This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log to check

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL log (Extras somehow did not come up):

OTL logfile created on: 9/7/2011 20:06:56 - Run 2
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\richtea\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.85 Gb Available Physical Memory | 62.95% Memory free
6.09 Gb Paging File | 4.75 Gb Available in Paging File | 78.10% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 181.32 Gb Free Space | 63.14% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.28 Gb Free Space | 11.75% Space Free | Partition Type: NTFS

Computer Name: HP2 | User Name: richtea | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\richtea\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\richtea\AppData\Local\Google\Update\1.3.21.65\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe (Privacyware/PWI, Inc.)
PRC - C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe (Privacyware/PWI, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\My Lockbox\mylbx.exe (FSPro Labs)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Windows\System32\sdclt.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\Program Files\My Lockbox\FSPFlt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (PFNet) – C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe (Privacyware/PWI, Inc.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (hpqddsvc) – C:\Program Files\HP\Photosmart R817\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqcxs08) – C:\Program Files\HP\Photosmart R817\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MpKsl14f1c111) – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{74D7ECBF-F9D2-41DC-BB26-7BE71DE9550F}\MpKsl14f1c111.sys (Microsoft Corporation)
DRV - (F-Secure Standalone Minifilter) – C:\Users\richtea\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys ()
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (pwipf6) – C:\Windows\System32\drivers\pwipf6.sys (Privacyware/PWI, Inc.)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (truecrypt) – C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (FSProFilter) – C:\Windows\System32\Drivers\FSPFltd.sys (FSPro Labs)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (IntcHdmiAddService) Intel® – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="
FF - prefs.js..browser.search.selectedEngine: "Ixquick HTTPS"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://ixquick.com/do/mypage.pl?prf=b845979a027bafb57da89364487ca393"
FF - prefs.js..extensions.enabledItems: [removed]:1.01
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.2
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="

FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\richtea\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\richtea\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/05 20:54:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/02 22:25:45 | 000,000,000 | —D | M]

[2009/10/05 19:19:47 | 000,000,000 | —D | M] (No name found) – C:\Users\richtea\AppData\Roaming\Mozilla\Extensions
[2011/09/05 18:43:57 | 000,000,000 | —D | M] (No name found) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions
[2010/05/04 15:43:03 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}(1885)
[2010/05/04 15:43:05 | 000,000,000 | —D | M] (NoScript) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(1886)
[2011/08/11 21:12:01 | 000,000,000 | —D | M] (FoxyProxy Standard) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\[removed]
[2010/01/09 18:04:27 | 000,000,000 | —D | M] (No name found) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\[removed]
[2011/01/09 17:51:49 | 000,001,832 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\bing.xml
[2010/01/03 01:25:07 | 000,000,939 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\dictionary.xml
[2010/01/03 01:27:01 | 000,002,060 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\eccellio-arts.xml
[2010/01/03 01:24:29 | 000,001,710 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\eccellio-movies.xml
[2010/01/03 01:29:24 | 000,002,443 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\google-scholar.xml
[2010/01/03 01:22:01 | 000,001,163 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\hollywoodcom.xml
[2010/01/03 01:22:13 | 000,001,512 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\imdb.xml
[2011/09/05 18:39:55 | 000,001,597 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\ixquick-https.xml
[2011/09/05 18:39:55 | 000,001,984 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\pixmac-search.xml
[2010/01/03 01:30:54 | 000,001,190 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\urban-dictionary.xml
[2010/01/03 01:22:47 | 000,001,232 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\yahoo-answers.xml
[2011/08/17 16:41:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/08/03 20:22:07 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\USERS\RICHTEA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FUJSEM93.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\USERS\RICHTEA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FUJSEM93.DEFAULT\EXTENSIONS\[removed]
[2011/09/05 20:54:59 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/03 20:21:36 | 000,611,224 | —- | M] (Oracle Corporation) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[1999/12/31 17:00:00 | 000,165,656 | —- | M] (Tracker Software Products Ltd.) – C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2010/01/01 10:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/09/05 19:03:32 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Privatefirewall] C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe (Privacyware/PWI, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: secunia.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\richtea\AppData\Roaming\IrfanView\IrfanView_Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\richtea\AppData\Roaming\IrfanView\IrfanView_Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/07 11:01:25 | 002,322,184 | —- | C] (ESET) – C:\Users\richtea\Desktop\esetsmartinstaller_enu(1).exe
[2011/09/05 21:03:10 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{BC8169FE-85BA-4132-BDD3-89E36B3211AB}
[2011/09/05 19:46:25 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Roaming\Malwarebytes
[2011/09/05 19:46:11 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/09/05 19:46:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/05 19:46:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/09/05 19:46:07 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/09/05 19:46:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/09/05 19:13:00 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/09/05 19:12:54 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/09/05 18:49:59 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/09/05 18:49:59 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/09/05 18:49:59 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/09/05 18:40:10 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/09/04 22:12:52 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{D2D3976A-BB48-4FCA-8B20-7C58E731116B}
[2011/09/04 22:02:50 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{E8F773C1-15A7-400C-B968-4351CA100FA4}
[2011/09/04 21:56:28 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{3D7BA22E-F5AA-4AEA-98EA-8236B64D0F3F}
[2011/08/24 23:24:06 | 000,000,000 | —D | C] – C:\Users\richtea\Desktop\ZHP
[2011/08/24 20:15:27 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{7123FBBF-5871-4EEA-979F-C992341ABF53}
[2011/08/24 20:08:25 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{F2641A41-F0F4-4335-9653-B15DAE74E161}
[2011/08/24 19:46:59 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{BD514528-4F52-4565-852D-966AA42F09FB}
[2011/08/24 19:42:01 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{20B8D3C8-C140-457C-A58C-097F3ECB5555}
[2011/08/23 22:13:00 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/08/23 22:12:48 | 000,000,000 | —D | C] – C:\Qoobox
[2011/08/23 21:47:07 | 004,195,009 | R— | C] (Swearware) – C:\Users\richtea\Desktop\ComboFix.exe
[2011/08/23 13:53:52 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\richtea\Desktop\OTL.exe
[2011/08/23 13:42:51 | 000,000,000 | —D | C] – C:\Users\richtea\Desktop\tdsskiller
[2011/08/19 23:28:37 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Roaming\MusicBee
[2011/08/19 23:25:36 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee
[2011/08/19 23:25:24 | 000,000,000 | —D | C] – C:\Program Files\MusicBee
[2011/08/19 19:46:53 | 000,122,760 | —- | C] (Privacyware/PWI, Inc.) – C:\Windows\System32\drivers\pwipf6.sys
[2011/08/19 19:46:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Privatefirewall 7.0
[2011/08/19 19:46:38 | 000,000,000 | —D | C] – C:\Program Files\Privacyware
[2011/08/18 22:38:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axantum AxCrypt
[2011/08/17 20:51:04 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{514D5BA7-4648-45FF-86CD-57EA709D1F4B}
[2011/08/17 20:50:05 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{83739872-229D-48DA-A719-1F487DC48CF0}
[2011/08/17 16:09:32 | 000,000,000 | —D | C] – C:\Program Files\Belarc
[2011/08/16 23:11:47 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{0789F593-5648-4D69-956B-63A161294387}
[2011/08/13 18:43:32 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{D1C90109-ED55-4575-B5D3-9C573355EFDB}
[2011/08/12 22:06:30 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{B7508487-A103-41C8-8331-0DA27B036C07}
[2011/08/12 22:05:31 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{DB37484D-D6B8-42D9-A6C3-E92EDE5AC1E7}
[2011/08/12 21:09:41 | 000,000,000 | —D | C] – C:\Windows\en
[2011/08/12 21:02:55 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{B7AE01F0-D696-4072-9DB4-BDF4B69D681A}
[2011/08/12 21:01:55 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{75B4D495-4A53-48E7-98AC-5717772DE2BB}
[2011/08/09 22:48:49 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/08/09 22:48:48 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/08/09 22:48:47 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/08/09 22:48:47 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/08/09 22:48:46 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/08/09 22:39:30 | 003,602,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/08/09 22:39:30 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/08/09 22:39:17 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/08/08 22:52:24 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{FDC8FB55-3B2E-45C4-81DE-5B780703F745}
[2011/08/08 22:15:54 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{74C39A60-BABC-4081-85BD-C55AD70F820C}
[2011/08/08 22:13:40 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{11383B92-D0B1-4AE7-AF1E-197F4B9FE086}
[2011/02/11 18:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2009/11/22 23:24:25 | 003,063,561 | —- | C] (Macromedia, Inc.) – C:\ProgramData\MobileTV.exe
[2009/11/22 23:24:24 | 002,989,660 | —- | C] (Macromedia, Inc.) – C:\ProgramData\DVD.exe
[2009/11/22 23:24:24 | 002,864,396 | —- | C] (Macromedia, Inc.) – C:\ProgramData\MPV.exe
[2009/11/22 23:24:24 | 002,331,174 | —- | C] (Macromedia, Inc.) – C:\ProgramData\Karaoke.exe
[2009/11/22 23:24:24 | 002,231,606 | —- | C] (Macromedia, Inc.) – C:\ProgramData\Games.exe
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/07 19:57:04 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000UA.job
[2011/09/07 19:56:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/07 15:20:23 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/07 15:20:23 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/07 11:01:26 | 002,322,184 | —- | M] (ESET) – C:\Users\richtea\Desktop\esetsmartinstaller_enu(1).exe
[2011/09/07 10:28:14 | 000,615,370 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/09/07 10:28:14 | 000,109,196 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/09/05 20:03:17 | 000,000,906 | —- | M] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/09/05 19:23:21 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2011/09/05 19:22:25 | 3149,074,432 | -HS- | M] () – C:\hiberfil.sys
[2011/09/05 19:03:32 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/09/05 18:49:23 | 004,195,009 | R— | M] (Swearware) – C:\Users\richtea\Desktop\ComboFix.exe
[2011/09/04 21:52:12 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000Core.job
[2011/09/04 21:37:32 | 000,000,330 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForrichtea.job
[2011/09/04 17:54:34 | 000,009,216 | —- | M] () – C:\Users\richtea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/04 17:12:07 | 000,007,728 | —- | M] () – C:\Users\richtea\AppData\Local\d3d9caps.dat
[2011/08/26 09:02:38 | 000,004,414 | —- | M] () – C:\Users\richtea\AppData\Roaming\wklnhst.dat
[2011/08/24 23:27:13 | 000,028,546 | —- | M] () – C:\Users\richtea\Desktop\ZHP.zip
[2011/08/23 13:53:55 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\richtea\Desktop\OTL.exe
[2011/08/22 22:41:34 | 000,302,093 | —- | M] () – C:\Users\richtea\AppData\Local\census.cache
[2011/08/22 22:41:31 | 000,155,469 | —- | M] () – C:\Users\richtea\AppData\Local\ars.cache
[2011/08/19 23:28:26 | 000,000,806 | —- | M] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\MusicBee.lnk
[2011/08/19 19:46:42 | 000,000,146 | —- | M] () – C:\Windows\ODBC.INI
[2011/08/18 18:36:41 | 000,002,401 | —- | M] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2011/08/17 16:37:05 | 000,001,845 | —- | M] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc.lnk
[2011/08/10 15:44:43 | 000,339,176 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/05 20:03:17 | 000,000,906 | —- | C] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/09/05 18:49:59 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/09/05 18:49:59 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/09/05 18:49:59 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/09/05 18:49:59 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/09/05 18:49:59 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/08/22 23:04:17 | 3149,074,432 | -HS- | C] () – C:\hiberfil.sys
[2011/08/19 23:28:26 | 000,000,806 | —- | C] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\MusicBee.lnk
[2011/08/18 23:06:18 | 000,302,093 | —- | C] () – C:\Users\richtea\AppData\Local\census.cache
[2011/08/18 23:05:59 | 000,155,469 | —- | C] () – C:\Users\richtea\AppData\Local\ars.cache
[2011/08/17 17:06:08 | 000,019,501 | —- | C] () – C:\Windows\WISR30B7.CAT
[2011/08/17 16:37:05 | 000,001,845 | —- | C] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc.lnk
[2011/08/17 16:09:33 | 000,001,857 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2011/08/14 20:39:08 | 000,028,546 | —- | C] () – C:\Users\richtea\Desktop\ZHP.zip
[2011/08/10 15:44:07 | 000,339,176 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2011/07/07 16:53:48 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/04/17 22:20:23 | 000,000,036 | —- | C] () – C:\Users\richtea\AppData\Local\housecall.guid.cache
[2011/03/19 22:57:43 | 000,000,095 | —- | C] () – C:\Users\richtea\AppData\Local\fusioncache.dat
[2011/03/19 18:07:05 | 000,072,918 | —- | C] () – C:\Windows\hpiins01.dat
[2010/10/01 00:18:20 | 000,000,146 | —- | C] () – C:\Windows\ODBC.INI
[2010/04/21 18:08:14 | 000,982,240 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2010/04/21 18:08:14 | 000,439,308 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2010/04/21 18:08:14 | 000,092,356 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2010/04/21 17:29:46 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2009/10/31 00:40:00 | 000,161,105 | —- | C] () – C:\Windows\hpqins00.dat
[2009/10/21 20:43:52 | 000,004,414 | —- | C] () – C:\Users\richtea\AppData\Roaming\wklnhst.dat
[2009/10/20 11:14:18 | 000,129,150 | —- | C] () – C:\Windows\hpiins06.dat
[2009/10/20 11:14:18 | 000,000,000 | —- | C] () – C:\Windows\hpimdl06.dat
[2009/10/18 04:48:51 | 000,009,216 | —- | C] () – C:\Users\richtea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/12 18:56:13 | 000,007,728 | —- | C] () – C:\Users\richtea\AppData\Local\d3d9caps.dat
[2009/10/11 18:22:43 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/10/11 18:22:42 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/10 13:08:03 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/04/22 16:10:21 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/03/05 07:54:58 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2008/07/06 22:29:46 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1518.dll
[2008/07/06 22:14:06 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2008/06/29 16:52:14 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2008/03/05 18:38:08 | 001,457,024 | —- | C] () – C:\Windows\System32\SSCProt.dll
[2006/11/02 14:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 14:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 12:33:01 | 000,615,370 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 12:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 12:33:01 | 000,109,196 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 12:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 12:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 10:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 10:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 09:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 09:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 11:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

========== LOP Check ==========

[2010/01/04 10:34:01 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Auslogics
[2011/03/20 16:15:48 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\f-secure
[2011/07/06 16:18:07 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\gtk-2.0
[2010/01/24 22:11:19 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\InfraRecorder
[2011/08/08 13:17:11 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\IrfanView
[2011/08/19 23:33:21 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\MusicBee
[2011/09/07 09:08:30 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Notepad++
[2009/10/27 13:58:50 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\OpenOffice.org
[2010/05/09 12:06:41 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\PhotoFiltre
[2010/04/17 17:59:08 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Picturenaut
[2011/04/12 20:32:02 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\QuickScan
[2009/10/21 20:44:05 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Template
[2010/03/16 08:51:03 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Tracker Software
[2010/12/19 23:57:37 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\TrueCrypt
[2010/05/30 22:27:18 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\WinPatrol
[2011/09/05 19:21:44 | 000,032,604 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 23:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 08:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2011/09/05 19:12:18 | 000,011,801 | —- | M] () – C:\ComboFix.txt
[2006/09/18 23:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/09/05 19:22:25 | 3149,074,432 | -HS- | M] () – C:\hiberfil.sys
[2011/09/05 19:22:24 | 3462,856,704 | -HS- | M] () – C:\pagefile.sys
[2011/08/10 12:46:03 | 000,012,520 | —- | M] () – C:\PureRa.txt
[2010/05/07 23:23:38 | 000,000,184 | —- | M] () – C:\setup.log
[2011/08/23 13:48:10 | 000,061,892 | —- | M] () – C:\TDSSKiller.2.5.17.0_23.08.2011_13.44.20_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 14:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 14:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 14:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/12 01:21:29 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 23:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/05 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD8O.DLL
[2007/03/18 20:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD8S.DLL
[2010/04/24 06:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2006/11/05 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP8O.DLL
[2007/03/18 20:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP8S.DLL
[2010/04/24 06:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP9W.DLL
[2006/11/02 14:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/27 04:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 04:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 05:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 05:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 05:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 12:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 12:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/09 18:39:20 | 000,000,337 | -HS- | M] () – C:\Users\richtea\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/05 18:49:23 | 004,195,009 | R— | M] (Swearware) – C:\Users\richtea\Desktop\ComboFix.exe
[2011/09/07 11:01:26 | 002,322,184 | —- | M] (ESET) – C:\Users\richtea\Desktop\esetsmartinstaller_enu(1).exe
[2011/08/23 13:53:55 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\richtea\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/08/22 22:08:30 | 000,008,192 | —- | M] () – C:\Windows\SECURITY\Database\edb.chk
[2011/08/22 22:08:30 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edb.log
[2011/08/22 22:02:28 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/08/22 22:02:28 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00002.jrs

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/10/05 19:07:30 | 000,000,402 | -HS- | M] () – C:\Users\richtea\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2009/11/22 23:24:24 | 002,989,660 | —- | M] (Macromedia, Inc.) – C:\ProgramData\DVD.exe
[2009/11/22 23:24:24 | 002,231,606 | —- | M] (Macromedia, Inc.) – C:\ProgramData\Games.exe
[2011/09/05 19:23:21 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2010/01/18 22:59:10 | 000,000,021 | —- | M] () – C:\ProgramData\hpqp.txt
[2011/03/20 01:58:27 | 000,004,820 | —- | M] () – C:\ProgramData\hpzinstall.log
[2009/11/22 23:24:24 | 002,331,174 | —- | M] (Macromedia, Inc.) – C:\ProgramData\Karaoke.exe
[2009/11/22 23:24:25 | 003,063,561 | —- | M] (Macromedia, Inc.) – C:\ProgramData\MobileTV.exe
[2009/11/22 23:24:24 | 002,864,396 | —- | M] (Macromedia, Inc.) – C:\ProgramData\MPV.exe
[2009/09/10 13:11:11 | 000,000,032 | —- | M] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/04/22 17:11:38 | 000,000,109 | —- | M] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2009/09/10 13:10:18 | 000,000,032 | —- | M] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/04/22 17:06:05 | 000,000,105 | —- | M] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2009/09/10 13:08:31 | 000,000,032 | —- | M] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/09/10 13:10:49 | 000,000,032 | —- | M] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/04/22 17:04:25 | 000,000,107 | —- | M] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2009/04/22 17:11:10 | 000,000,110 | —- | M] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2009/09/10 13:11:21 | 000,000,105 | —- | M] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-05 19:01:03

< End of report >


Will try to run WMP in various circumstances to see if the system is stable & report by tomorrow.
Problem remains. Running Windows Media Player on its own is fine, but as soon as I connect to the web, it is only a matter of time (short) before the system crashes. Another example is listening to MelodyGardot.com (in Chrome, presumably using Flash); as long as this is the only web traffic, things are OK. But when I open another tab and go to a website, down the system goes, with IRQL driver not equal or less notice. On reboot, the Privatefirewall does start up but strangely, in the All Traffic Allowed mode, although it is set to Filter Traffic. I also get a rather non-specific message that Windows had to close down unexpectedly & I would be informed if a solution is found. It makes me wonder if I this is a security problem, or compatibility issue.
I am not seeing any signs of malware in the log and all the automated scans are coming up clean.I suggest you try asking in our windows forum and the techs there may be able to help http://forums.whatthetech.com/index.php?showforum=119


Please do the following to clean up the tools we have used here.Delete Tdsskiller,f-secure and ESET and any logs you have





ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI