09 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)

Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)

Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application

Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)

Error - 22/08/2011 8:53:14 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)

Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)

Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application

Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)

Error - 23/08/2011 8:09:44 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

[ Application Events ]
Error - 21/08/2011 9:31:26 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 21/08/2011 3:38:09 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)

Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)

Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application

Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)

Error - 22/08/2011 8:53:14 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)

Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)

Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application

Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)

Error - 23/08/2011 8:09:44 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

[ System Events ]
Error - 26/08/2011 5:05:05 PM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NAV service.

Error - 26/08/2011 5:05:35 PM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NAV service.

Error - 26/08/2011 9:54:46 PM | Computer Name = OWNER-92DFBD76A | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022156E075E has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 26/08/2011 9:56:10 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 26/08/2011 9:56:10 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Creative Service for CDROM Access service terminated unexpectedly.
It has done this 1 time(s).

Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly.
It has done this 1 time(s).


< End of report >


< End of report >
You have ASK installed as your search engine, it should be uninstalled



* It promotes its toolbars on sites targeted at kids.
* It promotes its toolbars through ads that appear to be part of other companies' sites.
* It promotes its toolbars through other companies' spyware.
* It is Installed without any disclosure whatsoever and without any consent from the user whatsoever.
* It solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.
* It makes confusing changes to user's browsers - increasing Ask's revenues while taking users to pages they didn't intend to visit.


Lets check for a rootkit

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-08-28 10:39:06 —————————– 10:39:06.078 OS Version: Windows 5.1.2600 Service Pack 3 10:39:06.078 Number of processors: 4 586 0xF0B 10:39:06.078 ComputerName: OWNER-92DFBD76A UserName: User 10:39:09.546 Initialize success 10:39:38.140 AVAST engine defs: 11082701 10:39:48.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-6 10:39:48.171 Disk 0 Vendor: ST3320613AS SD22 Size: 305245MB BusType: 3 10:39:48.203 Disk 0 MBR read successfully 10:39:48.203 Disk 0 MBR scan 10:39:48.359 Disk 0 Windows XP default MBR code 10:39:48.359 Disk 0 scanning sectors +625121280 10:39:48.484 Disk 0 scanning C:\WINDOWS\system32\drivers 10:40:12.218 Service scanning 10:40:15.343 Modules scanning 10:40:36.593 Disk 0 trace - called modules: 10:40:36.609 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll dvd43llh.sys atapi.sys pciide.sys 10:40:36.609 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a853ab8] 10:40:36.609 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000072[0x8a88ba48] 10:40:36.609 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-6[0x8a857d98] 10:40:36.609 \Driver\atapi[0x8a8405a8] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> dvd43llh.sys[0xba3a9b20] 10:40:40.203 AVAST engine scan C:\WINDOWS 10:41:18.140 AVAST engine scan C:\WINDOWS\system32 10:48:45.703 AVAST engine scan C:\WINDOWS\system32\drivers 10:49:25.015 AVAST engine scan C:\Documents and Settings\User 11:20:52.015 AVAST engine scan C:\Documents and Settings\All Users 11:32:06.375 Scan finished successfully 11:32:57.671 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\User\Desktop\MBR.dat" 11:32:57.671 The log file has been saved successfully to "C:\Documents and Settings\User\Desktop\aswMBR.txt"
Hi


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
2011/08/28 13:57:49.0015 1840 TDSS rootkit removing tool 2.5.17.0 Aug 22 2011 15:46:57 2011/08/28 13:57:50.0015 1840 ================================================================================ 2011/08/28 13:57:50.0015 1840 SystemInfo: 2011/08/28 13:57:50.0015 1840 2011/08/28 13:57:50.0015 1840 OS Version: 5.1.2600 ServicePack: 3.0 2011/08/28 13:57:50.0015 1840 Product type: Workstation 2011/08/28 13:57:50.0015 1840 ComputerName: OWNER-92DFBD76A 2011/08/28 13:57:50.0015 1840 UserName: User 2011/08/28 13:57:50.0015 1840 Windows directory: C:\WINDOWS 2011/08/28 13:57:50.0015 1840 System windows directory: C:\WINDOWS 2011/08/28 13:57:50.0015 1840 Processor architecture: Intel x86 2011/08/28 13:57:50.0015 1840 Number of processors: 4 2011/08/28 13:57:50.0015 1840 Page size: 0x1000 2011/08/28 13:57:50.0015 1840 Boot type: Normal boot 2011/08/28 13:57:50.0015 1840 ================================================================================ 2011/08/28 13:58:02.0640 1840 Initialize success 2011/08/28 13:58:11.0718 1324 ================================================================================ 2011/08/28 13:58:11.0718 1324 Scan started 2011/08/28 13:58:11.0718 1324 Mode: Manual; 2011/08/28 13:58:11.0718 1324 ================================================================================ 2011/08/28 13:58:13.0734 1324 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/08/28 13:58:14.0093 1324 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/08/28 13:58:14.0625 1324 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/08/28 13:58:15.0078 1324 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys 2011/08/28 13:58:17.0093 1324 ASPI (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\System32\DRIVERS\ASPI32.sys 2011/08/28 13:58:17.0359 1324 ASPI32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\ASPI32.sys 2011/08/28 13:58:17.0578 1324 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/08/28 13:58:17.0921 1324 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys 2011/08/28 13:58:18.0406 1324 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/08/28 13:58:18.0703 1324 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/08/28 13:58:19.0062 1324 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/08/28 13:58:19.0500 1324 BHDrvx86 (f7ff24bb7714247f27b615b3a7d8b132) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110812.001\BHDrvx86.sys 2011/08/28 13:58:20.0078 1324 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/08/28 13:58:20.0375 1324 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/08/28 13:58:20.0859 1324 ccHP (e941e709847fa00e0dd6d58d2b8fb5e1) C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys 2011/08/28 13:58:21.0531 1324 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/08/28 13:58:21.0781 1324 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/08/28 13:58:22.0156 1324 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/08/28 13:58:23.0609 1324 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/08/28 13:58:24.0203 1324 DLABOIOM (a14524d3f130a57163e0b3e057fc85d5) C:\WINDOWS\system32\DLA\DLABOIOM.SYS 2011/08/28 13:58:24.0421 1324 DLACDBHM (7581407a6a3c56860ae31e6e423fe824) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 2011/08/28 13:58:24.0609 1324 DLADResN (7c4cdf8a684b63d7482e0bf7440dc3b5) C:\WINDOWS\system32\DLA\DLADResN.SYS 2011/08/28 13:58:24.0843 1324 DLAIFS_M (97bca2aac06a9fea56615b4b15bdb9b8) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 2011/08/28 13:58:25.0140 1324 DLAOPIOM (be8d558cf749424f0de612813f7c6725) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 2011/08/28 13:58:25.0312 1324 DLAPoolM (7e5277cb45dc5e2a86af8ce093c7ef31) C:\WINDOWS\system32\DLA\DLAPoolM.SYS 2011/08/28 13:58:25.0484 1324 DLARTL_N (693dfd92d41a3d270053cd97834e4960) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS 2011/08/28 13:58:25.0671 1324 DLAUDFAM (d886b6d02b51e5bd61b8a571a16d5ca2) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 2011/08/28 13:58:25.0890 1324 DLAUDF_M (2c0ecf7a9d5162d87c64e2ae868b5039) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 2011/08/28 13:58:26.0421 1324 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/08/28 13:58:27.0000 1324 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/08/28 13:58:27.0265 1324 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/08/28 13:58:27.0515 1324 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/08/28 13:58:27.0984 1324 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/08/28 13:58:28.0203 1324 DRVMCDB (73623d89faef4d1aa600edee8b490bc5) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 2011/08/28 13:58:28.0421 1324 DRVNDDM (2aeee1600d0f14ba535f90a1f4411b54) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 2011/08/28 13:58:28.0703 1324 dvd43llh (1fc1eed3ea0c3a0ecf8a95b97e1b4831) C:\WINDOWS\system32\DRIVERS\dvd43llh.sys 2011/08/28 13:58:29.0093 1324 eeCtrl (8f7dbc4be48f5388a6fe1f285e7948ef) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/08/28 13:58:29.0375 1324 EraserUtilRebootDrv (3ee14d400e0fdd0d214275a4a20b7022) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/08/28 13:58:29.0781 1324 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/08/28 13:58:30.0140 1324 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 2011/08/28 13:58:30.0328 1324 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/08/28 13:58:30.0562 1324 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/08/28 13:58:30.0859 1324 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2011/08/28 13:58:31.0171 1324 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/08/28 13:58:31.0531 1324 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/08/28 13:58:31.0781 1324 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 2011/08/28 13:58:32.0125 1324 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/08/28 13:58:32.0453 1324 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/08/28 13:58:32.0718 1324 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/08/28 13:58:33.0281 1324 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/08/28 13:58:34.0156 1324 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/08/28 13:58:36.0140 1324 ialm (cd32607f1cc8ac67224334ae123f7b98) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 2011/08/28 13:58:38.0421 1324 IDSxpx86 (e72d3894d42355e9cd5fd77e1e4fea11) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110826.030\IDSxpx86.sys 2011/08/28 13:58:38.0750 1324 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/08/28 13:58:39.0531 1324 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/08/28 13:58:39.0750 1324 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2011/08/28 13:58:40.0109 1324 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/08/28 13:58:40.0468 1324 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/08/28 13:58:40.0859 1324 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/08/28 13:58:41.0296 1324 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/08/28 13:58:41.0593 1324 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/08/28 13:58:41.0859 1324 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/08/28 13:58:42.0250 1324 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/08/28 13:58:42.0578 1324 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/08/28 13:58:42.0843 1324 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/08/28 13:58:43.0234 1324 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/08/28 13:58:43.0484 1324 L1e (303627228dd739d98289679901a38c8f) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys 2011/08/28 13:58:44.0203 1324 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/08/28 13:58:44.0406 1324 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/08/28 13:58:45.0125 1324 monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\monfilt.sys 2011/08/28 13:58:45.0750 1324 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/08/28 13:58:46.0078 1324 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/08/28 13:58:46.0281 1324 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/08/28 13:58:46.0531 1324 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys 2011/08/28 13:58:47.0078 1324 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/08/28 13:58:47.0609 1324 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/08/28 13:58:48.0156 1324 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/08/28 13:58:48.0375 1324 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/08/28 13:58:48.0625 1324 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/08/28 13:58:48.0859 1324 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/08/28 13:58:49.0250 1324 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/08/28 13:58:49.0500 1324 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/08/28 13:58:49.0765 1324 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys 2011/08/28 13:58:50.0156 1324 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 2011/08/28 13:58:50.0656 1324 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/08/28 13:58:52.0453 1324 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110827.002\NAVENG.SYS 2011/08/28 13:58:53.0531 1324 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110827.002\NAVEX15.SYS 2011/08/28 13:58:55.0656 1324 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/08/28 13:58:56.0500 1324 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/08/28 13:58:57.0468 1324 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/08/28 13:58:58.0750 1324 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/08/28 13:59:00.0109 1324 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/08/28 13:59:01.0343 1324 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/08/28 13:59:02.0468 1324 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/08/28 13:59:03.0187 1324 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/08/28 13:59:03.0859 1324 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/08/28 13:59:04.0796 1324 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/08/28 13:59:05.0781 1324 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/08/28 13:59:06.0437 1324 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/08/28 13:59:07.0343 1324 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/08/28 13:59:08.0421 1324 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/08/28 13:59:09.0140 1324 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/08/28 13:59:09.0671 1324 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/08/28 13:59:10.0281 1324 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/08/28 13:59:11.0281 1324 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/08/28 13:59:11.0734 1324 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/08/28 13:59:16.0609 1324 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/08/28 13:59:17.0515 1324 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/08/28 13:59:18.0296 1324 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/08/28 13:59:18.0890 1324 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/08/28 13:59:21.0203 1324 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/08/28 13:59:21.0531 1324 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/08/28 13:59:21.0843 1324 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/08/28 13:59:22.0140 1324 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/08/28 13:59:22.0359 1324 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/08/28 13:59:22.0640 1324 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/08/28 13:59:23.0015 1324 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/08/28 13:59:23.0328 1324 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/08/28 13:59:23.0609 1324 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 2011/08/28 13:59:23.0875 1324 ScFBPNT2 (50b724c9d03111245df270bc3f49f04d) C:\WINDOWS\system32\drivers\ScFBPNT2.SYS 2011/08/28 13:59:24.0250 1324 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/08/28 13:59:24.0609 1324 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/08/28 13:59:24.0828 1324 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/08/28 13:59:25.0406 1324 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/08/28 13:59:26.0093 1324 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/08/28 13:59:26.0734 1324 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/08/28 13:59:27.0234 1324 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/08/28 13:59:27.0734 1324 SRTSP (ec5c3c6260f4019b03dfaa03ec8cbf6a) C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS 2011/08/28 13:59:28.0171 1324 SRTSPX (55d5c37ed41231e3ac2063d16df50840) C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS 2011/08/28 13:59:28.0531 1324 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/08/28 13:59:28.0890 1324 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\WINDOWS\system32\drivers\StarOpen.sys 2011/08/28 13:59:29.0296 1324 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/08/28 13:59:29.0609 1324 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/08/28 13:59:29.0875 1324 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/08/28 13:59:30.0656 1324 SymDS (56890bf9d9204b93042089d4b45ae671) C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS 2011/08/28 13:59:31.0140 1324 SymDSMon (4c155fa65cbf81513e4b9d088737e9cf) C:\WINDOWS\system32\drivers\SymDSMon.sys 2011/08/28 13:59:31.0468 1324 SymEFA (1c91df5188150510a6f0cf78f7d94b69) C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS 2011/08/28 13:59:31.0812 1324 SymEvent (961b48b86f94d4cc8ceb483f8aa89374) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2011/08/28 13:59:32.0828 1324 SymIRON (dc80fbf0a348e54853ef82eed4e11e35) C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS 2011/08/28 13:59:33.0765 1324 SYMSpeedDisk (e9983667331d463f1e5b34f9170a9ae0) C:\WINDOWS\system32\drivers\SymSpeedDisk.sys 2011/08/28 13:59:34.0281 1324 SYMTDI (41aad61f87ca8e3b5d0f7fe7fba0797d) C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS 2011/08/28 13:59:35.0171 1324 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/08/28 13:59:35.0531 1324 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/08/28 13:59:36.0078 1324 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/08/28 13:59:36.0328 1324 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/08/28 13:59:36.0890 1324 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/08/28 13:59:38.0109 1324 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/08/28 13:59:39.0281 1324 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/08/28 13:59:40.0328 1324 USB28xxBGA (f0e0bd77c255c95d317cd69c2e8efb92) C:\WINDOWS\system32\DRIVERS\emBDA.sys 2011/08/28 13:59:41.0187 1324 USB28xxOEM (925e82ffe06a37799e5cb486528ed835) C:\WINDOWS\system32\DRIVERS\emOEM.sys 2011/08/28 13:59:41.0734 1324 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 2011/08/28 13:59:42.0140 1324 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/08/28 13:59:42.0406 1324 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/08/28 13:59:42.0703 1324 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/08/28 13:59:43.0156 1324 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/08/28 13:59:43.0406 1324 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/08/28 13:59:43.0687 1324 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/08/28 13:59:44.0093 1324 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/08/28 13:59:44.0328 1324 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/08/28 13:59:44.0687 1324 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 2011/08/28 13:59:45.0109 1324 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/08/28 13:59:45.0375 1324 VIAHdAudAddService (6b2c9ee4c16616e9398bbd0bc80ceb22) C:\WINDOWS\system32\drivers\viahduaa.sys 2011/08/28 13:59:45.0843 1324 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/08/28 13:59:46.0203 1324 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/08/28 13:59:46.0765 1324 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/08/28 13:59:47.0140 1324 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/08/28 13:59:47.0375 1324 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/08/28 13:59:47.0609 1324 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/08/28 13:59:47.0828 1324 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/08/28 13:59:48.0031 1324 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 2011/08/28 13:59:48.0500 1324 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR2 2011/08/28 13:59:48.0593 1324 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk2\DR8 2011/08/28 13:59:48.0593 1324 Boot (0x1200) (774cd9bc1fa49c1013ffbbc571e95cee) \Device\Harddisk0\DR0\Partition0 2011/08/28 13:59:48.0609 1324 Boot (0x1200) (d64696adb088b80317079382f625f7c9) \Device\Harddisk1\DR2\Partition0 2011/08/28 13:59:48.0625 1324 Boot (0x1200) (b4dc9037e303a23c0be4b1c5d93c2773) \Device\Harddisk2\DR8\Partition0 2011/08/28 13:59:48.0625 1324 ================================================================================ 2011/08/28 13:59:48.0625 1324 Scan finished 2011/08/28 13:59:48.0625 1324 ================================================================================ 2011/08/28 13:59:48.0640 1008 Detected object count: 0 2011/08/28 13:59:48.0640 1008 Actual detected object count: 0
Hi,

Sorry for the delay, been without power for a couple of days. Finally was restored this morning



Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2


[external image: Posted Image]


[external image: Posted Image]

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
computer will now not start up recieving error message - windows could not start up because the following file is corupt or missing cwindow\system32\config\system
Did you run Combofix, did it complete and reboot your system ? You may have a rootkit on board playing havoc with your system

  • Go to Start> Shut off your Computer> Restart
  • Or if the computer is off press the power button
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Last Known Good
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode



Do you have your windows CD or the Recovery CD that came with your system ?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI