This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

blocks ALL antivirus or file scanning programs, Google Redirect

331 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

disable dm10ad registry entry not found (didnot disable) disable 9dc20117 was disabled attrib -r -a -s -h C:\WINDOWS\385991325 Peramiters arnt correct delete C:\WINDOWS\385991325 dident seem to do anything 385991325:1648230120 is still in the processes list hmm what do you think???
OK the file is not just an ads then : I actually have another one running just like yours at the moment but on a Vista

Retry like this

attrib -r -a -s -h C:\WINDOWS\385991325:1648230120
delete C:\WINDOWS\385991325:1648230120
wellll i think i just solved this problem my self. none of the things in recovery console were doing anything. sooo i went to the actual file on the drive. deleted it. and made a new text document and put the same name. set it to encrypted and read only. restarted and now thier is no385991325:1648230120 in the proceses list yay! pc started up much faster. i also dont have a CPU consuming svchost in the processes any more
ok i just started combofix from the desktop. it started perfectly and this ones not renamed. should i let it scan and do its thing or no?
Yes please - and thank you for that nugget of information - why I didn't think of that I don't know :blush: Excellent job though - I shall incorporate that now Thankee :thumbup:
yay combofix ran perfectly. it detected the zero access root kit. restarted did somethings and now i have a log *crosses fingers*


yea and the whole file thing was a shot in the dark. but it seemed like it just might work :). luckily it just dident create another file with a name that's a little different.

im usualy able to fix things my self but this one. was a bad one lol


ComboFix 11-10-25.04 - matt 10/25/2011 15:45:34.3.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\admin\Application Data\FlvTube Toolbar
C:\Install.exe
C:\svchost.exe
c:\windows\$NtUninstallKB25386$
c:\windows\$NtUninstallKB25386$\2646737175\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB25386$\2646737175\L\jruabiem
c:\windows\$NtUninstallKB25386$\2646737175\loader.tlb
c:\windows\$NtUninstallKB25386$\2646737175\U\@00000001
c:\windows\$NtUninstallKB25386$\2646737175\U\@000000c0
c:\windows\$NtUninstallKB25386$\2646737175\U\@000000cb
c:\windows\$NtUninstallKB25386$\2646737175\U\@000000cf
c:\windows\$NtUninstallKB25386$\2646737175\U\@80000000
c:\windows\$NtUninstallKB25386$\2646737175\U\@800000c0
c:\windows\$NtUninstallKB25386$\2646737175\U\@800000cb
c:\windows\$NtUninstallKB25386$\2646737175\U\@800000cf
c:\windows\$NtUninstallKB25386$\3398469043
c:\windows\385991325
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\system32\c_43440.nls
.
Infected copy of c:\windows\system32\drivers\afd.sys was found and disinfected
Restored copy from - The cat found it :)
c:\program files\Icecast2 Win32\icecastService.exe . . . is infected!!
c:\program files\Icecast2 Win32\icecastService.exe . . . was deleted!! You should re-install the program it pertains to
.
Infected copy of c:\program files\iPod\bin\iPodService.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{925D5044-4EDC-42DF-A47F-C805E589DF8B}\RP290\A0548620.exe
.
c:\windows\system32\NMSSvc.exe . . . is infected!!
c:\windows\system32\NMSSvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe . . . is infected!!
c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Ralink\Common\RaRegistry.exe . . . is infected!!
c:\program files\Ralink\Common\RaRegistry.exe . . . was deleted!! You should re-install the program it pertains to
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_9dc20117
.
.
((((((((((((((((((((((((( Files Created from 2011-09-25 to 2011-10-25 )))))))))))))))))))))))))))))))
.
.
2011-12-25 02:28 . 1996-08-13 10:03 60080 —-a-w- c:\windows\system32\WFM0203.ACV
2011-12-25 02:28 . 1996-08-13 10:03 5024 —-a-w- c:\windows\system32\WFM0201.ACV
2011-12-25 02:28 . 1996-08-13 10:03 49616 —-a-w- c:\windows\system32\WFM0202.ACV
2011-12-25 02:28 . 1996-08-13 10:03 12800 —-a-w- c:\windows\system32\WFM0200.ACV
2011-12-25 02:28 . 1996-08-13 10:01 19472 —-a-w- c:\windows\system32\WFM0007.ACV
2011-12-25 02:28 . 1996-08-13 10:01 19344 —-a-w- c:\windows\system32\WFM0011.ACV
2011-12-25 02:28 . 1996-08-13 10:01 13360 —-a-w- c:\windows\system32\WFM0006.ACV
2011-12-25 02:28 . 1995-05-13 10:00 7680 —-a-w- c:\windows\system32\CTFS32.ACM
2011-12-25 02:28 . 1995-05-13 10:00 11776 —-a-w- c:\windows\system32\CTADP32.ACM
2011-12-25 02:28 . 2011-10-25 04:11 ——– d—–w- c:\program files\Creative
2011-12-24 20:08 . 2011-12-24 20:08 4272498 —-a-r- C:\svchost(6).exe
2011-12-24 20:08 . 2011-12-24 20:08 4272498 —-a-r- C:\svchost(5).exe
2011-12-24 20:08 . 2011-12-24 20:08 4272498 —-a-r- C:\svchost(4).exe
2011-12-24 20:08 . 2011-12-24 20:08 4272498 —-a-r- C:\svchost(3).exe
2011-12-24 20:08 . 2011-12-24 20:08 4272498 —-a-r- C:\svchost(2).exe
2011-12-24 19:12 . 2011-12-24 19:12 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-22 20:46 . 2011-12-22 20:46 ——– d—–w- C:\_OTL
2011-12-22 09:59 . 2011-12-25 02:27 ——– d—–w- C:\New Folder (2)
2011-12-22 09:00 . 2008-04-14 04:15 10624 -c–a-w- c:\windows\system32\dllcache\gameenum.sys
2011-12-22 09:00 . 2008-04-14 04:15 10624 —-a-w- c:\windows\system32\drivers\gameenum.sys
2011-12-22 08:57 . 2001-08-17 16:19 40704 -c–a-w- c:\windows\system32\dllcache\es1371mp.sys
2011-12-22 08:57 . 2001-08-17 16:19 40704 —-a-w- c:\windows\system32\drivers\es1371mp.sys
2011-12-21 20:22 . 2011-12-21 20:22 924632 —-a-w- c:\program files\Mozilla Firefox\firefox.exe
2011-12-18 20:34 . 2011-12-18 20:34 81920 —-a-w- c:\windows\ALCFDRTM.EXE
2011-12-18 20:27 . 2005-11-01 00:17 135168 —-a-w- c:\windows\system32\RtlCPAPI(6).dll
2011-12-18 20:27 . 2005-11-01 00:17 135168 —-a-w- c:\windows\system32\RtlCPAPI(5).dll
2011-12-18 20:27 . 2005-11-01 00:17 135168 —-a-w- c:\windows\system32\RtlCPAPI(4).dll
2011-12-18 20:27 . 2005-11-01 00:17 135168 —-a-w- c:\windows\system32\RtlCPAPI(3).dll
2011-12-18 20:27 . 2005-11-01 00:17 135168 —-a-w- c:\windows\system32\RtlCPAPI(2).dll
2011-10-25 20:42 . 2011-02-14 18:47 138496 -c–a-w- c:\windows\system32\dllcache\afd.sys
2011-10-25 20:42 . 2011-02-14 18:47 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-10-25 05:11 . 2011-10-25 05:11 ——– d—–w- c:\documents and settings\matt\DoctorWeb
2011-10-25 04:49 . 2011-10-25 04:50 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-10-25 01:59 . 2011-10-25 02:03 ——– d—–w- c:\documents and settings\matt\Application Data\GetRightToGo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-21 05:08 . 2011-04-08 01:00 81920 —-a-w- c:\windows\ALCFDRTM.VER
2011-10-25 04:45 . 2011-05-23 02:30 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-25 03:55 . 2011-08-12 14:09 50112 –sha-w- c:\windows\system32\c_43440.nl_
2011-08-31 19:30 . 2011-08-23 09:30 90112 —-a-w- c:\windows\DUMP5a16.tmp
2011-08-31 19:26 . 2011-08-23 09:30 90112 —-a-w- c:\windows\DUMP5b10.tmp
2011-08-31 14:54 . 2011-08-31 14:54 94768 —-a-w- c:\windows\system32\drivers\80223438.sys
2011-08-31 14:54 . 2011-08-31 14:54 94768 —-a-w- c:\windows\system32\drivers\76704618.sys
2011-08-31 14:52 . 2011-08-31 14:52 94768 —-a-w- c:\windows\system32\drivers\61068841.sys
2011-08-24 18:13 . 2011-08-23 09:30 90112 —-a-w- c:\windows\DUMP6ca4.tmp
2011-08-21 12:25 . 2011-08-21 12:25 39192 —-a-w- c:\windows\system32\Partizan.exe
2011-08-21 12:25 . 2011-08-21 12:25 35816 —-a-w- c:\windows\system32\drivers\Partizan.sys
2011-08-21 12:25 . 2011-08-21 12:25 2 –shatr- c:\windows\winstart.bat
2011-06-13 19:38 . 2011-06-13 19:38 728858 —-a-w- c:\program files\Common Files\unins000.exe
2011-12-21 20:22 . 2011-08-17 00:34 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
.
[-] 2011-02-14 . E17798E1E6FF1CA9C67B8576570E05EE . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
c:\windows\System32\wuauclt.exe … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{807ca0aa-7cb3-4f03-bd61-076f618cc82d}]
2009-11-07 06:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-09-01 640888]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2011-04-30 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"PROMon.exe"="PROMon.exe" [2002-10-30 73728]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" [2011-03-24 167936]
"cFosTASKTR"="c:\windows\BOX_cFosTASK.exe" [2010-05-01 407476]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Ralink Wireless Utility.lnk - c:\program files\Ralink\Common\RaUI.exe [2011-4-6 1560576]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aim"="c:\program files\AIM\aim.exe" /d locale=en-US
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"IgfxTray"=c:\windows\system32\igfxtray.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"Persistence"=c:\windows\system32\igfxpers.exe
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"AlcWzrd"=ALCWZRD.EXE
"TaskTray"=
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\NGM\\NGM.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Phoenix Viewer\\SLVoice.exe"=
"c:\\Program Files\\Phoenix Viewer\\SLPlugin.exe"=
"c:\\Program Files\\SpacialAudio\\SAMBC\\SAMBC.exe"=
"c:\\Program Files\\Icecast2 Win32\\Icecast2win.exe"=
"c:\\Program Files\\VirtualDJ\\virtualdj_pro.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Complete\\Civilization4.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Complete\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Call of Duty\\CoDUOMP.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\Downloads\\Codec-C.exe"=
"c:\\WINDOWS\\system32\\wscript.exe"=
"c:\\Program Files\\tixati\\tixati.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\DivX\\DivX Plus Web Player\\DDMService.exe"=
"c:\\Program Files\\Phoenix Viewer\\PhoenixViewer.exe"=
"c:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\BitLord\\Rulers.Of.Nations.Geopolitical.Simulator.2.PC.Game(djDEVASTATE™)\\Rulers.Of.Nations.Geopolitical.Simulator.2.PC.Game(djDEVASTATE™)\\_start.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\Downloads\\MicrosoftFixit.AudioPlayback.Run.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\Documents and Settings\\matt\\Desktop\\downloads\\Unreal Tournament\\UnrealTournament\\System\\UnrealTournament.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Updater6\\Adobe_Updater.exe"=
"c:\\Program Files\\Driver-Soft\\DriverGenius\\DriverGenius.exe"=
"c:\\Program Files\\TuneUp Utilities 2011\\UpdateWizard.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\Downloads\\SoftonicDownloader_for_process-killer.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\Downloads\\NPE.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\MFAData\\SelfUpd\\avgmfapx.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\Program Files\\Apple Software Update\\SoftwareUpdate.exe"=
"c:\\Program Files\\Defcon\\defcon.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\Downloads\\utorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\Downloads\\SkypeSetup.exe"=
"c:\\Program Files\\AVAST Software\\Avast\\Setup\\avast.setup"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe"=
"c:\\Program Files\\Adobe Media Player\\Adobe Media Player.exe"=
"c:\\Program Files\\Common Files\\Adobe AIR\\Versions\\1.0\\Resources\\Adobe AIR Updater.exe"=
"c:\\Documents and Settings\\admin\\My Documents\\Downloads\\utorrent.exe"=
"c:\\Documents and Settings\\admin\\My Documents\\Downloads\\msgr11us.exe"=
"c:\\Program Files\\Freecorder\\FLVPlayer.exe"=
"c:\\Documents and Settings\\admin\\My Documents\\Downloads\\FLVDirect.exe"=
"c:\\Program Files\\DivX\\DivX Plus Player\\DivX Plus Player.exe"=
"c:\\Program Files\\Mozilla Firefox\\abcd.exe.exe"=
"c:\\Documents and Settings\\matt\\Application Data\\Real\\Update\\UpgradeHelper\\RealPlayer\\9.00\\rnupgagent.exe"=
"c:\\Documents and Settings\\admin\\Application Data\\Real\\Update\\UpgradeHelper\\RealPlayer\\9.00\\rnupgagent.exe"=
"c:\\Documents and Settings\\matt\\My Documents\\Downloads\\Brothersoftdownloader_for_Advanced_Process_Termination.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"58221:TCP"= 58221:TCP:Pando Media Booster
"58221:UDP"= 58221:UDP:Pando Media Booster
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [x]
R2 Icecast-trunk;Icecast-trunk Streaming Media Server;c:\program files\Icecast2 Win32\icecastService.exe [x]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [x]
R3 38982636;38982636;c:\windows\system32\drivers\61068841.sys [2011-08-31 94768]
R3 39128875;39128875;c:\windows\system32\drivers\80223438.sys [2011-08-31 94768]
R3 51518490;51518490;c:\windows\system32\drivers\76704618.sys [2011-08-31 94768]
R3 AIDA32Driver;AIDA32Driver;c:\docume~1\matt\LOCALS~1\Temp\Rar$EX36.416\aida32.sys [x]
R3 cpuz130;cpuz130;c:\docume~1\matt\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
R3 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2011-08-21 35816]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 XDva385;XDva385;c:\windows\system32\XDva385.sys [x]
S0 mv61xxmm;mv61xxmm; [x]
S0 mv64xxmm;mv64xxmm; [x]
S0 mvxxmm;mvxxmm; [x]
S2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\Drivers\Scutum50.sys [2009-04-21 19072]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-09-05 c:\windows\Tasks\Automatic Maintenance.job
- c:\program files\TuneUp Utilities 2011\OneClickStarter.exe [2010-10-27 23:26]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com/?l=dis&o;=16794S
uInternet Settings,ProxyOverride = *.local
IE: Download with FLV Blaster - c:\documents and settings\matt\Application Data\FLV Blaster\Internet Explorer\script.htm
IE: Download with FLV Blaster\Contexts - 1 (0x1)
IE: Download with FLV Blaster\Flags - 1 (0x1)
TCP: DhcpNameServer = 192.168.15.1
FF - ProfilePath - c:\documents and settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;=
FF - user.js: keyword.URL - hxxp://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Skype - c:\program files\Skype\Phone\Skype.exe
SafeBoot-38982636.sys
SafeBoot-39128875.sys
SafeBoot-51518490.sys
AddRemove-SB16 - c:\program files\Creative\CTSND\DeIsL1.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-25 16:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(896)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(1772)
c:\windows\system32\WININET.dll
c:\documents and settings\matt\Local Settings\Application Data\FLVService\lib\FLVSrvLib.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\PROMon.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2011-10-25 16:05:23 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-25 21:05
.
Pre-Run: 53,886,287,872 bytes free
Post-Run: 54,053,527,552 bytes free
.
- - End Of File - - 64E3E2586B374A8ED0B0A4A74C1436ED
We got the right service though ——-\Service_9dc20117 I will be trying that on my next unfortunate victim - Thanks

Could you run a fresh OTL log now selecting all users and I will remove any remnants

But more to the point how is the computer behaving ?

I have a few files that need replacing so I will use OTL to look for them


  • Run OTL.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    sfcfiles.*
    wuauclt.*
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window.
  • Post this logs
computer is running great. the google redirect seems to be gone (thanks you! sooo annoying lol) but the windows install still dosent work. and i dont think system restore is fixed yet. still have a few file on the desktop that the virus blocked. so i cant i cant delete them or move them. but heres the log

OTL logfile created on: 10/25/2011 4:40:54 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\matt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.30 Mb Total Physical Memory | 523.34 Mb Available Physical Memory | 51.55% Memory free
14.65 Gb Paging File | 14.33 Gb Available in Paging File | 97.82% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.12 Gb Total Space | 50.40 Gb Free Space | 22.49% Space Free | Partition Type: NTFS
Drive D: | 8.74 Gb Total Space | 4.76 Gb Free Space | 54.41% Space Free | Partition Type: FAT32

Computer Name: MATTHEW-B672D25 | User Name: matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\matt\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PROMon.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()


========== Win32 Services (SafeList) ==========

SRV - (RalinkRegistryWriter) – File not found
SRV - (PCToolsSSDMonitorSvc) – File not found
SRV - (NMSSvc) Intel® – File not found
SRV - (Icecast-trunk) – File not found
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (MSIServer) – C:\WINDOWS\System32\msiexec.exe ()


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (39128875) – C:\WINDOWS\system32\drivers\80223438.sys (Kaspersky Lab, GERT)
DRV - (51518490) – C:\WINDOWS\system32\drivers\76704618.sys (Kaspersky Lab, GERT)
DRV - (38982636) – C:\WINDOWS\system32\drivers\61068841.sys (Kaspersky Lab, GERT)
DRV - (Partizan) – C:\WINDOWS\system32\drivers\Partizan.sys (Greatis Software)
DRV - (mvxxmm) – C:\WINDOWS\System32\drivers\mvxxmm.sys (Marvell Semiconductor Inc.)
DRV - (mv64xxmm) – C:\WINDOWS\System32\drivers\mv64xxmm.sys (Marvell Semiconductor Inc.)
DRV - (mv61xxmm) – C:\WINDOWS\System32\drivers\mv61xxmm.sys (Marvell Semiconductor Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (Scutum50) – C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) – C:\WINDOWS\system32\drivers\vcsvad.sys (Avnex)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o;=16794S
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B2 19 A5 54 5A F4 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: [removed]:3.3.5.1
FF - prefs.js..extensions.enabledItems: [removed]:1.7.3
FF - prefs.js..extensions.enabledItems: [removed]:5.90
FF - prefs.js..extensions.enabledItems: {3DB5ABE1-407D-458F-AD5D-8D89BD625CCC}:1.2.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.3.5.20110120033202
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.4
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.8
FF - prefs.js..extensions.enabledItems: {e6103d7b-6052-4575-a010-59037765e87a}:[removed]
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:5.0.0
FF - prefs.js..extensions.enabledItems: [removed]:2.5.3
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.2.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.7
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.66
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: {bb6bc1bb-f824-4702-90cd-35e2fb24f25d}:1.5.1
FF - prefs.js..keyword.URL: "http://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;="
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "[removed]"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl_port: 80

FF - user.js..keyword.URL: "http://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;="
FF - user.js..keyword.enabled: 1

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/04/07 00:28:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/04/07 00:28:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2011/04/29 21:29:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/21 15:22:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/25 00:35:23 | 000,000,000 | —D | M]

[2011/05/24 21:41:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Extensions
[2011/05/24 21:41:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Extensions\[removed]
[2011/10/16 17:39:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions
[2011/06/21 14:04:38 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/18 13:07:56 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011/05/08 16:55:17 | 000,000,000 | —D | M] (Veehd Plugin) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{3DB5ABE1-407D-458F-AD5D-8D89BD625CCC}
[2011/08/17 23:53:08 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/05/08 17:04:25 | 000,000,000 | —D | M] (Tamper Data) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2011/08/16 18:46:21 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2011/07/07 17:12:35 | 000,000,000 | —D | M] (Cookies Manager+) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
[2011/07/07 07:29:22 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2011/08/16 18:46:25 | 000,000,000 | —D | M] ("BetterPrivacy") – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}(2)
[2011/08/16 18:46:22 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(2)
[2011/08/16 18:46:23 | 000,000,000 | —D | M] (quixley_v2 Community Toolbar) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e6103d7b-6052-4575-a010-59037765e87a}(2)
[2011/07/07 06:42:59 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/04/23 04:18:30 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/06/21 14:04:58 | 000,000,000 | —D | M] (Firebug) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/10/16 17:39:19 | 000,000,000 | —D | M] (Ghostery) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/05/04 23:17:12 | 000,000,000 | —D | M] (FLV Blaster) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/06/10 22:28:27 | 000,002,568 | —- | M] () – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\searchplugins\askcom.xml
[2011/12/24 18:44:45 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/12 18:21:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/12 19:07:02 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/05/07 03:35:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\[removed]
[2011/04/12 18:21:01 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/21 15:22:54 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/13 18:58:48 | 002,418,176 | —- | M] (1 mal 1 Software GmbH) – C:\Program Files\mozilla firefox\plugins\NpFp530.dll
[2011/12/21 15:22:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/24 18:34:05 | 000,001,235 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\flvtube.xml

O1 HOSTS File: ([2011/10/25 16:01:17 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [cFosTASKTR] C:\WINDOWS\BOX_cFosTASK.exe ()
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PROMon.exe] C:\WINDOWS\System32\PROMon.exe (Intel Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download with FLV Blaster - C:\Documents and Settings\matt\Application Data\FLV Blaster\Internet Explorer\script.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBBAC1D3-9A89-4AC7-B78F-AF89E2DEA75A}: DhcpNameServer = 192.168.15.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/24 21:28:18 | 000,000,097 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (Partizan)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/12/24 21:28:00 | 000,000,000 | —D | C] – C:\Program Files\Creative
[2011/12/24 20:44:05 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\Desktop\New Folder (2)(2)
[2011/12/24 19:30:50 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\matt\Desktop\HiJackThis.exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(6).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(5).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(4).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(3).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(2).exe
[2011/12/24 06:30:41 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/24 06:27:11 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/12/24 06:27:10 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/12/24 06:27:06 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/12/24 06:27:05 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/12/24 06:26:34 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/12/24 06:26:10 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/24 06:21:00 | 004,271,407 | R— | C] (Swearware) – C:\ComboFix.exe
[2011/12/22 15:46:27 | 000,000,000 | —D | C] – C:\_OTL
[2011/12/22 15:00:51 | 004,274,341 | R— | C] (Swearware) – C:\Documents and Settings\matt\Desktop\ComboFix.exe
[2011/12/22 05:16:00 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\matt\Desktop\OTL.exe
[2011/12/22 04:59:38 | 000,000,000 | —D | C] – C:\New Folder (2)
[2011/12/18 07:10:48 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Real
[2011/10/25 16:05:25 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/10/25 01:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\Desktop\device identifyer
[2011/10/25 00:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\DoctorWeb
[2011/10/24 23:49:15 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/10/24 23:08:08 | 000,000,000 | —D | C] – C:\ComboFix(7)
[2011/10/24 23:04:40 | 000,000,000 | —D | C] – C:\ComboFix(6)
[2011/10/24 23:01:02 | 000,000,000 | —D | C] – C:\ComboFix(5)
[2011/10/24 22:57:49 | 000,000,000 | —D | C] – C:\ComboFix(4)
[2011/10/24 22:53:59 | 000,000,000 | —D | C] – C:\ComboFix(3)
[2011/10/24 22:32:41 | 000,000,000 | —D | C] – C:\ComboFix(2)
[2011/10/24 20:59:49 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\Application Data\GetRightToGo
[2011/10/16 09:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/10/16 09:38:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/24 21:34:43 | 000,504,722 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/24 21:34:43 | 000,088,848 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/24 21:28:18 | 000,000,097 | —- | M] () – C:\AUTOEXEC.BAT
[2011/12/24 19:56:50 | 000,000,227 | —- | M] () – C:\WINDOWS\SYSTEM.I~I
[2011/12/24 19:30:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\matt\Desktop\HiJackThis.exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(6).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(5).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(4).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(3).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(2).exe
[2011/12/24 06:21:03 | 004,271,407 | R— | M] (Swearware) – C:\ComboFix.exe
[2011/12/22 17:43:07 | 079,471,296 | —- | M] () – C:\Documents and Settings\matt\Desktop\u38dn2jh.exe
[2011/12/22 16:10:48 | 098,304,600 | —- | M] () – C:\Documents and Settings\matt\Desktop\setup_11.0.0.1245.x01_2011_10_22_21_43.exe
[2011/12/22 04:03:59 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/20 19:13:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/25 16:40:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\matt\Desktop\OTL.exe
[2011/10/25 16:01:17 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/10/25 16:00:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/25 15:39:43 | 004,274,341 | R— | M] (Swearware) – C:\Documents and Settings\matt\Desktop\ComboFix.exe
[2011/10/25 00:25:58 | 000,000,064 | —- | M] () – C:\WINDOWS\wininit.ini
[2011/10/25 00:16:45 | 000,000,336 | RHS- | M] () – C:\boot.ini
[2011/10/24 23:50:12 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/10/24 22:55:52 | 000,050,112 | -HS- | M] () – C:\WINDOWS\System32\c_43440.nl_
[2011/10/24 20:44:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/16 23:15:25 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/10/16 10:56:20 | 000,000,865 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Phoenix Viewer.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/24 21:28:07 | 000,011,760 | —- | C] () – C:\WINDOWS\System32\WFM0001A.CSP
[2011/12/24 21:28:07 | 000,009,004 | —- | C] () – C:\WINDOWS\System32\WFM0203A.CSP
[2011/12/24 21:28:07 | 000,009,004 | —- | C] () – C:\WINDOWS\System32\WFM0202A.CSP
[2011/12/24 21:28:07 | 000,006,776 | —- | C] () – C:\WINDOWS\System32\WFM0201A.CSP
[2011/12/24 21:28:07 | 000,006,108 | —- | C] () – C:\WINDOWS\System32\WFM0011A.CSP
[2011/12/24 21:28:07 | 000,002,238 | —- | C] () – C:\WINDOWS\System32\WFM0200A.CSP
[2011/12/24 21:28:07 | 000,001,524 | —- | C] () – C:\WINDOWS\System32\WFM0006A.CSP
[2011/12/24 21:28:07 | 000,001,478 | —- | C] () – C:\WINDOWS\System32\WFM0007A.CSP
[2011/12/24 21:27:37 | 000,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.I~I
[2011/12/24 06:31:32 | 000,000,220 | —- | C] () – C:\Boot.bak
[2011/12/24 06:31:29 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/12/24 06:27:11 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/12/24 06:27:11 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/12/24 06:27:08 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/12/24 06:27:08 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/12/24 06:27:08 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/12/22 17:43:03 | 079,471,296 | —- | C] () – C:\Documents and Settings\matt\Desktop\u38dn2jh.exe
[2011/12/22 16:06:34 | 098,304,600 | —- | C] () – C:\Documents and Settings\matt\Desktop\setup_11.0.0.1245.x01_2011_10_22_21_43.exe
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(6).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(5).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(4).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(3).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(2).dll
[2011/10/25 00:25:58 | 000,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2011/10/25 00:03:24 | 000,000,691 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
[2011/10/16 10:56:20 | 000,000,865 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Phoenix Viewer.lnk
[2011/08/23 06:04:51 | 000,001,638 | —- | C] () – C:\WINDOWS\Sandboxie.ini
[2011/07/14 15:49:19 | 000,000,819 | —- | C] () – C:\WINDOWS\CoDUO.INI
[2011/07/14 15:24:21 | 000,037,336 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/07/14 14:52:16 | 000,000,036 | —- | C] () – C:\Documents and Settings\matt\Local Settings\Application Data\housecall.guid.cache
[2011/07/14 12:09:21 | 000,000,745 | —- | C] () – C:\WINDOWS\CoD.INI
[2011/07/08 23:43:00 | 000,000,203 | —- | C] () – C:\WINDOWS\GSdx9.INI
[2011/07/08 13:01:19 | 000,000,203 | —- | C] () – C:\WINDOWS\GSdx9 sse2.INI
[2011/06/13 14:38:55 | 000,182,275 | —- | C] () – C:\WINDOWS\System32\d3d10core.dll
[2011/06/13 14:38:55 | 000,124,931 | —- | C] () – C:\WINDOWS\System32\dxgi.dll
[2011/06/13 14:38:52 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\M2000Twn.dll
[2011/06/13 14:38:49 | 000,728,858 | —- | C] () – C:\Program Files\Common Files\unins000.exe
[2011/06/13 14:38:49 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\CompressATI2.dll
[2011/06/13 14:38:49 | 000,003,005 | —- | C] () – C:\Program Files\Common Files\unins000.dat
[2011/05/31 12:30:07 | 000,000,171 | —- | C] () – C:\WINDOWS\icecast2.ini
[2011/05/30 22:19:36 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2011/04/29 20:55:50 | 000,008,704 | —- | C] () – C:\Documents and Settings\matt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/23 05:56:54 | 000,000,980 | —- | C] () – C:\WINDOWS\eReg.dat
[2011/04/21 21:03:42 | 000,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2011/04/21 21:03:41 | 000,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2011/04/18 18:38:30 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2011/04/13 16:44:06 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2011/04/08 22:04:58 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/07 16:20:49 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2011/04/06 08:49:03 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/04/06 08:23:13 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\DiagFunc.dll
[2011/04/06 08:23:13 | 000,001,191 | —- | C] () – C:\WINDOWS\System32\W32N55.INI
[2011/04/06 08:23:13 | 000,000,480 | —- | C] () – C:\WINDOWS\System32\DiagFunc.ini
[2011/04/06 08:22:11 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4764.dll
[2011/04/05 22:31:10 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/05 22:25:31 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/05 17:18:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/05 17:16:47 | 002,019,440 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/25 12:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/01 02:46:04 | 000,407,476 | —- | C] () – C:\WINDOWS\BOX_cFosTASK.exe
[2010/02/28 10:17:48 | 003,284,480 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2008/04/14 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 06:00:00 | 000,504,722 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 06:00:00 | 000,095,744 | —- | C] () – C:\WINDOWS\System32\msiexec.exe
[2008/04/14 06:00:00 | 000,088,848 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 06:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 06:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/03/26 08:36:48 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\PROInst.dll
[2002/02/06 09:04:14 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\NMSInst.dll
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2011/06/15 13:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ableton
[2011/06/03 22:14:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2011/10/16 23:20:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/08/23 05:28:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/08/12 08:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\firebird
[2011/08/14 00:40:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/08/23 05:28:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/12 12:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/05/13 08:29:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2011/07/13 22:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2011/04/06 10:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2011/04/21 20:46:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/08/16 18:53:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Premium
[2011/04/06 08:23:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2011/10/25 00:18:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/06/13 15:07:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/06/13 14:55:24 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011/05/24 21:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/08/23 03:36:23 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\.minecraft
[2011/06/15 13:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Ableton
[2011/06/03 22:16:19 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\acccore
[2011/05/27 13:47:01 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Avnex
[2011/08/27 10:24:00 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\BitLord
[2011/08/16 19:17:59 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Blender Foundation
[2011/04/06 08:04:49 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Blitware
[2011/04/07 00:29:45 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\DDMSettings
[2011/08/12 07:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\ElevatedDiagnostics
[2011/05/04 23:17:11 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\FLV Blaster
[2011/06/13 15:29:53 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\FrostWire
[2011/10/24 21:03:55 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\GetRightToGo
[2011/08/22 20:06:05 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\MWSE
[2011/05/13 08:30:04 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Paltalk
[2011/07/20 11:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Python-Eggs
[2011/07/14 15:34:50 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Registry Mechanic
[2011/05/24 22:38:40 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\rockbox.org
[2011/06/26 11:35:49 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\SecondLife
[2011/08/24 09:19:40 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\SystemRequirementsLab
[2011/06/13 13:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\TeamViewer
[2011/06/02 01:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Titanium
[2011/08/19 21:30:32 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\tixati
[2011/08/16 18:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\tixati(3)
[2011/06/13 14:56:09 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\TuneUp Software
[2011/10/25 16:06:41 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\uTorrent
[2011/09/05 08:14:00 | 000,000,474 | —- | M] () – C:\WINDOWS\Tasks\Automatic Maintenance.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2011/12/24 06:21:03 | 004,271,407 | R— | M] (Swearware) – C:\ComboFix.exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(2).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(3).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(4).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(5).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(6).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(2).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(3).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(4).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(5).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(6).exe


< MD5 for: SFCFILES.DLL >
[2011/02/14 13:56:08 | 001,614,848 | —- | M] (Microsoft Corporation) MD5=E17798E1E6FF1CA9C67B8576570E05EE – C:\pebuilder3110a\BartPE\i386\system32\sfcfiles.dll
[2011/02/14 13:56:08 | 001,614,848 | —- | M] (Microsoft Corporation) MD5=E17798E1E6FF1CA9C67B8576570E05EE – C:\WINDOWS\system32\sfcfiles.dll

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 177 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:76650B61

< End of report >
ok well i figured out how to fix windows installer. and remove the files on my desktop that have been blocked. you just right click it and select properties, then select the security tab (note: you much have "use simple file shareing" unchecked. to do that you go to tools/folder options/view then scroll down and its at the bottom.) once in security tab click add click advanced then find now on the right side find your login name or just select user at the bottom then click ok then click ok again once thats done select the one you just added and give it full control and you will be able to freely delete it. (i had to do that with msiexec.exe. then i just reinstalled windows installer and it works fine now)
OTL looks good and sfcfiles is legitimate - However, there was no spare wuauclt.exe to replace. So download and run the latest copy from here

We are possible just in the repair and tidy phase now

Could you list any problems you are experiencing and we will try to fix them
well tbh i think the only thing wrong is that programs still arnt making any system restore points. im not going to try and restore just to be safe lol other then that thier dosent seem to be anything wrong
OTL is having problems creating a restore point

Could you go to windows\system32\inf and locate sr.inf
Right click and select install

This will attempt to reinstall system restore - you may need to show hidden files
ok it seems to have reinstalled. theirs no entry's ecsept for right now. luckily i have a copy of windows xp professional for things like this because the file it needed wasn't on the drive any more x.x lol

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI