This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Slow, Odd Network Traffic

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Fairly recently I've had multiple issues pop up on my PC. The main problem is that I'm seeing very high CPU/memory usage (mostly due to svchost.exe) and have also noticed in my router log access to websites from my desktop even when browsers are closed. These sites include redirecting-here888.com, uiadverver.com among others.

I initially thought the svchost.exe issue might be MS automatic update, so I disabled that completed but am still seeing the issue.

Below is the log file from HijackThis. Thanks in advance for your help. JVR

====================

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:11:59 PM, on 9/16/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\lexpps.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jim\Local Settings\Temporary Internet Files\Content.IE5\O6Q9JBKY\HiJackThis[1].exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcher…d&%language
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: DCA - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
O3 - Toolbar: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100429 -Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 2.8; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
O4 - Startup: GoZone iSync.lnk = C:\Program Files\GoZone\GoZone_iSync.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra 'Tools' menuitem: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.kyw1060.com
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: www.phillies.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1263953748824
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} (Photo Upload Plugin Class) - http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://69.126.199.53:81/activex/AMC.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 13551 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)










  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Log file from TDSSKiller…found one malicious item 2011/09/18 14:48:59.0398 6092 TDSS rootkit removing tool 2.5.22.0 Sep 13 2011 15:55:17 2011/09/18 14:49:01.0054 6092 ================================================================================ 2011/09/18 14:49:01.0054 6092 SystemInfo: 2011/09/18 14:49:01.0054 6092 2011/09/18 14:49:01.0054 6092 OS Version: 5.1.2600 ServicePack: 3.0 2011/09/18 14:49:01.0054 6092 Product type: Workstation 2011/09/18 14:49:01.0054 6092 ComputerName: REYNOLDS 2011/09/18 14:49:01.0054 6092 UserName: Admin 2011/09/18 14:49:01.0054 6092 Windows directory: C:\WINDOWS 2011/09/18 14:49:01.0054 6092 System windows directory: C:\WINDOWS 2011/09/18 14:49:01.0054 6092 Processor architecture: Intel x86 2011/09/18 14:49:01.0054 6092 Number of processors: 2 2011/09/18 14:49:01.0054 6092 Page size: 0x1000 2011/09/18 14:49:01.0054 6092 Boot type: Normal boot 2011/09/18 14:49:01.0054 6092 ================================================================================ 2011/09/18 14:49:02.0913 6092 Initialize success 2011/09/18 14:49:05.0772 5472 ================================================================================ 2011/09/18 14:49:05.0772 5472 Scan started 2011/09/18 14:49:05.0772 5472 Mode: Manual; 2011/09/18 14:49:05.0772 5472 ================================================================================ 2011/09/18 14:49:07.0647 5472 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS 2011/09/18 14:49:07.0944 5472 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/09/18 14:49:08.0085 5472 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/09/18 14:49:08.0178 5472 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys 2011/09/18 14:49:08.0288 5472 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/09/18 14:49:08.0413 5472 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys 2011/09/18 14:49:08.0585 5472 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\System32\DRIVERS\agp440.sys 2011/09/18 14:49:08.0710 5472 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys 2011/09/18 14:49:08.0819 5472 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys 2011/09/18 14:49:08.0928 5472 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys 2011/09/18 14:49:09.0022 5472 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys 2011/09/18 14:49:09.0163 5472 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys 2011/09/18 14:49:09.0272 5472 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys 2011/09/18 14:49:09.0397 5472 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys 2011/09/18 14:49:09.0522 5472 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys 2011/09/18 14:49:09.0694 5472 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/09/18 14:49:09.0803 5472 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys 2011/09/18 14:49:09.0881 5472 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys 2011/09/18 14:49:10.0006 5472 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys 2011/09/18 14:49:10.0131 5472 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/09/18 14:49:10.0210 5472 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/09/18 14:49:10.0460 5472 ati2mtag (2d30381d718228d2841cf962e9e86499) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/09/18 14:49:10.0616 5472 atinevxx (d335e45bfa1bf0bf93a8d3c15d1fc0e1) C:\WINDOWS\system32\DRIVERS\atinevxx.sys 2011/09/18 14:49:10.0725 5472 ATITUNEP (4e09c36d16c5c310e9e8065385e743c2) C:\WINDOWS\system32\DRIVERS\atineuxx.sys 2011/09/18 14:49:10.0850 5472 ativraxx (866332d193898755dc955a4ad111ac89) C:\WINDOWS\system32\DRIVERS\atinraxx.sys 2011/09/18 14:49:10.0944 5472 ATIXSAudio (2bf5f72ad56964451b2e7b22aae389d1) C:\WINDOWS\system32\DRIVERS\atinesxx.sys 2011/09/18 14:49:11.0053 5472 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/09/18 14:49:11.0163 5472 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/09/18 14:49:11.0319 5472 BCMModem (41347688046d49cde0f6d138a534f73d) C:\WINDOWS\system32\DRIVERS\BCMSM.sys 2011/09/18 14:49:11.0428 5472 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/09/18 14:49:11.0819 5472 BHDrvx86 (09b8897ac84c49beabea75cf9fe1ab45) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110909.001\BHDrvx86.sys 2011/09/18 14:49:12.0194 5472 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys 2011/09/18 14:49:12.0272 5472 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/09/18 14:49:12.0366 5472 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/09/18 14:49:12.0444 5472 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys 2011/09/18 14:49:12.0538 5472 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/09/18 14:49:12.0678 5472 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/09/18 14:49:12.0788 5472 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/09/18 14:49:12.0991 5472 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys 2011/09/18 14:49:13.0163 5472 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys 2011/09/18 14:49:13.0272 5472 ctac32k (4c638290979600ae2ae329d1608ad2ec) C:\WINDOWS\system32\drivers\ctac32k.sys 2011/09/18 14:49:13.0428 5472 ctaud2k (cf5662375781f741513c169cd4094100) C:\WINDOWS\system32\drivers\ctaud2k.sys 2011/09/18 14:49:13.0569 5472 ctdvda2k (437f2b31ba8b6b264d38b4fe6682faec) C:\WINDOWS\system32\drivers\ctdvda2k.sys 2011/09/18 14:49:13.0694 5472 ctprxy2k (678849d1af0750f68dbdc185252d5926) C:\WINDOWS\system32\drivers\ctprxy2k.sys 2011/09/18 14:49:13.0772 5472 ctsfm2k (3a076ebfbbbd6879a78863944980da32) C:\WINDOWS\system32\drivers\ctsfm2k.sys 2011/09/18 14:49:13.0897 5472 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys 2011/09/18 14:49:13.0991 5472 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys 2011/09/18 14:49:14.0194 5472 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/09/18 14:49:14.0319 5472 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/09/18 14:49:14.0444 5472 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/09/18 14:49:14.0522 5472 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/09/18 14:49:14.0631 5472 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/09/18 14:49:14.0756 5472 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys 2011/09/18 14:49:15.0225 5472 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/09/18 14:49:15.0491 5472 drvmcdb (b15f9e526ba511a48b1b1b8537815740) C:\WINDOWS\system32\drivers\drvmcdb.sys 2011/09/18 14:49:15.0584 5472 drvnddm (b295700e684ed1984db1d6be40354421) C:\WINDOWS\system32\drivers\drvnddm.sys 2011/09/18 14:49:15.0756 5472 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 2011/09/18 14:49:16.0037 5472 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 2011/09/18 14:49:16.0178 5472 E100B (95974e66d3de4951d29e28e8bc0b644c) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2011/09/18 14:49:16.0350 5472 eeCtrl (8f7dbc4be48f5388a6fe1f285e7948ef) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/09/18 14:49:16.0491 5472 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys 2011/09/18 14:49:16.0616 5472 emupia (f7511cf63ef82f7227c03028a3abadb5) C:\WINDOWS\system32\drivers\emupia2k.sys 2011/09/18 14:49:16.0678 5472 EraserUtilRebootDrv (3ee14d400e0fdd0d214275a4a20b7022) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/09/18 14:49:16.0850 5472 EUSBMSD (3dc945a9abbfb2ecf268eed276e05fec) C:\WINDOWS\system32\DRIVERS\EUSBMSD.SYS 2011/09/18 14:49:16.0990 5472 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/09/18 14:49:17.0115 5472 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/09/18 14:49:17.0225 5472 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/09/18 14:49:17.0319 5472 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/09/18 14:49:17.0444 5472 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/09/18 14:49:17.0584 5472 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/09/18 14:49:17.0647 5472 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/09/18 14:49:17.0740 5472 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 2011/09/18 14:49:17.0850 5472 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/09/18 14:49:18.0037 5472 ha10kx2k (f24dd43adc784177b28984043bc022ab) C:\WINDOWS\system32\drivers\ha10kx2k.sys 2011/09/18 14:49:18.0162 5472 hap16v2k (ff65c807ea641ff7310a61be4dec6479) C:\WINDOWS\system32\drivers\hap16v2k.sys 2011/09/18 14:49:18.0256 5472 HidIr (bb1a6fb7d35a91e599973fa74a619056) C:\WINDOWS\system32\DRIVERS\hidir.sys 2011/09/18 14:49:18.0334 5472 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/09/18 14:49:18.0428 5472 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys 2011/09/18 14:49:18.0537 5472 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/09/18 14:49:18.0631 5472 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 2011/09/18 14:49:18.0725 5472 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys 2011/09/18 14:49:18.0803 5472 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/09/18 14:49:19.0131 5472 IDSxpx86 (e72d3894d42355e9cd5fd77e1e4fea11) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110917.031\IDSxpx86.sys 2011/09/18 14:49:19.0381 5472 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/09/18 14:49:19.0506 5472 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys 2011/09/18 14:49:19.0615 5472 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys 2011/09/18 14:49:19.0740 5472 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/09/18 14:49:19.0850 5472 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/09/18 14:49:19.0943 5472 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/09/18 14:49:20.0053 5472 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/09/18 14:49:20.0147 5472 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/09/18 14:49:20.0256 5472 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/09/18 14:49:20.0350 5472 IrBus (b43b36b382aea10861f7c7a37f9d4ae2) C:\WINDOWS\system32\DRIVERS\IrBus.sys 2011/09/18 14:49:20.0443 5472 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/09/18 14:49:20.0553 5472 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/09/18 14:49:20.0662 5472 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/09/18 14:49:20.0787 5472 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/09/18 14:49:20.0865 5472 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/09/18 14:49:20.0975 5472 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/09/18 14:49:21.0240 5472 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/09/18 14:49:21.0334 5472 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/09/18 14:49:21.0397 5472 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 2011/09/18 14:49:21.0475 5472 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/09/18 14:49:21.0600 5472 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/09/18 14:49:21.0662 5472 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/09/18 14:49:21.0756 5472 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys 2011/09/18 14:49:21.0881 5472 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/09/18 14:49:22.0021 5472 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/09/18 14:49:22.0178 5472 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/09/18 14:49:22.0287 5472 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/09/18 14:49:22.0381 5472 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/09/18 14:49:22.0443 5472 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/09/18 14:49:22.0553 5472 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/09/18 14:49:22.0646 5472 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/09/18 14:49:22.0756 5472 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 2011/09/18 14:49:22.0865 5472 MVDCODEC (04dd08f6c43d331c238197e7deaf0d5e) C:\WINDOWS\system32\DRIVERS\atinmdxx.sys 2011/09/18 14:49:22.0975 5472 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/09/18 14:49:23.0256 5472 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110917.007\NAVENG.SYS 2011/09/18 14:49:23.0381 5472 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110917.007\NAVEX15.SYS 2011/09/18 14:49:23.0631 5472 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/09/18 14:49:23.0709 5472 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/09/18 14:49:23.0959 5472 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/09/18 14:49:24.0053 5472 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/09/18 14:49:24.0162 5472 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/09/18 14:49:24.0365 5472 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/09/18 14:49:24.0443 5472 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/09/18 14:49:24.0521 5472 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/09/18 14:49:24.0709 5472 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/09/18 14:49:24.0803 5472 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/09/18 14:49:24.0943 5472 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/09/18 14:49:25.0115 5472 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/09/18 14:49:25.0396 5472 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/09/18 14:49:25.0631 5472 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/09/18 14:49:25.0740 5472 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/09/18 14:49:25.0912 5472 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/09/18 14:49:26.0037 5472 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys 2011/09/18 14:49:26.0178 5472 ossrv (f0184fe6069be1541a3d18c02a73d161) C:\WINDOWS\system32\drivers\ctoss2k.sys 2011/09/18 14:49:26.0256 5472 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys 2011/09/18 14:49:26.0349 5472 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/09/18 14:49:26.0412 5472 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/09/18 14:49:26.0521 5472 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/09/18 14:49:26.0599 5472 PCDCODEC (1a3e460843151029f98f87274fbb40ca) C:\WINDOWS\system32\DRIVERS\atinpdxx.sys 2011/09/18 14:49:26.0693 5472 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/09/18 14:49:26.0881 5472 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/09/18 14:49:27.0006 5472 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/09/18 14:49:27.0412 5472 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys 2011/09/18 14:49:27.0490 5472 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys 2011/09/18 14:49:27.0646 5472 PfModNT (c8a2d6ff660ac601b7bb9a9b16a5c25e) C:\WINDOWS\System32\drivers\PfModNT.sys 2011/09/18 14:49:27.0771 5472 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/09/18 14:49:27.0896 5472 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/09/18 14:49:27.0990 5472 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/09/18 14:49:28.0084 5472 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/09/18 14:49:28.0209 5472 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys 2011/09/18 14:49:28.0287 5472 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys 2011/09/18 14:49:28.0365 5472 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys 2011/09/18 14:49:28.0459 5472 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys 2011/09/18 14:49:28.0537 5472 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys 2011/09/18 14:49:28.0631 5472 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys 2011/09/18 14:49:28.0709 5472 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/09/18 14:49:28.0802 5472 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/09/18 14:49:28.0912 5472 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/09/18 14:49:29.0037 5472 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/09/18 14:49:29.0162 5472 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/09/18 14:49:29.0255 5472 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/09/18 14:49:29.0380 5472 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/09/18 14:49:29.0505 5472 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/09/18 14:49:29.0599 5472 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/09/18 14:49:29.0818 5472 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/09/18 14:49:29.0974 5472 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/09/18 14:49:30.0052 5472 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/09/18 14:49:30.0162 5472 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/09/18 14:49:30.0349 5472 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys 2011/09/18 14:49:30.0427 5472 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/09/18 14:49:30.0521 5472 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys 2011/09/18 14:49:30.0615 5472 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/09/18 14:49:30.0787 5472 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\System32\DRIVERS\sr.sys 2011/09/18 14:49:31.0130 5472 SRTSP (83726cf02eced69138948083e06b6eac) C:\WINDOWS\System32\Drivers\N360\0501000.01D\SRTSP.SYS 2011/09/18 14:49:31.0443 5472 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSPX.SYS 2011/09/18 14:49:31.0583 5472 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/09/18 14:49:31.0693 5472 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 2011/09/18 14:49:31.0865 5472 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 2011/09/18 14:49:32.0052 5472 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/09/18 14:49:32.0130 5472 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/09/18 14:49:32.0224 5472 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/09/18 14:49:32.0333 5472 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys 2011/09/18 14:49:32.0412 5472 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys 2011/09/18 14:49:32.0552 5472 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMDS.SYS 2011/09/18 14:49:32.0708 5472 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMEFA.SYS 2011/09/18 14:49:32.0880 5472 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2011/09/18 14:49:33.0162 5472 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\WINDOWS\system32\drivers\N360\0501000.01D\Ironx86.SYS 2011/09/18 14:49:33.0333 5472 SYMTDI (dec35ccaf7a222df918306cd2fdfbd39) C:\WINDOWS\System32\Drivers\N360\0501000.01D\SYMTDI.SYS 2011/09/18 14:49:33.0458 5472 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys 2011/09/18 14:49:33.0537 5472 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys 2011/09/18 14:49:33.0630 5472 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/09/18 14:49:33.0755 5472 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/09/18 14:49:33.0896 5472 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/09/18 14:49:34.0036 5472 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/09/18 14:49:34.0130 5472 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/09/18 14:49:34.0286 5472 tfsnboio (2aceb9567639ff2db9d862104a80227a) C:\WINDOWS\system32\dla\tfsnboio.sys 2011/09/18 14:49:34.0380 5472 tfsncofs (d9f936eac2a6d55e3de87bedff8137a9) C:\WINDOWS\system32\dla\tfsncofs.sys 2011/09/18 14:49:34.0458 5472 tfsndrct (0fd9805bc047ada2cff540d4b7fa71fb) C:\WINDOWS\system32\dla\tfsndrct.sys 2011/09/18 14:49:34.0521 5472 tfsndres (f8b907198e2540a4a340f1e6775f7b71) C:\WINDOWS\system32\dla\tfsndres.sys 2011/09/18 14:49:34.0615 5472 tfsnifs (fb11349b31346290d098941f0216cc45) C:\WINDOWS\system32\dla\tfsnifs.sys 2011/09/18 14:49:34.0693 5472 tfsnopio (1994265f3a90e23a9434bba687f1a069) C:\WINDOWS\system32\dla\tfsnopio.sys 2011/09/18 14:49:34.0771 5472 tfsnpool (0b3d2bd550aa63bfd25ae8c5afbf7f76) C:\WINDOWS\system32\dla\tfsnpool.sys 2011/09/18 14:49:34.0865 5472 tfsnudf (716edddba259a2d699332df95301edda) C:\WINDOWS\system32\dla\tfsnudf.sys 2011/09/18 14:49:34.0990 5472 tfsnudfa (a8ee7bbdd0b8c01e38221d0dca2e7aaa) C:\WINDOWS\system32\dla\tfsnudfa.sys 2011/09/18 14:49:35.0130 5472 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys 2011/09/18 14:49:35.0255 5472 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/09/18 14:49:35.0349 5472 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys 2011/09/18 14:49:35.0474 5472 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/09/18 14:49:35.0646 5472 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 2011/09/18 14:49:35.0740 5472 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/09/18 14:49:35.0849 5472 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/09/18 14:49:35.0990 5472 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/09/18 14:49:36.0115 5472 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/09/18 14:49:36.0255 5472 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/09/18 14:49:36.0349 5472 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/09/18 14:49:36.0443 5472 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/09/18 14:49:36.0568 5472 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/09/18 14:49:36.0661 5472 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys 2011/09/18 14:49:36.0771 5472 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys 2011/09/18 14:49:36.0880 5472 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/09/18 14:49:37.0052 5472 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/09/18 14:49:37.0177 5472 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys 2011/09/18 14:49:37.0318 5472 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/09/18 14:49:37.0505 5472 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 2011/09/18 14:49:37.0599 5472 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/09/18 14:49:37.0677 5472 MBR (0x1B8) (cdac57608c39097805c8c958f1f73d97) \Device\Harddisk0\DR0 2011/09/18 14:49:37.0693 5472 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.a (0) 2011/09/18 14:49:37.0708 5472 Boot (0x1200) (b9e81464156e28b66ed872da1925d8d6) \Device\Harddisk0\DR0\Partition0 2011/09/18 14:49:37.0724 5472 ================================================================================ 2011/09/18 14:49:37.0724 5472 Scan finished 2011/09/18 14:49:37.0724 5472 ================================================================================ 2011/09/18 14:49:37.0739 5464 Detected object count: 1 2011/09/18 14:49:37.0739 5464 Actual detected object count: 1 2011/09/18 14:50:29.0518 5464 \Device\Harddisk0\DR0 (Rootkit.Boot.Pihar.a) - will be cured after reboot 2011/09/18 14:50:29.0518 5464 \Device\Harddisk0\DR0 - ok 2011/09/18 14:50:29.0518 5464 Rootkit.Boot.Pihar.a(\Device\Harddisk0\DR0) - User select action: Cure 2011/09/18 14:50:36.0815 5564 Deinitialize success
OTL Log file (OTL.txt)

OTL logfile created on: 9/18/2011 2:58:16 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Admin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 75.05% Memory free
3.10 Gb Paging File | 2.40 Gb Available in Paging File | 77.53% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 18.31 Gb Free Space | 16.38% Space Free | Partition Type: NTFS

Computer Name: REYNOLDS | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Support.com\bin\tgcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
PRC - C:\WINDOWS\SYSTEM32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
MOD - C:\WINDOWS\SYSTEM32\cl31cl3.dll ()
MOD - C:\WINDOWS\SYSTEM32\dlbacnv4.dll ()
MOD - C:\WINDOWS\SYSTEM32\pdf995mon.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBAPP5C.DLL ()
MOD - C:\Program Files\Dell AIO Printer A940\ConvDIB.dll ()


========== Win32 Services (SafeList) ==========

SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – File not found
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (WMConnectCDS) – C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110909.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110917.031\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110917.007\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110917.007\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0501000.01D\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (IrBus) – C:\WINDOWS\SYSTEM32\DRIVERS\irbus.sys (Microsoft Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (ATITUNEP) – C:\WINDOWS\SYSTEM32\DRIVERS\atineuxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio) – C:\WINDOWS\SYSTEM32\DRIVERS\atinesxx.sys (ATI Technologies Inc.)
DRV - (atinevxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinevxx.sys (ATI Technologies Inc.)
DRV - (PCDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (MVDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (ativraxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ctdvda2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) – C:\WINDOWS\SYSTEM32\DRIVERS\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\DRIVERS\pfmodnt.sys (Creative Technology Ltd.)
DRV - (emupia) – C:\WINDOWS\SYSTEM32\DRIVERS\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctac32k.sys (Creative Technology Ltd)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EUSBMSD) – C:\WINDOWS\SYSTEM32\DRIVERS\EUSBMSD.SYS (SCM Microsystems Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=5: C:\Program Files\Google\Google Updater\1.2.567.20382\npCIDetect5.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2011/08/29 11:18:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_1_3 [2011/09/18 14:52:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/24 22:18:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/02 17:17:56 | 000,000,000 | —D | M]

[2011/09/04 10:39:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/18 16:39:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/22 06:57:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/08/24 16:36:17 | 000,002,197 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google-search.xml

O1 HOSTS File: ([2008/08/18 19:43:06 | 000,020,712 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 0.0.0.0 www.doubleclick.net
O1 - Hosts: 0.0.0.0 ad.preferances.com
O1 - Hosts: 0.0.0.0 ad.doubleclick.com
O1 - Hosts: 0.0.0.0 ads.web.aol.com
O1 - Hosts: 0.0.0.0 ad.preferences.com
O1 - Hosts: 0.0.0.0 ad.washingtonpost.com
O1 - Hosts: 0.0.0.0 adpick.switchboard.com
O1 - Hosts: 0.0.0.0 ads.doubleclick.com
O1 - Hosts: 0.0.0.0 ads.infospace.com
O1 - Hosts: 0.0.0.0 ads.msn.com
O1 - Hosts: 0.0.0.0 ads.switchboard.com
O1 - Hosts: 0.0.0.0 ads.enliven.com
O1 - Hosts: 0.0.0.0 oz.valueclick.com
O1 - Hosts: 0.0.0.0 doubleclick.net
O1 - Hosts: 0.0.0.0 ads.doubleclick.net
O1 - Hosts: 0.0.0.0 ad2.doubleclick.net
O1 - Hosts: 0.0.0.0 ad3.doubleclick.net
O1 - Hosts: 0.0.0.0 ad4.doubleclick.net
O1 - Hosts: 0.0.0.0 ad5.doubleclick.net
O1 - Hosts: 0.0.0.0 ad6.doubleclick.net
O1 - Hosts: 0.0.0.0 ad7.doubleclick.net
O1 - Hosts: 0.0.0.0 ad8.doubleclick.net
O1 - Hosts: 0.0.0.0 ad9.doubleclick.net
O1 - Hosts: 0.0.0.0 ad10.doubleclick.net
O1 - Hosts: 693 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll (Compete, Inc.)
O2 - BHO: (Upromise TurboSaver) - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter File not found
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [Sonic RecordNow!] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra 'Tools' menuitem : Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} https://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1263953748824 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://69.126.199.53:81/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB (Reg Error: Key error.)
O16 - DPF: ppctlcab http://www.pestscan.com/scanner/ppctlcab.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CE910A3A-E4CB-42EF-B86F-01A2AE78491A}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - (WRLogonNTF.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/08/08 15:47:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SsiEfr.e)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: wave - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/09/18 14:55:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Adobe
[2011/09/18 14:55:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Admin\PrivacIE
[2011/09/18 14:55:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\Google
[2011/09/18 14:55:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Google
[2011/09/18 14:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Desktop\tdsskiller
[2011/09/18 14:48:01 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2011/09/18 14:12:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Apple Computer
[2011/09/18 14:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\GTek
[2011/09/18 14:11:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\Apple Computer
[2011/09/18 14:08:14 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Admin\IETldCache
[2011/09/18 14:07:10 | 000,000,000 | –SD | C] – C:\Documents and Settings\Admin\Application Data\Microsoft
[2011/09/18 14:07:10 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Admin\Application Data
[2011/09/18 14:07:10 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Favorites
[2011/09/18 14:07:10 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Admin\Cookies
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Sun
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Sonic
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Real
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Macromedia
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Identities
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Desktop
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Creative
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\ApplicationHistory
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2011/09/18 14:07:09 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Admin\SendTo
[2011/09/18 14:07:09 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Admin\Recent
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Startup
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Start Menu
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents\My Pictures
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents\My Music
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Accessories
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\Templates
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\PrintHood
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\NetHood
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\Local Settings
[2011/09/18 14:07:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Dell Accessories
[2011/09/08 20:11:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Glary Utilities
[2011/09/08 20:11:38 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2011/09/08 20:03:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/09/05 08:36:46 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/09/05 08:36:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/05 08:36:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/09/05 08:36:41 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/05 08:36:41 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/09/03 06:17:37 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/09/01 08:32:14 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2011/08/31 16:00:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/08/31 14:31:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Real
[2011/08/30 20:51:51 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/08/30 08:27:29 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/08/29 11:38:16 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/08/29 11:20:57 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2003/11/10 09:35:11 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/18 14:57:00 | 000,000,564 | —- | M] () – C:\WINDOWS\tasks\PCDoctorBackgroundMonitorTask.job
[2011/09/18 14:55:24 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/09/18 14:54:00 | 000,000,432 | —- | M] () – C:\WINDOWS\tasks\SystemToolsDailyTest.job
[2011/09/18 14:53:44 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/09/18 14:52:34 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc7170fa92ab76.job
[2011/09/18 14:52:34 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/09/18 14:52:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/09/18 14:52:07 | 2683,375,616 | -HS- | M] () – C:\hiberfil.sys
[2011/09/18 14:51:18 | 000,030,932 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/18 14:51:18 | 000,030,932 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/18 14:51:18 | 000,030,600 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/18 14:51:18 | 000,030,600 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/18 14:51:18 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/09/18 14:51:18 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/09/18 14:51:18 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2011/09/18 14:51:18 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2011/09/18 14:50:38 | 004,481,358 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2011/09/18 14:48:06 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2011/09/18 14:47:36 | 001,388,161 | —- | M] () – C:\Documents and Settings\Admin\Desktop\tdsskiller.zip
[2011/09/18 14:42:17 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/18 14:10:15 | 000,000,815 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/17 15:53:06 | 000,000,696 | —- | M] () – C:\WINDOWS\DELLSTAT.INI
[2011/09/13 20:43:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/05 14:44:11 | 000,000,209 | RHS- | M] () – C:\BOOT.INI
[2011/09/03 06:17:37 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/08/26 23:40:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/24 21:39:37 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/18 14:47:11 | 001,388,161 | —- | C] () – C:\Documents and Settings\Admin\Desktop\tdsskiller.zip
[2011/09/18 14:10:14 | 000,000,803 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Internet Explorer.lnk
[2011/09/18 14:09:28 | 000,000,792 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Windows Media Player.lnk
[2011/09/18 14:07:12 | 000,001,612 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Sonic MyDVD.lnk
[2011/09/18 14:07:12 | 000,001,298 | —- | C] () – C:\Documents and Settings\Admin\Desktop\Media Center.lnk
[2011/09/18 14:07:12 | 000,000,815 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/18 14:07:12 | 000,000,742 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/09/18 14:07:12 | 000,000,708 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/09/18 14:07:12 | 000,000,669 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk
[2011/09/18 14:07:12 | 000,000,079 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/09/18 14:07:11 | 000,000,136 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\fusioncache.dat
[2011/09/18 14:07:10 | 000,001,503 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Remote Assistance.lnk
[2011/09/18 14:07:10 | 000,000,738 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Outlook Express.lnk
[2011/09/12 13:25:34 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc7170fa92ab76.job
[2011/09/09 20:08:05 | 2683,375,616 | -HS- | C] () – C:\hiberfil.sys
[2011/09/08 20:11:43 | 000,000,308 | —- | C] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/05/22 00:00:23 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/04/13 19:22:56 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/04/13 19:22:56 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/04/12 16:00:01 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/03/03 18:41:57 | 000,292,984 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/11/10 18:06:15 | 000,069,076 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/09/26 15:58:10 | 000,479,232 | —- | C] () – C:\WINDOWS\ssndii.exe
[2009/09/26 15:55:38 | 000,022,723 | —- | C] () – C:\WINDOWS\System32\cl31cl3.dll
[2008/07/02 19:02:36 | 000,000,294 | —- | C] () – C:\WINDOWS\EReg077.dat
[2008/07/02 18:35:19 | 000,000,647 | —- | C] () – C:\WINDOWS\hegames.ini
[2007/05/13 20:58:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2007/01/04 20:19:40 | 000,001,168 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/06/30 16:41:04 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2006/06/24 11:21:08 | 000,006,638 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/21 22:44:50 | 000,809,233 | -HS- | C] () – C:\WINDOWS\System32\aycdd.ini2
[2006/03/09 20:36:32 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/03/09 20:36:32 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006/03/07 13:26:51 | 000,421,227 | -HS- | C] () – C:\WINDOWS\System32\aycdd.ini
[2005/12/15 19:54:14 | 000,000,021 | —- | C] () – C:\WINDOWS\DVDSentry.ini
[2005/09/13 18:27:08 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlbacnv4.dll
[2005/06/11 21:30:01 | 000,000,137 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2005/05/02 21:11:23 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2004/09/26 21:46:38 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/13 19:19:28 | 000,000,356 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2004/06/21 20:04:17 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2004/02/04 21:39:07 | 000,000,048 | —- | C] () – C:\WINDOWS\wpd99.drv
[2004/01/31 09:17:53 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\pdfmona.dll
[2004/01/31 09:17:53 | 000,050,364 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2004/01/19 22:18:59 | 000,020,924 | —- | C] () – C:\WINDOWS\unins000.dat
[2003/12/06 15:57:04 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2003/11/24 22:15:40 | 000,000,082 | —- | C] () – C:\WINDOWS\MPLAYER.INI
[2003/11/24 22:11:35 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[2003/11/24 22:11:35 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2003/11/24 21:23:19 | 000,000,030 | —- | C] () – C:\WINDOWS\INTURS.DAT
[2003/11/24 21:05:13 | 000,000,078 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/11/24 21:04:42 | 000,000,165 | —- | C] () – C:\WINDOWS\Quicken.ini
[2003/11/23 21:53:11 | 000,000,696 | —- | C] () – C:\WINDOWS\DELLSTAT.INI
[2003/11/12 04:54:00 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/11/10 10:01:08 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/11/10 09:44:23 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/11/10 09:42:04 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2003/11/10 09:42:04 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2003/11/10 09:38:07 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2003/11/10 09:35:35 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2003/11/10 09:35:35 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2003/11/10 09:35:12 | 000,232,723 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2003/11/10 09:35:12 | 000,190,842 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2003/11/10 09:35:12 | 000,138,716 | —- | C] () – C:\WINDOWS\System32\ctbas2w.dat
[2003/11/10 09:35:12 | 000,110,720 | —- | C] () – C:\WINDOWS\System32\CTBASICW.DAT
[2003/11/10 09:35:12 | 000,066,807 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2003/11/10 09:35:12 | 000,053,674 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2003/11/10 09:35:12 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2003/11/10 09:35:12 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2003/11/10 09:35:11 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2003/11/10 09:35:11 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2003/11/10 09:35:11 | 000,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2003/11/10 09:35:11 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2003/11/10 09:35:10 | 000,000,184 | —- | C] () – C:\WINDOWS\System32\e000001.dat
[2003/11/10 09:35:07 | 000,831,600 | —- | C] () – C:\WINDOWS\System32\Ctaa1.dat
[2003/11/10 09:34:42 | 000,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2003/11/10 09:34:09 | 000,000,264 | —- | C] () – C:\WINDOWS\wininit.ini
[2003/11/10 09:12:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2003/11/10 09:10:00 | 000,515,814 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2003/11/10 09:10:00 | 000,102,766 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2003/11/10 08:50:16 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:54:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/08/08 17:27:48 | 000,330,688 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/08/08 17:26:58 | 000,000,791 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2003/08/08 15:47:20 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/08/08 15:41:52 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2003/07/30 09:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2003/07/30 09:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2003/07/30 09:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2003/07/30 09:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2003/07/30 09:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2003/07/30 09:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/07/30 09:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2003/02/17 19:00:42 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbavs.dll
[2003/02/17 19:00:36 | 000,000,177 | —- | C] () – C:\WINDOWS\System32\dlbacoin.ini
[2003/02/05 13:11:12 | 000,000,126 | —- | C] () – C:\WINDOWS\System32\DLBAPLC.INI
[2003/01/07 17:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 17:07:14 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2001/08/23 17:07:02 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[1980/01/01 02:00:00 | 000,303,104 | —- | C] () – C:\WINDOWS\System32\ati2evxx.exe
[1980/01/01 02:00:00 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll

========== LOP Check ==========

[2003/11/10 09:29:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/04/18 14:11:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/05/24 16:07:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCDr
[2007/11/16 07:13:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/07/07 21:51:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/13 19:23:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2011/09/08 20:03:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2010/04/02 19:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/11 20:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/10 19:08:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/09/18 14:52:34 | 000,000,308 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
[2011/09/18 14:55:24 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/09/18 14:57:00 | 000,000,564 | —- | M] () – C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/09/18 15:07:00 | 000,000,432 | —- | M] () – C:\WINDOWS\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2003/08/08 15:47:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/11/24 15:48:04 | 000,006,922 | —- | M] () – C:\background.bmp
[2006/01/10 17:44:00 | 000,008,214 | —- | M] () – C:\backgroundb.bmp
[2011/09/05 14:44:11 | 000,000,209 | RHS- | M] () – C:\BOOT.INI
[2003/08/08 15:20:20 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2003/08/08 15:47:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2003/11/10 08:56:26 | 000,005,870 | RH– | M] () – C:\DELL.SDR
[2004/06/11 22:11:13 | 000,000,051 | —- | M] () – C:\DVDPATH.TXT
[2011/09/18 14:52:07 | 2683,375,616 | -HS- | M] () – C:\hiberfil.sys
[2005/12/09 15:52:34 | 000,000,824 | —- | M] () – C:\highlight.bmp
[2003/08/08 17:36:14 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2003/08/08 15:47:32 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2003/11/10 09:39:39 | 000,000,868 | -H– | M] () – C:\IPH.PH
[2005/12/09 15:52:34 | 000,004,664 | —- | M] () – C:\logo.bmp
[2004/04/27 18:18:12 | 000,874,368 | —- | M] () – C:\MSDElog.log
[2003/08/08 15:47:32 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/09/27 06:28:08 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/04 22:02:44 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2011/09/18 14:52:01 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2005/11/10 21:07:00 | 000,000,824 | —- | M] () – C:\popupblocker003.bmp
[2005/11/10 21:07:00 | 000,000,824 | —- | M] () – C:\popupblocker004.bmp
[2006/03/15 22:06:00 | 008,194,514 | —- | M] (Network Associates, Inc.) – C:\sdat4719.exe
[2006/04/10 20:33:33 | 008,286,905 | —- | M] (Network Associates, Inc.) – C:\sdat4737.exe
[2005/11/10 21:07:00 | 000,000,824 | —- | M] () – C:\search.bmp
[2005/11/10 21:07:00 | 000,000,824 | —- | M] () – C:\search013.bmp
[2006/03/16 20:45:01 | 005,037,072 | —- | M] (Safer Networking Limited ) – C:\spybotsd14.exe
[2006/04/10 20:48:01 | 000,001,103 | —- | M] () – C:\SuperDAT.log
[2003/11/10 09:40:45 | 000,000,087 | —- | M] () – C:\SystemInfo.ini

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/08/08 15:46:44 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/08/13 05:40:19 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\spool\prtprocs\w32x86\cl31cpc.dll
[2003/02/17 19:00:42 | 000,077,824 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\DLBAPP5C.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 17:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/08/08 15:34:02 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2003/08/08 15:34:02 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2003/08/08 15:34:02 | 000,401,408 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/04 22:09:57 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2003/11/10 09:16:38 | 000,000,310 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\convert.log

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/09/18 14:10:07 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2003/08/08 15:54:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/09/18 14:48:06 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/09/18 14:10:07 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Admin\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/09/18 14:55:52 | 000,032,768 | —- | M] () – C:\Documents and Settings\Admin\Cookies\INDEX.DAT

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-10 00:25:07

< >

< End of report >
OTL (Extras.txt)

OTL Extras logfile created on: 9/18/2011 2:58:16 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Admin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 75.05% Memory free
3.10 Gb Paging File | 2.40 Gb Available in Paging File | 77.53% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 18.31 Gb Free Space | 16.38% Space Free | Partition Type: NTFS

Computer Name: REYNOLDS | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Setup.exe" = D:\Setup.exe:*:Enabled:Setup Wizard of WRT55AG
"C:\Program Files\Linksys\LogViewer\LogViewer.exe" = C:\Program Files\Linksys\LogViewer\LogViewer.exe:*:Enabled:LogViewer
"C:\Program Files\Support.com\bin\tgcmd.exe" = C:\Program Files\Support.com\bin\tgcmd.exe:*:Enabled:Support.com Scheduler and Command Dispatcher – (SupportSoft, Inc.)
"C:\Documents and Settings\Jim\Local Settings\Temp\Temporary Directory 1 for LogViewerv1.14[1].zip\Log Viewer v1.14.exe" = C:\Documents and Settings\Jim\Local Settings\Temp\Temporary Directory 1 for LogViewerv1.14[1].zip\Log Viewer v1.14.exe:*:Enabled:Log Viewer
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealOne Player – (RealNetworks, Inc.)
"C:\Program Files\Savings Bond Wizard\SBWizard.exe" = C:\Program Files\Savings Bond Wizard\SBWizard.exe:*:Enabled:Savings Bond Wizard – (U.S. Department of the Treasury)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0DA9061C-A8C6-4B0E-BF2B-1E444D8642E3}" = Sonic PrimeTime
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic UDF Reader
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 23
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"{410438A3-B591-4028-B70A-3CC0B33FBCD1}" =
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{4468EF97-A253-4699-9E1C-88CAE2C6832D}" = ABBYY FineReader 5.0 Sprint
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4E6F4A97-631B-4C11-80AC-80111B64A909}" = ATIMCEE
"{51F96AEC-D902-4434-A0DC-B9692A21AE7C}" = MobileMe Control Panel
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = Sonic MyDVD
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{66563AD8-637B-407F-BCA7-0233A16891AB}" = Business Contact Manager for Outlook 2003
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7E6066E6-8B5B-4100-B0FA-1D9E9B663CBA}" = iTunes
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0901)
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B2CFE3B-7F55-4786-A20D-BB244914F6D8}" = EarthLink Setup Files
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.0
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB4EDC19-3B5E-4838-80E7-92454323B0FE}" = Garmin VoiceStudio v2.10
"{AC76BA86-7AD7-1033-7B44-A83000000003}" = Adobe Reader 8.3.0
"{B136E4A4-7660-4F15-9752-EF8E6BA7866D}" = Family Tree Maker 2005
"{B1AD83A0-DC92-41E3-B111-E9472349768C}" = RollerCoaster Tycoon 2: Wacky Worlds
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B609E018-8A33-4BA9-B3D4-C1FD5AECB88C}" = Greeting Card Factory Deluxe 2.0
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{D9DA2DF6-8CB6-4E3C-A29E-FAECFBA3E9A7}" = Garmin POI Loader
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E82BF103-904F-49C0-B77F-6EC110B71E87}" = Sound Blaster Audigy 2
"{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}" = Garmin Communicator Plugin
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"America Online us" = America Online (Choose which version to remove)
"AolCoach" = AOL Coach Version 1.0(Build:20030807.3)
"ATI Display Driver" = ATI Display Driver
"AXIS Media Control Embedded" = AXIS Media Control Embedded
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"comcastDD" = Desktop Doctor
"Dell AIO Printer A940" = Dell AIO Printer A940
"Dell Support Center" = Dell Support Center
"exPressit S.E. 2.1" = exPressit S.E. 2.1
"Family Tree Maker" = Family Tree Maker 9.0
"Glary Utilities_is1" = Glary Utilities 2.37.0.1260
"Google Updater" = Google Updater
"GoZone iSync" = GoZone iSync
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"InstallShield_{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"InstallShield_{4E6F4A97-631B-4C11-80AC-80111B64A909}" = ATIMCEE
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LiveUpdate" = LiveUpdate 1.90 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"N360" = Norton Security Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenMG HotFix4.5-06-05-10-01" = OpenMG Limited Patch 4.5-06-05-12-01
"Pdf995" = Pdf995
"Picasa 3" = Picasa 3
"PROSet" = Intel® PRO Network Connections Drivers
"Reader Rabbit's Preschool" = Reader Rabbit's Preschool
"RealPlayer 6.0" = RealPlayer
"Samsung CLP-310 Series" = Samsung CLP-310 Series
"Savings Bond Wizard" = Savings Bond Wizard
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Upromise TurboSaver" = Upromise TurboSaver (remove only)
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Webshots Desktop" = Webshots Desktop
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-1.2.3_is1" = The GIMP 1.2.5-20030729-1
"WinGTK-1.3_is1" = GTK+ 1.3.0-20030717-1 runtime environment
"WMCSetup" = Windows Media Connect
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Zoo Tycoon 1.0" = Zoo Tycoon Expanded

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/7/2011 9:51:45 AM | Computer Name = REYNOLDS | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 9/7/2011 9:51:45 AM | Computer Name = REYNOLDS | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1485391

Error - 9/7/2011 9:51:45 AM | Computer Name = REYNOLDS | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1485391

Error - 9/8/2011 8:33:16 AM | Computer Name = REYNOLDS | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module urlmon.dll, version 8.0.6001.19100, fault address 0x000062f4.

Error - 9/11/2011 8:52:17 PM | Computer Name = REYNOLDS | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module Flash10t.ocx, version 10.3.181.26, fault address 0x001984cb.

Error - 9/13/2011 8:28:53 AM | Computer Name = REYNOLDS | Source = Windows Media Center Download | ID = 4
Description = An unknown connection failure occurred. Please try again later.

Error - 9/15/2011 8:32:09 AM | Computer Name = REYNOLDS | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x3cfa97fc.

Error - 9/17/2011 2:15:33 PM | Computer Name = REYNOLDS | Source = Windows Media Center Download | ID = 1
Description = Failure attempting to download new Guide data. Please ensure that
you are connected to the Internet. If you connect through a LAN, ensure that your
proxy or firewall has been properly configured.

Error - 9/17/2011 2:15:33 PM | Computer Name = REYNOLDS | Source = Windows Media Center Download | ID = 1
Description = Failure attempting to download new Guide data. Please ensure that
you are connected to the Internet. If you connect through a LAN, ensure that your
proxy or firewall has been properly configured.

Error - 9/17/2011 3:04:14 PM | Computer Name = REYNOLDS | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module mshtml.dll, version 8.0.6001.19120, fault address 0x001097fc.

[ System Events ]
Error - 9/18/2011 11:12:15 AM | Computer Name = REYNOLDS | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.

Error - 9/18/2011 11:12:46 AM | Computer Name = REYNOLDS | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.

Error - 9/18/2011 11:13:17 AM | Computer Name = REYNOLDS | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.

Error - 9/18/2011 1:11:14 PM | Computer Name = REYNOLDS | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 9/18/2011 1:18:54 PM | Computer Name = REYNOLDS | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2

Error - 9/18/2011 1:18:54 PM | Computer Name = REYNOLDS | Source = Service Control Manager | ID = 7000
Description = The SupportSoft Sprocket Service (dellsupportcenter) service failed
to start due to the following error: %%2

Error - 9/18/2011 1:18:54 PM | Computer Name = REYNOLDS | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 9/18/2011 2:53:13 PM | Computer Name = REYNOLDS | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2

Error - 9/18/2011 2:53:13 PM | Computer Name = REYNOLDS | Source = Service Control Manager | ID = 7000
Description = The SupportSoft Sprocket Service (dellsupportcenter) service failed
to start due to the following error: %%2

Error - 9/18/2011 2:53:13 PM | Computer Name = REYNOLDS | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2


< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Here are the results of Combofix…

ComboFix 11-09-19.03 - Admin 09/19/2011 18:05:33.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2559.1756 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Security Suite *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Admin\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Admin\Local Settings\Application Data\ApplicationHistory\caspol.exe.ae73cd99.ini
c:\documents and settings\Admin\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.8fb3d965.ini
c:\documents and settings\Admin\Local Settings\Application Data\ApplicationHistory\MSI291.tmp.a8a811e2.ini
c:\documents and settings\Admin\Local Settings\Application Data\ApplicationHistory\ngen.exe.89f695a3.ini
c:\documents and settings\Admin\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
c:\documents and settings\Admin\Local Settings\Application Data\ApplicationHistory\snchk.exe.bc20ddb9.ini
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\caspol.exe.ae73cd99.ini
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.8fb3d965.ini
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\MSI291.tmp.a8a811e2.ini
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\ngen.exe.89f695a3.ini
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\snchk.exe.bc20ddb9.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\AlertView.exe.8de2ebce.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\AllertEula.exe.561b80e6.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\caspol.exe.ae73cd99.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\DA_PASlog.exe.266217b1.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\DFolder.exe.368dcbb5.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\DNgen.exe.420e9c76.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\DReg1.exe.1f05a5b1.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\dsca.exe.cf6b816f.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\EHShell.exe.a87fcbb.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\EHShell.exe.a87fcbb.ini.inuse
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\ExpEval21.exe.8f3e9125.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\GUI.exe.872652eb.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.8fb3d965.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\MSI291.tmp.a8a811e2.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\NGen.exe.2c05686e.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\ngen.exe.89f695a3.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini.inuse
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\OUTLOOK.EXE.92d487ce.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\rng.exe.ac4aa698.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\snchk.exe.bc20ddb9.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\startDSLog.exe.8ba7e4eb.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.27decd74.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.70cb5133.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.77164975.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.84bf43f2.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.ba34fb79.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.f711c2b7.ini
c:\documents and settings\Chris\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.fe78d26e.ini
c:\documents and settings\Chris\WINDOWS
c:\documents and settings\Jim\WINDOWS
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\AlertView.exe.8de2ebce.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\AllertEula.exe.561b80e6.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\caspol.exe.ae73cd99.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\DA_PASlog.exe.266217b1.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\DFolder.exe.368dcbb5.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\dsca.exe.cf6b816f.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\EHShell.exe.a87fcbb.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\ExpEval21.exe.8f3e9125.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.8fb3d965.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\MSI291.tmp.a8a811e2.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\mswmc.exe.ed1fcd7a.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\ngen.exe.89f695a3.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini.inuse
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\OUTLOOK.EXE.92d487ce.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\rng.exe.ac4aa698.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\snchk.exe.bc20ddb9.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.27decd74.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.70cb5133.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.77164975.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.ba34fb79.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.f711c2b7.ini
c:\documents and settings\Lisa\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.fe78d26e.ini
c:\documents and settings\NetworkService\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\NetworkService\Local Settings\Application Data\ApplicationHistory\mswmccds.exe.5bdff540.ini.inuse
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\caspol.exe.ae73cd99.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\DFolder.exe.368dcbb5.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\dsca.exe.cf6b816f.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\EHShell.exe.a87fcbb.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\ExpEval21.exe.8f3e9125.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.8fb3d965.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\MSI291.tmp.a8a811e2.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\ngen.exe.89f695a3.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini.inuse
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\rng.exe.ac4aa698.ini
c:\documents and settings\Timmy\Local Settings\Application Data\ApplicationHistory\snchk.exe.bc20ddb9.ini
c:\documents and settings\Timmy\My Documents\~WRL0764.tmp
c:\documents and settings\Timmy\My Documents\~WRL0910.tmp
c:\documents and settings\Timmy\My Documents\~WRL2543.tmp
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\caspol.exe.ae73cd99.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\DA_PASlog.exe.266217b1.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\EHShell.exe.a87fcbb.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.8fb3d965.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\MSI291.tmp.a8a811e2.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\ngen.exe.89f695a3.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini.inuse
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\rng.exe.ac4aa698.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\snchk.exe.bc20ddb9.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.77164975.ini
c:\documents and settings\Visitor\Local Settings\Application Data\ApplicationHistory\WMITarget.exe.ba34fb79.ini
c:\windows\SYSTEM32\aycdd.bak1
c:\windows\SYSTEM32\aycdd.bak2
c:\windows\SYSTEM32\aycdd.ini
c:\windows\SYSTEM32\aycdd.ini2
c:\windows\SYSTEM32\aycdd.tmp
c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory
c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory\caspol.exe.ae73cd99.ini
c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.8fb3d965.ini
c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory\MSI291.tmp.a8a811e2.ini
c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory\ngen.exe.89f695a3.ini
c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory\snchk.exe.bc20ddb9.ini
c:\windows\TSOC.LOG
.
.
((((((((((((((((((((((((( Files Created from 2011-08-19 to 2011-09-19 )))))))))))))))))))))))))))))))
.
.
2011-09-18 18:07 . 2011-09-18 20:27 ——– d—–w- c:\documents and settings\Admin
2011-09-16 23:40 . 2011-08-12 02:44 7152464 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{6361CFC5-16DB-4AC1-9DAB-B6A4378BDFBF}\mpengine.dll
2011-09-16 23:20 . 2011-09-16 23:20 ——– d—–w- c:\documents and settings\Visitor\Application Data\Apple Computer
2011-09-16 23:19 . 2011-09-16 23:20 ——– d—–w- c:\documents and settings\Visitor\Local Settings\Application Data\Apple Computer
2011-09-16 23:19 . 2011-09-16 23:19 ——– d-sh–w- c:\documents and settings\Visitor\IETldCache
2011-09-09 00:11 . 2011-09-09 00:11 ——– d—–w- c:\program files\Glary Utilities
2011-09-09 00:03 . 2011-09-09 00:03 ——– d—–w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-09-05 12:36 . 2011-07-06 23:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-05 12:36 . 2011-09-05 12:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-09-05 12:36 . 2011-09-05 12:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-09-05 12:36 . 2011-07-06 23:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-09-03 10:17 . 2011-09-03 10:17 599040 ——w- c:\windows\system32\dllcache\crypt32.dll
2011-08-31 20:00 . 2011-08-31 20:03 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2011-08-31 00:51 . 2011-08-31 00:57 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-03 10:17 . 2003-03-20 22:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-08-12 02:44 . 2006-04-01 01:54 7152464 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-07-18 16:14 . 2010-03-17 02:31 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-18 16:14 . 2010-03-17 02:31 60872 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-07-15 13:29 . 2003-07-30 13:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2003-07-30 13:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-29 21:48 . 2011-06-29 21:48 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-24 14:10 . 2003-07-30 13:00 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2004-02-06 22:05 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2003-07-30 13:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2003-07-30 13:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-21 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2008-04-14 50176]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-07 335872]
"AsioReg"="CTASIO.DLL" [2003-02-20 110592]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2007-03-07 1773568]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-03 122939]
"CTHelper"="CTHELPER.EXE" [2003-02-20 28672]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2008-08-08 524288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Jim^Start Menu^Programs^Startup^Webshots.lnk]
path=c:\documents and settings\Jim\Start Menu\Programs\Startup\Webshots.lnk
backup=c:\windows\pss\Webshots.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-05-27 18:52 40368 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-06-07 21:51 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
2006-05-08 09:17 81920 —-a-w- c:\progra~1\Sony\SONICS~1\SSAAD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-05-21 12:30 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2006-04-15 20:14 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2003-08-19 06:01 110592 —-a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Upromise Tray]
2009-04-14 22:37 139264 —-a-w- c:\program files\Upromise\UpromiseTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Upromise Update]
2009-04-13 21:50 96136 —-a-w- c:\program files\Upromise\dca-ua.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
2004-11-11 04:15 111816 —-a-w- c:\program files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Support.com\\bin\\tgcmd.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Savings Bond Wizard\\SBWizard.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\SYSTEM32\DRIVERS\N360\0501000.01D\symds.sys [7/18/2011 12:14 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\N360\0501000.01D\symefa.sys [7/18/2011 12:14 PM 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110909.001\BHDrvx86.sys [9/9/2011 1:44 PM 816760]
R1 SymIRON;Symantec Iron Driver;c:\windows\SYSTEM32\DRIVERS\N360\0501000.01D\ironx86.sys [7/18/2011 12:14 PM 136312]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\5.1.0.29\ccsvchst.exe [7/18/2011 12:13 PM 130008]
R2 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [7/31/2011 4:01 PM 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110917.031\IDSXpx86.sys [9/17/2011 2:16 PM 356280]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/6/2009 5:57 PM 133104]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/6/2009 5:57 PM 133104]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - GUPDATEM
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
2011-09-18 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-09-09 13:26]
.
2011-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc7170fa92ab76.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-06 21:56]
.
2011-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-06 21:56]
.
2011-09-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
2011-09-19 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:08]
.
2004-10-19 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-10-19 22:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB
DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://69.126.199.53:81/activex/AMC.cab
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
MSConfigStartUp-WinPatrol - c:\progra~1\BILLPS~1\WINPAT~1\winpatrol.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-19 18:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
Completion time: 2011-09-19 18:19:46
ComboFix-quarantined-files.txt 2011-09-19 22:19
.
Pre-Run: 19,447,259,136 bytes free
Post-Run: 20,218,880,000 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - D9E6A5D238155F71D35BE8FFC866B7D1
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.





Also tell me how the computer is running now.
here;s the Malware bytes log… Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7750 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 9/19/2011 9:29:13 PM mbam-log-2011-09-19 (21-29-13).txt Scan type: Quick scan Objects scanned: 262932 Time elapsed: 6 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Here;s the ESET online log… will let me PC run for awhile and see how its doing… ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=c2b139bc5f7e534bbe174e138cbad760 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-09-20 04:16:03 # local_time=2011-09-20 12:16:03 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=3589 16777173 80 84 932079 67060828 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=145100 # found=6 # cleaned=6 # scan_time=7431 C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\aycdd.bak1.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\aycdd.bak2.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\aycdd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\aycdd.ini2.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\aycdd.tmp.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP1\A0000136.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
PC has been on for a few hours now and CPU / memory usage is noticeably improved. svchost.exe is not using nearly as much memory. Also network traffic in the router log appears appropriate for the sites/programs I use.

Other than the virtumonde virus that was detected, what other issues did you see?

Thanks so much for your help.

Here is the log from the latest OTL run…
==============

OTL logfile created on: 9/20/2011 5:37:43 PM - Run 2
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Admin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.77 Gb Available Physical Memory | 70.91% Memory free
3.10 Gb Paging File | 2.18 Gb Available in Paging File | 70.42% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 18.72 Gb Free Space | 16.76% Space Free | Partition Type: NTFS

Computer Name: REYNOLDS | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\asoelnch.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\dwwin.exe (Microsoft Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Support.com\bin\tgcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
PRC - C:\WINDOWS\SYSTEM32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
MOD - C:\WINDOWS\SYSTEM32\cl31cl3.dll ()
MOD - C:\WINDOWS\SYSTEM32\dlbacnv4.dll ()
MOD - C:\WINDOWS\SYSTEM32\pdf995mon.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBAPP5C.DLL ()
MOD - C:\Program Files\Dell AIO Printer A940\ConvDIB.dll ()


========== Win32 Services (SafeList) ==========

SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – File not found
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (WMConnectCDS) – C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110909.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110917.033\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110920.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110920.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0501000.01D\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (IrBus) – C:\WINDOWS\SYSTEM32\DRIVERS\irbus.sys (Microsoft Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (ATITUNEP) – C:\WINDOWS\SYSTEM32\DRIVERS\atineuxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio) – C:\WINDOWS\SYSTEM32\DRIVERS\atinesxx.sys (ATI Technologies Inc.)
DRV - (atinevxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinevxx.sys (ATI Technologies Inc.)
DRV - (PCDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (MVDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (ativraxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ctdvda2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) – C:\WINDOWS\SYSTEM32\DRIVERS\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\DRIVERS\pfmodnt.sys (Creative Technology Ltd.)
DRV - (emupia) – C:\WINDOWS\SYSTEM32\DRIVERS\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctac32k.sys (Creative Technology Ltd)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EUSBMSD) – C:\WINDOWS\SYSTEM32\DRIVERS\EUSBMSD.SYS (SCM Microsystems Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=5: C:\Program Files\Google\Google Updater\1.2.567.20382\npCIDetect5.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2011/08/29 11:18:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_1_3 [2011/09/18 14:52:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/24 22:18:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/02 17:17:56 | 000,000,000 | —D | M]

[2011/09/04 10:39:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/18 16:39:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/22 06:57:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/08/24 16:36:17 | 000,002,197 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google-search.xml

O1 HOSTS File: ([2011/09/19 18:16:48 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll (Compete, Inc.)
O2 - BHO: (Upromise TurboSaver) - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra 'Tools' menuitem : Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} https://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1263953748824 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://69.126.199.53:81/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB (Reg Error: Key error.)
O16 - DPF: ppctlcab http://www.pestscan.com/scanner/ppctlcab.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CE910A3A-E4CB-42EF-B86F-01A2AE78491A}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - (WRLogonNTF.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/08/08 15:47:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SsiEfr.e)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/19 21:59:28 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/09/19 21:21:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Malwarebytes
[2011/09/19 18:02:58 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/09/19 18:00:24 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/09/19 18:00:24 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/09/19 18:00:24 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/09/19 18:00:24 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/09/19 18:00:12 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/09/19 18:00:00 | 000,000,000 | —D | C] – C:\Qoobox
[2011/09/19 17:59:55 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents\My Videos
[2011/09/19 17:59:55 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Administrative Tools
[2011/09/19 17:56:51 | 004,218,951 | R— | C] (Swearware) – C:\Documents and Settings\Admin\Desktop\ComboFix.exe
[2011/09/18 14:55:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Adobe
[2011/09/18 14:55:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Admin\PrivacIE
[2011/09/18 14:55:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\Google
[2011/09/18 14:55:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Google
[2011/09/18 14:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Desktop\tdsskiller
[2011/09/18 14:48:01 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2011/09/18 14:12:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Apple Computer
[2011/09/18 14:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\GTek
[2011/09/18 14:11:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\Apple Computer
[2011/09/18 14:08:14 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Admin\IETldCache
[2011/09/18 14:07:10 | 000,000,000 | –SD | C] – C:\Documents and Settings\Admin\Application Data\Microsoft
[2011/09/18 14:07:10 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Admin\Application Data
[2011/09/18 14:07:10 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Favorites
[2011/09/18 14:07:10 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Admin\Cookies
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Sun
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Sonic
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Real
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Macromedia
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Identities
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Desktop
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Creative
[2011/09/18 14:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2011/09/18 14:07:09 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Admin\SendTo
[2011/09/18 14:07:09 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Admin\Recent
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Startup
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Start Menu
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents\My Pictures
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents\My Music
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents
[2011/09/18 14:07:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Accessories
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\Templates
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\PrintHood
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\NetHood
[2011/09/18 14:07:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Admin\Local Settings
[2011/09/18 14:07:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Dell Accessories
[2011/09/08 20:11:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Glary Utilities
[2011/09/08 20:11:38 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2011/09/08 20:03:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/09/05 08:36:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/05 08:36:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/09/05 08:36:41 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/05 08:36:41 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/09/03 06:17:37 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/09/01 08:32:14 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2011/08/31 16:00:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/08/31 14:31:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Real
[2011/08/30 20:51:51 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/08/30 08:27:29 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/08/29 11:38:16 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/08/29 11:20:57 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2003/11/10 09:35:11 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/20 17:43:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/20 17:36:58 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/09/20 17:34:58 | 004,481,358 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2011/09/20 17:33:00 | 000,000,564 | —- | M] () – C:\WINDOWS\tasks\PCDoctorBackgroundMonitorTask.job
[2011/09/20 13:30:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc7170fa92ab76.job
[2011/09/20 05:37:29 | 000,030,932 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/20 05:37:29 | 000,030,932 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/20 05:37:29 | 000,030,600 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/20 05:37:29 | 000,030,600 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/09/20 05:37:29 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/09/20 05:37:29 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/09/20 05:37:29 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2011/09/20 05:37:29 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2011/09/20 04:18:28 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/20 01:30:38 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/09/19 21:21:49 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/19 18:16:48 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2011/09/19 18:03:05 | 000,000,325 | RHS- | M] () – C:\BOOT.INI
[2011/09/19 17:57:14 | 004,218,951 | R— | M] (Swearware) – C:\Documents and Settings\Admin\Desktop\ComboFix.exe
[2011/09/18 17:57:42 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/09/18 15:27:29 | 000,000,696 | —- | M] () – C:\WINDOWS\DELLSTAT.INI
[2011/09/18 14:52:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/09/18 14:52:07 | 2683,375,616 | -HS- | M] () – C:\hiberfil.sys
[2011/09/18 14:48:06 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2011/09/18 14:47:36 | 001,388,161 | —- | M] () – C:\Documents and Settings\Admin\Desktop\tdsskiller.zip
[2011/09/18 14:10:15 | 000,000,815 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/05 14:44:11 | 000,000,209 | —- | M] () – C:\Boot.bak
[2011/09/03 06:17:37 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/08/26 23:40:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/24 21:39:37 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/19 21:21:49 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/19 18:03:05 | 000,000,209 | —- | C] () – C:\Boot.bak
[2011/09/19 18:03:00 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/09/19 18:00:24 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/09/19 18:00:24 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/09/19 18:00:24 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/09/19 18:00:24 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/09/19 18:00:24 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/09/18 14:47:11 | 001,388,161 | —- | C] () – C:\Documents and Settings\Admin\Desktop\tdsskiller.zip
[2011/09/18 14:10:14 | 000,000,803 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Internet Explorer.lnk
[2011/09/18 14:09:28 | 000,000,792 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Windows Media Player.lnk
[2011/09/18 14:07:12 | 000,001,612 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Sonic MyDVD.lnk
[2011/09/18 14:07:12 | 000,001,298 | —- | C] () – C:\Documents and Settings\Admin\Desktop\Media Center.lnk
[2011/09/18 14:07:12 | 000,000,815 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/18 14:07:12 | 000,000,742 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/09/18 14:07:12 | 000,000,708 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/09/18 14:07:12 | 000,000,669 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk
[2011/09/18 14:07:12 | 000,000,079 | —- | C] () – C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/09/18 14:07:11 | 000,000,136 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\fusioncache.dat
[2011/09/18 14:07:10 | 000,001,503 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Remote Assistance.lnk
[2011/09/18 14:07:10 | 000,000,738 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Outlook Express.lnk
[2011/09/12 13:25:34 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc7170fa92ab76.job
[2011/09/09 20:08:05 | 2683,375,616 | -HS- | C] () – C:\hiberfil.sys
[2011/09/08 20:11:43 | 000,000,308 | —- | C] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/05/22 00:00:23 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/04/13 19:22:56 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/04/13 19:22:56 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/04/12 16:00:01 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/03/03 18:41:57 | 000,292,984 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/11/10 18:06:15 | 000,069,076 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/09/26 15:58:10 | 000,479,232 | —- | C] () – C:\WINDOWS\ssndii.exe
[2009/09/26 15:55:38 | 000,022,723 | —- | C] () – C:\WINDOWS\System32\cl31cl3.dll
[2008/07/02 19:02:36 | 000,000,294 | —- | C] () – C:\WINDOWS\EReg077.dat
[2008/07/02 18:35:19 | 000,000,647 | —- | C] () – C:\WINDOWS\hegames.ini
[2007/05/13 20:58:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2007/01/04 20:19:40 | 000,001,168 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/06/30 16:41:04 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2006/06/24 11:21:08 | 000,006,638 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/09 20:36:32 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/03/09 20:36:32 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2005/12/15 19:54:14 | 000,000,021 | —- | C] () – C:\WINDOWS\DVDSentry.ini
[2005/09/13 18:27:08 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlbacnv4.dll
[2005/06/11 21:30:01 | 000,000,137 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2005/05/02 21:11:23 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2004/09/26 21:46:38 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/13 19:19:28 | 000,000,356 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2004/06/21 20:04:17 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2004/02/04 21:39:07 | 000,000,048 | —- | C] () – C:\WINDOWS\wpd99.drv
[2004/01/31 09:17:53 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\pdfmona.dll
[2004/01/31 09:17:53 | 000,050,364 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2004/01/19 22:18:59 | 000,020,924 | —- | C] () – C:\WINDOWS\unins000.dat
[2003/12/06 15:57:04 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2003/11/24 22:15:40 | 000,000,082 | —- | C] () – C:\WINDOWS\MPLAYER.INI
[2003/11/24 22:11:35 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[2003/11/24 22:11:35 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2003/11/24 21:23:19 | 000,000,030 | —- | C] () – C:\WINDOWS\INTURS.DAT
[2003/11/24 21:05:13 | 000,000,078 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/11/24 21:04:42 | 000,000,165 | —- | C] () – C:\WINDOWS\Quicken.ini
[2003/11/23 21:53:11 | 000,000,696 | —- | C] () – C:\WINDOWS\DELLSTAT.INI
[2003/11/12 04:54:00 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/11/10 10:01:08 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/11/10 09:44:23 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/11/10 09:42:04 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2003/11/10 09:42:04 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2003/11/10 09:38:07 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2003/11/10 09:35:35 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2003/11/10 09:35:35 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2003/11/10 09:35:12 | 000,232,723 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2003/11/10 09:35:12 | 000,190,842 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2003/11/10 09:35:12 | 000,138,716 | —- | C] () – C:\WINDOWS\System32\ctbas2w.dat
[2003/11/10 09:35:12 | 000,110,720 | —- | C] () – C:\WINDOWS\System32\CTBASICW.DAT
[2003/11/10 09:35:12 | 000,066,807 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2003/11/10 09:35:12 | 000,053,674 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2003/11/10 09:35:12 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2003/11/10 09:35:12 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2003/11/10 09:35:11 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2003/11/10 09:35:11 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2003/11/10 09:35:11 | 000,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2003/11/10 09:35:11 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2003/11/10 09:35:10 | 000,000,184 | —- | C] () – C:\WINDOWS\System32\e000001.dat
[2003/11/10 09:35:07 | 000,831,600 | —- | C] () – C:\WINDOWS\System32\Ctaa1.dat
[2003/11/10 09:34:42 | 000,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2003/11/10 09:34:09 | 000,000,264 | —- | C] () – C:\WINDOWS\wininit.ini
[2003/11/10 09:12:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2003/11/10 09:10:00 | 000,515,814 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2003/11/10 09:10:00 | 000,102,766 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2003/11/10 08:50:16 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:54:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/08/08 17:27:48 | 000,330,688 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/08/08 17:26:58 | 000,000,791 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2003/08/08 15:47:20 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/08/08 15:41:52 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2003/07/30 09:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2003/07/30 09:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2003/07/30 09:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2003/07/30 09:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2003/07/30 09:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2003/07/30 09:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/07/30 09:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2003/02/17 19:00:42 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbavs.dll
[2003/02/17 19:00:36 | 000,000,177 | —- | C] () – C:\WINDOWS\System32\dlbacoin.ini
[2003/02/05 13:11:12 | 000,000,126 | —- | C] () – C:\WINDOWS\System32\DLBAPLC.INI
[2003/01/07 17:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 17:07:14 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2001/08/23 17:07:02 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[1980/01/01 02:00:00 | 000,303,104 | —- | C] () – C:\WINDOWS\System32\ati2evxx.exe
[1980/01/01 02:00:00 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll

========== LOP Check ==========

[2003/11/10 09:29:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/04/18 14:11:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/05/24 16:07:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCDr
[2007/11/16 07:13:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/07/07 21:51:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/13 19:23:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2011/09/08 20:03:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2010/04/02 19:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/11 20:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/10 19:08:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/09/18 17:57:42 | 000,000,308 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
[2011/09/20 01:30:38 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/09/20 17:33:00 | 000,000,564 | —- | M] () – C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job

========== Purity Check ==========



< End of report >

Other than the virtumonde virus that was detected, what other issues did you see?

The main infection was the rootkit removed by TDSSKiller.




You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.











Download TFC to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean











[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 and save it to your desktop.
  • Scroll down to where it says JDK 7 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 7 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI