This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very sluggish computer/ choppy interwebs

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Lately the computer has slowed down to an almost crawl, and the internet has been intermittently going off and on. Also been sending bogus emails


OTL logfile created on: 9/18/2011 11:14:06 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 70.02% Memory free
3.85 Gb Paging File | 3.35 Gb Available in Paging File | 87.03% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092C:\pagefile.sys 2 2 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.13 Gb Total Space | 1.79 Gb Free Space | 12.68% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 34.53 Gb Free Space | 35.36% Space Free | Partition Type: NTFS
Drive F: | 3.75 Gb Total Space | 3.75 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: DANIEL-65C6EC9E | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - D:\Program Files\Trillian\trillian.exe (Cerulean Studios)
PRC - D:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealUpgrade\realupgrade.exe (RealNetworks, Inc.)
PRC - D:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
PRC - D:\Program Files\Orbitdownloader\orbitnet.exe (Orbitdownloader.com)
PRC - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - D:\Program Files\Trillian\libspeex.dll ()
MOD - D:\Program Files\Trillian\libungif.dll ()
MOD - D:\Program Files\Trillian\zlib1.dll ()
MOD - d:\Program Files\Trillian\languages\en\buddy.dll ()
MOD - d:\Program Files\Trillian\languages\en\talk.dll ()
MOD - d:\Program Files\Trillian\languages\en\trillian.dll ()
MOD - d:\Program Files\Trillian\languages\en\events.dll ()
MOD - d:\Program Files\Trillian\languages\en\toolkit.dll ()
MOD - D:\Program Files\Orbitdownloader\wtlctrl.dll ()
MOD - C:\WINDOWS\system32\acs.exe ()
MOD - C:\WINDOWS\system32\dxmasf.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (avgwd) – D:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (StarWindServiceAE) – d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()


========== Driver Services (SafeList) ==========

DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (libusb0) – C:\WINDOWS\system32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\SHP5211.sys (Atheros Communications, Inc.)
DRV - (MLPTDR_C) – C:\WINDOWS\system32\MLPTDR_C.SYS (Minolta Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.startup.homepage: "http://search.orbitdownloader.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: d:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: d:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: D:\Program Files\AVG\AVG2012\Firefox4\ [2011/09/15 12:05:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/09/05 21:51:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/09/07 02:14:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins

[2009/07/12 12:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions
[2009/07/12 12:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions\[removed]
[2011/09/13 23:34:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions
[2011/09/06 23:23:28 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/05 21:43:54 | 000,003,739 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\searchplugins\avg-secure-search.xml
[2011/09/05 21:32:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 12:57:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/09/05 21:46:20 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/09/15 12:05:00 | 000,000,000 | —D | M] (AVG Safe Search) – D:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2010/05/23 12:57:22 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = d:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\plugins/avgnpss.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\

O1 HOSTS File: ([2011/09/15 12:00:08 | 000,436,898 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15053 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AVG_TRAY] D:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] d:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk = D:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1278997763765 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ADA77DDB-645F-48A0-BD3F-DC5769D52C0C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\video/x-flv - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/09 16:04:31 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (D:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3filter - ac3filter.acm File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ffdshow.ax ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/18 23:11:08 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:10:52 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
[2011/09/15 22:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\FACEBOOK!
[2011/09/15 16:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/15 16:05:23 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/15 12:02:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Start Menu\Programs\Google Chrome
[2011/09/15 12:01:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google
[2011/09/13 23:34:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Orbit
[2011/09/05 21:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Spybot - Search & Destroy
[2011/09/05 21:51:20 | 000,198,832 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/09/05 21:51:15 | 000,272,896 | —- | C] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/09/05 21:51:15 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/09/05 21:51:15 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/09/05 21:51:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Real
[2011/09/05 21:47:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/09/05 21:46:33 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/09/05 21:46:33 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/09/05 21:46:33 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/09/05 21:46:33 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/09/05 21:44:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
[2011/09/05 21:43:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\AVG 2012
[2011/09/05 21:43:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2011/08/29 15:58:26 | 000,000,000 | —D | C] – C:\Program Files\Compaq
[2011/08/29 15:58:20 | 000,000,000 | —D | C] – C:\CPQSYSTEM
[2004/11/24 14:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/18 23:14:06 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/18 23:14:06 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/18 23:12:47 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
[2011/09/18 23:11:46 | 000,625,664 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\dds.scr
[2011/09/18 23:11:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:06:00 | 000,001,014 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
[2011/09/18 18:02:26 | 104,554,326 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/09/18 17:04:30 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/18 12:06:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
[2011/09/18 11:05:34 | 000,000,656 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
[2011/09/18 11:05:12 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/18 11:05:05 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/09/18 11:02:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/17 14:07:32 | 000,002,411 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Google Chrome.lnk
[2011/09/17 14:07:32 | 000,002,389 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/15 16:05:27 | 000,000,670 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 12:05:00 | 000,000,616 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2012.lnk
[2011/09/15 12:00:08 | 000,436,898 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/09/14 13:40:26 | 000,224,256 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/13 23:34:18 | 000,000,628 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/09/10 00:41:45 | 000,000,596 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Shortcut to trillian.exe.lnk
[2011/09/05 21:57:34 | 000,436,472 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20110915-120008.backup
[2011/09/05 21:51:38 | 000,000,929 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2011/09/05 21:51:20 | 000,198,832 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/09/05 21:51:15 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/09/05 21:51:15 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/09/05 21:51:15 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/09/05 21:48:47 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2011/09/05 21:46:20 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/09/05 21:46:20 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/09/05 21:46:20 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/09/05 21:46:20 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/09/05 21:46:20 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/09/05 21:45:05 | 000,000,626 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/18 23:11:15 | 000,625,664 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\dds.scr
[2011/09/15 16:05:27 | 000,000,670 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 12:02:34 | 000,002,411 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Google Chrome.lnk
[2011/09/15 12:02:34 | 000,002,389 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/15 12:01:07 | 000,001,014 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
[2011/09/15 12:01:06 | 000,000,962 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
[2011/09/10 00:41:45 | 000,000,596 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Shortcut to trillian.exe.lnk
[2011/09/06 23:15:20 | 000,000,656 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
[2011/09/05 21:54:38 | 000,000,628 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/09/05 21:51:52 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/05 21:51:51 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/05 21:51:38 | 000,000,929 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2011/09/05 21:48:47 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Adobe Reader X.lnk
[2011/09/05 21:48:47 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2011/09/05 21:43:26 | 000,000,616 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2012.lnk
[2011/07/15 13:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\vvgo2823x2r50oejm
[2011/07/15 13:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\vvgo2823x2r50oejm
[2010/07/12 13:54:24 | 000,252,836 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/07/12 13:54:22 | 000,252,836 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/07/12 13:54:22 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/07/09 13:32:43 | 002,292,678 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/05/02 09:09:14 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/04/18 14:19:05 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/18 14:19:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/18 14:19:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/18 14:19:05 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/18 14:19:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/17 17:35:31 | 000,000,036 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\housecall.guid.cache
[2009/12/19 10:39:00 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/10/08 12:47:02 | 000,025,964 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/06/28 15:21:30 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/06/28 15:21:30 | 000,022,328 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\PnkBstrK.sys
[2009/06/28 15:21:14 | 000,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/06/28 15:21:14 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2009/06/28 15:21:12 | 000,000,319 | —- | C] () – C:\WINDOWS\game.ini
[2009/06/22 13:36:15 | 000,002,528 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\$_hpcst$.hpc
[2009/05/13 02:27:58 | 000,004,914 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/05/05 19:26:14 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/05/05 12:21:23 | 000,224,256 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/03 21:06:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2009/05/03 19:45:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/05/03 19:41:05 | 000,022,720 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/05/03 14:35:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/05/03 14:33:21 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/04 18:31:29 | 000,180,224 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/12/19 10:15:58 | 004,338,246 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/12/17 12:41:18 | 000,884,237 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2008/12/17 12:22:58 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/17 12:22:48 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/12/17 12:17:34 | 000,239,247 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 11:59:54 | 000,560,802 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2007/08/09 16:04:08 | 000,021,952 | -H– | C] () – C:\Program Files\folder.htt
[2006/11/02 11:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2005/06/20 10:31:34 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2005/06/20 10:31:34 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2004/10/03 12:50:54 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 01:07:22 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/17 11:36:38 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/10 14:09:52 | 000,021,282 | —- | C] () – C:\WINDOWS\MSTMON_C.INI
[2002/09/03 21:38:42 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\MCMM___C.DLL
[2002/09/03 17:38:04 | 000,010,242 | —- | C] () – C:\WINDOWS\MSUMLT_C.INI
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,311,934 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,040,196 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/09/05 21:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG10
[2011/09/05 22:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2009/05/03 21:49:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2010/10/06 16:18:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2011/09/18 18:02:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2011/09/02 21:43:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
[2009/08/09 11:48:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/06/27 15:48:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/03 13:57:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/07/13 14:15:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Auslogics
[2010/10/06 16:19:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG10
[2011/09/05 21:44:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
[2011/07/13 13:56:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Azureus
[2011/05/05 12:16:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\FrostWire
[2009/12/08 14:29:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GetRightToGo
[2010/04/17 15:27:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GrabPro
[2011/06/01 14:26:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\MechCAD
[2010/08/15 22:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\OpenCandy
[2011/09/18 11:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Orbit
[2011/05/26 12:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong
[2010/08/15 22:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\ProgSense
[2009/08/25 17:36:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Trillian
[2011/09/18 11:05:05 | 000,000,282 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/05/02 13:46:57 | 000,010,524 | —- | M] () – C:\aaw7boot.log
[2008/09/02 18:12:28 | 000,000,645 | —- | M] () – C:\Active SMART.lnk
[2009/02/25 22:05:49 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2007/08/09 16:04:31 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2009/05/06 00:59:40 | 000,000,487 | -HS- | M] () – C:\Boot.bak
[2011/07/14 05:00:52 | 000,000,440 | -HS- | M] () – C:\boot.ini
[2009/05/06 01:54:32 | 000,000,580 | RHS- | M] () – C:\Boot.ini.saved
[2009/04/22 00:28:23 | 000,383,200 | RHS- | M] () – C:\bootmgr
[2009/05/06 01:54:33 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/23 22:48:47 | 000,009,428 | —- | M] () – C:\ComboFix.txt
[2007/08/09 16:04:31 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2008/03/29 04:54:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2007/08/09 16:04:31 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/30 18:52:12 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2007/08/09 16:04:31 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 22:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/03 21:22:16 | 000,250,048 | RHS- | M] () – C:\ntldr
[1993/02/20 12:49:52 | 000,000,030 | —- | M] () – C:\readme.bat
[2010/04/18 14:12:45 | 000,000,387 | —- | M] () – C:\rkill.log
[2009/12/06 20:11:35 | 000,002,870 | —- | M] () – C:\RootRepeal report 12-06-09 (19-11-35).txt
[2009/05/03 13:07:45 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/05/03 13:23:21 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/05/03 13:28:05 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/05/03 14:23:03 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/05/03 17:23:38 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/05/03 18:28:06 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/04/29 11:51:11 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/04/29 21:49:31 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/04/30 16:07:14 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/04/30 16:36:05 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/04/30 17:19:43 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/05/01 15:39:25 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/05/02 13:39:29 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/05/02 13:40:22 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/05/02 13:40:38 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/05/02 14:11:14 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/05/02 14:43:31 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/05/02 15:11:06 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/05/02 15:23:57 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/05/03 02:10:55 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/05/03 13:07:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/05/03 13:23:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/05/03 13:28:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/05/03 14:23:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/05/03 17:23:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/05/03 18:28:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/04/29 11:51:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/04/29 21:49:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/04/30 16:07:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/04/30 16:36:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/04/30 17:19:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/05/01 15:39:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/05/02 13:39:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/05/02 13:40:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/05/02 13:40:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/05/02 14:11:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/05/02 14:43:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/05/02 15:11:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/05/02 15:23:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/05/03 02:10:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/07/12 13:27:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2002/09/03 18:19:44 | 000,009,728 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\MIMFPR_C.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2007/08/09 16:04:08 | 000,000,271 | -HS- | M] () – C:\Program Files\desktop.ini
[2007/08/09 16:04:08 | 000,021,952 | -H– | M] () – C:\Program Files\folder.htt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/07/12 07:51:07 | 004,718,592 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/07/12 01:54:06 | 000,049,152 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2010/07/12 07:51:07 | 028,311,552 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/07/12 07:51:07 | 006,553,600 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/12 13:27:58 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/03 21:30:13 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/03 19:48:35 | 000,000,079 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/10/11 21:15:27 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\ATF-Cleaner.exe
[2011/09/18 23:11:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:12:47 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-19 05:49:48

< End of report >
Hi karamazov,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


It appears you may have an old copy of Combofix installed. If so… please drag it to your recycle bin.


Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
karamazov,

copy and paste the log in sections… but skip the information contained in the Snapshot section (It is probably the part that is making your log huge.)
ComboFix 11-09-22.04 - Daniel 09/22/2011 20:45:10.4.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1359 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\1.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\a.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\b.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\c.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\d.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\e.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\f.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\g.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\h.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\i.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\J.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\k.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\l.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\m.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\mru.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\n.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\o.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\p.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\q.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\r.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\s.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\t.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\u.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\v.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\w.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\x.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\y.xml c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong\Data\z.xml c:\program files\messenger\msmsgsin.exe c:\windows\iun6002.exe c:\windows\system32\d3d9caps.dat . . ((((((((((((((((((((((((( Files Created from 2011-08-23 to 2011-09-23 ))))))))))))))))))))))))))))))) . . 2011-09-15 21:05 . 2011-08-31 22:00 22216 -c–a-w- c:\windows\system32\drivers\mbam.sys 2011-09-15 17:01 . 2011-09-15 17:02 ——– dc—-w- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google 2011-09-06 02:51 . 2011-09-06 02:51 499712 -c–a-w- c:\windows\system32\msvcp71.dll 2011-09-06 02:51 . 2011-09-06 02:51 348160 -c–a-w- c:\windows\system32\msvcr71.dll 2011-09-06 02:47 . 2011-09-06 02:47 ——– dc—-w- c:\program files\Common Files\Adobe AIR 2011-09-06 02:46 . 2011-09-06 02:46 73728 -c–a-w- c:\windows\system32\javacpl.cpl 2011-09-06 02:44 . 2011-09-06 02:44 ——– dc—-w- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012 2011-09-06 02:43 . 2011-09-06 03:58 ——– dc—-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG2012 2011-08-29 20:58 . 2011-09-03 04:53 ——– dc—-w- c:\program files\Compaq 2011-08-29 20:58 . 2011-08-29 20:58 ——– dc—-w- C:\CPQSYSTEM . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-06 02:46 . 2010-05-23 17:57 472808 -c–a-w- c:\windows\system32\deployJava1.dll 2011-08-08 11:08 . 2011-08-08 11:08 40016 -c–a-w- c:\windows\system32\drivers\avgmfx86.sys 2011-08-05 21:13 . 2009-05-06 02:33 436792 -c–a-w- c:\windows\system32\drivers\sptd.sys 2011-07-11 06:14 . 2011-07-11 06:14 295248 -c–a-w- c:\windows\system32\drivers\avgtdix.sys 2011-07-11 06:14 . 2011-07-11 06:14 23120 -c–a-w- c:\windows\system32\drivers\AVGIDSEH.sys 2011-07-11 06:13 . 2011-07-11 06:13 229840 -c–a-w- c:\windows\system32\drivers\avgldx86.sys 2011-07-11 06:13 . 2011-07-11 06:13 32464 -c–a-w- c:\windows\system32\drivers\avgrkx86.sys 2009-05-01 21:02 . 2009-05-01 21:02 1044480 -c–a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 -c–a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll .
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="d:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-04 16858112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-02-23 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-02-23 13880424]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"AVG_TRAY"="d:\program files\AVG\AVG2012\avgtray.exe" [2011-09-08 2401120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-09-06 273528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1392" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Orbit.lnk - d:\program files\Orbitdownloader\orbitdm.exe [2011-9-5 1843000]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0d:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^108Mbps Wireless LAN Adapte.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\108Mbps Wireless LAN Adapte.lnk
backup=c:\windows\pss\108Mbps Wireless LAN Adapte.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 17:55 937920 -c–a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2009-05-04 02:04 69632 -c–a-w- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-04-12 22:46 1135912 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 21:44 3883856 -c–a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 18:06 254696 -c–a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YahooAUService"=2 (0x2)
"PnkBstrB"=2 (0x2)
"PnkBstrA"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life 2 deathmatch\\hl2.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life deathmatch source\\hl2.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\opposing force\\hl.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life blue shift\\hl.exe"=
"d:\\Windows.old\\Program Files\\Trillian\\trillian.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\counter-strike\\hl.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life\\hl.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"=
"d:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"d:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 1:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7/11/2011 1:13 AM 32464]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys –> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/11/2011 1:13 AM 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R2 avgwd;AVG WatchDog;d:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 MLPTDR_C;MLPTDR_C;c:\windows\system32\MLPTDR_C.SYS [9/3/2002 7:31 PM 19296]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [7/14/2010 2:15 AM 28160]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-15 17:01]
.
2011-09-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-15 17:01]
.
2011-09-23 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 20:22]
.
2011-09-23 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 20:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.orbitdownloader.com
uInternet Settings,ProxyOverride = *.local
IE: &Download by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: motive.com\patttbc.att
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.orbitdownloader.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
——- File Associations ——-
.
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-ATT-SST_McciTrayApp - c:\program files\ATT-SST\McciTrayApp.exe
MSConfigStartUp-Info Center - c:\program files\PCPitstop\Info Center\InfoCenter.exe
MSConfigStartUp-iTunesHelper - d:\itunes\iTunesHelper.exe
MSConfigStartUp-Messenger (Yahoo!) - c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
MSConfigStartUp-PC Pitstop PC Matic Reminder - d:\program files\PCPitstop\PC Matic\Reminder-PCMatic.exe
MSConfigStartUp-QuickTime Task - d:\program files\QuickTime\QTTask.exe
MSConfigStartUp-SearchSettings - c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-22 20:49
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-09-22 20:50:38
ComboFix-quarantined-files.txt 2011-09-23 01:50
ComboFix2.txt 2010-04-24 03:48
ComboFix3.txt 2010-04-18 23:15
ComboFix4.txt 2010-04-18 19:30
ComboFix5.txt 2011-09-23 01:43
.
Pre-Run: 1,567,817,728 bytes free
Post-Run: 1,514,106,880 bytes free
.
- - End Of File - - C3ECDC1A19BA5AD198EFA5CE0F9E028E
karamazov,

Let's have a look with an online scanner.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=316d8f0df744154d8a01ba969f14745c # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-09-23 06:54:26 # local_time=2011-09-23 01:54:26 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777175 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=160153 # found=6 # cleaned=0 # scan_time=6380 C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch4.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Sun\Java\Deployment\cache\6.0\63\2679febf-4b325a07 Java/TrojanDownloader.OpenStream.NBL trojan (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5 a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I D:\Windows.old\Program Files\microsoft frontpage\ICQ\eZROMs\Google\TurboNote\BACKUP\Newer\OrbitDownloaderSetup4002.exe Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I D:\Windows.old\Program Files\microsoft frontpage\ICQ\eZROMs\Google\TurboNote\BACKUP\Newer\OrbitSetup4.0.6.exe Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I
karamazov,

That looks pretty good. Only a couple of things to deal with:

Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

How do things seem to be running now?
ComboFix 11-09-22.04 - Daniel 09/26/2011 17:10:21.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1340 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Daniel.DANIEL-65C6EC9E\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5
c:\windows\system32\d3d9caps.dat
.
.
((((((((((((((((((((((((( Files Created from 2011-08-26 to 2011-09-26 )))))))))))))))))))))))))))))))
.
.
2011-09-23 16:59 . 2011-09-23 16:59 ——– dc—-w- c:\program files\ESET
2011-09-15 21:05 . 2011-08-31 22:00 22216 -c–a-w- c:\windows\system32\drivers\mbam.sys
2011-09-15 17:01 . 2011-09-15 17:02 ——– dc—-w- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google
2011-09-06 02:51 . 2011-09-06 02:51 499712 -c–a-w- c:\windows\system32\msvcp71.dll
2011-09-06 02:51 . 2011-09-06 02:51 348160 -c–a-w- c:\windows\system32\msvcr71.dll
2011-09-06 02:47 . 2011-09-06 02:47 ——– dc—-w- c:\program files\Common Files\Adobe AIR
2011-09-06 02:46 . 2011-09-06 02:46 73728 -c–a-w- c:\windows\system32\javacpl.cpl
2011-09-06 02:44 . 2011-09-06 02:44 ——– dc—-w- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
2011-09-06 02:43 . 2011-09-06 03:58 ——– dc—-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG2012
2011-08-29 20:58 . 2011-09-03 04:53 ——– dc—-w- c:\program files\Compaq
2011-08-29 20:58 . 2011-08-29 20:58 ——– dc—-w- C:\CPQSYSTEM
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-06 02:46 . 2010-05-23 17:57 472808 -c–a-w- c:\windows\system32\deployJava1.dll
2011-08-08 11:08 . 2011-08-08 11:08 40016 -c–a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-08-05 21:13 . 2009-05-06 02:33 436792 -c–a-w- c:\windows\system32\drivers\sptd.sys
2011-07-11 06:14 . 2011-07-11 06:14 295248 -c–a-w- c:\windows\system32\drivers\avgtdix.sys
2011-07-11 06:14 . 2011-07-11 06:14 23120 -c–a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2011-07-11 06:13 . 2011-07-11 06:13 229840 -c–a-w- c:\windows\system32\drivers\avgldx86.sys
2011-07-11 06:13 . 2011-07-11 06:13 32464 -c–a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 -c–a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 -c–a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-09-23_01.49.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-09-26 16:44 . 2011-09-26 16:44 16384 c:\windows\Temp\Perflib_Perfdata_794.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="d:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-04 16858112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-02-23 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-02-23 13880424]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"AVG_TRAY"="d:\program files\AVG\AVG2012\avgtray.exe" [2011-09-08 2401120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-09-06 273528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1392" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Orbit.lnk - d:\program files\Orbitdownloader\orbitdm.exe [2011-9-5 1843000]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0d:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^108Mbps Wireless LAN Adapte.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\108Mbps Wireless LAN Adapte.lnk
backup=c:\windows\pss\108Mbps Wireless LAN Adapte.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 17:55 937920 -c–a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2009-05-04 02:04 69632 -c–a-w- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-04-12 22:46 1135912 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 21:44 3883856 -c–a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 18:06 254696 -c–a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YahooAUService"=2 (0x2)
"PnkBstrB"=2 (0x2)
"PnkBstrA"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life 2 deathmatch\\hl2.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life deathmatch source\\hl2.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\opposing force\\hl.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life blue shift\\hl.exe"=
"d:\\Windows.old\\Program Files\\Trillian\\trillian.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\counter-strike\\hl.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\half-life\\hl.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Windows.old\\Program Files\\Steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"=
"d:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"d:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 1:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7/11/2011 1:13 AM 32464]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys –> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/11/2011 1:13 AM 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R2 avgwd;AVG WatchDog;d:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 MLPTDR_C;MLPTDR_C;c:\windows\system32\MLPTDR_C.SYS [9/3/2002 7:31 PM 19296]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [7/14/2010 2:15 AM 28160]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-15 17:01]
.
2011-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
- c:\documents and settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-15 17:01]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 20:22]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 20:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.orbitdownloader.com
uInternet Settings,ProxyOverride = *.local
IE: &Download by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: motive.com\patttbc.att
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.orbitdownloader.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-26 17:15
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-09-26 17:17:08
ComboFix-quarantined-files.txt 2011-09-26 22:17
ComboFix2.txt 2011-09-23 01:50
ComboFix3.txt 2010-04-24 03:48
ComboFix4.txt 2010-04-18 23:15
ComboFix5.txt 2011-09-26 22:09
.
Pre-Run: 1,600,983,040 bytes free
Post-Run: 1,631,092,736 bytes free
.
- - End Of File - - 70782D8F8BCB398CE08B78D27D0BE1D2


Seems to be running better now. A lot less hangy internet and it seems to have a pretty solid connection
Log looks good :D

It is important that you do the following. Obviously… last time you were helped you didn't.

Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI