This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirection / Fake Virus Scan

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Running Windows 7 Ultimate. Initial problems with the computer: - Redirection of browsers (to IP: [removed]). Trying a second time loaded the page. - Anti-virus sites were completely blocked. Researched on another computer and started killing processes like 170.exe. At that point: - Task manager shut down, as did Zone Alarm, AdAware, and everything else I had running. - Trying to run anything, the program was immediately shut down. - When each program shut down, I got notices that the programs were infected. - A fake virus scan popped up, warning me of infected files and child porn. Booting into Safe Mode and running Malwarebytes Anti-Malware, along with me deleting files that were created at the time I was infected (Zone Alarm popped up a notice, but I thought it had prevented infection) eventually allowed me to boot back into Windows. Malwarebytes then found privacy.exe, which it also quarantined. Everything seems to be working, except that the Google Updater keeps crashing. (Not sure if that's related.) I'd been planning to reinstall this computer anyway, so making sure the MBR is clean is my primary concern since I can boot from the Windows CD.
OTL.Txt:

OTL logfile created on: 11/20/2011 9:05:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\cherie\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 65.25% Memory free
5.98 Gb Paging File | 4.87 Gb Available in Paging File | 81.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50.00 Gb Total Space | 7.41 Gb Free Space | 14.81% Space Free | Partition Type: NTFS
Drive D: | 99.04 Gb Total Space | 9.73 Gb Free Space | 9.82% Space Free | Partition Type: NTFS
Drive E: | 1.06 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 111.78 Gb Total Space | 1.67 Gb Free Space | 1.50% Space Free | Partition Type: NTFS

Computer Name: CHERIE-LAPTOP | User Name: cherie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\cherie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\cherie\AppData\Local\auditpol.exe ()
PRC - C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\drivers\o2flash.exe (O2Micro International)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\cherie\AppData\Local\auditpol.exe ()
MOD - C:\Users\cherie\AppData\Local\auditpol.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MySQL) – C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (vsmon) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (O2FLASH) – C:\Windows\System32\drivers\o2flash.exe (O2Micro International)
SRV - (AERTFilters) – C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (Adobe Version Cue CS3) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (pneteth) – C:\Windows\System32\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV - (truecrypt) – C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (cpuz135) – C:\Windows\System32\drivers\cpuz135_x32.sys (CPUID)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (netw5v32) Intel® – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (O2MDRDR) – C:\Windows\System32\drivers\o2media.sys (O2Micro )
DRV - (O2SDRDR) – C:\Windows\System32\drivers\o2sd.sys (O2Micro )
DRV - (MagicTune) – C:\Windows\System32\drivers\MTictwl.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 01 67 86 A8 EF 82 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:53212

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.sidereel.com/users"
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.6.2
FF - prefs.js..extensions.enabledItems: {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}:2.3.1
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.12
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.8.23
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {a95d8332-e4b4-6e7f-98ac-20b733364387}:0.5.2
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 53212
FF - prefs.js..network.proxy.socks: "127.0.0.1"
FF - prefs.js..network.proxy.socks_port: 9000
FF - prefs.js..network.proxy.type: 1

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\cherie\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\cherie\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/11/20 11:02:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/30 09:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/10 19:03:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox 7\components [2011/11/10 19:49:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox 7\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/09/20 09:00:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2011/06/05 18:58:51 | 000,000,000 | —D | M] (No name found) – C:\Users\cherie\AppData\Roaming\Mozilla\Extensions
[2011/11/18 22:45:09 | 000,000,000 | —D | M] (No name found) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions
[2011/07/11 18:38:32 | 000,000,000 | —D | M] (Delicious Bookmarks) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2011/06/06 12:39:57 | 000,000,000 | —D | M] (oldbar) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}
[2011/10/20 18:44:56 | 000,000,000 | —D | M] (ColorZilla) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2011/07/15 11:49:40 | 000,000,000 | —D | M] (LeechBlock) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{a95d8332-e4b4-6e7f-98ac-20b733364387}
[2011/11/10 19:49:56 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/06/05 21:22:58 | 000,000,000 | —D | M] (Web Developer) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2011/10/03 13:22:48 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/08/27 13:11:15 | 000,000,000 | —D | M] (QuickProxy) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{d5ea4520-61a1-11da-8cd6-0800200c9a66}
[2011/11/18 22:45:09 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/06/06 12:39:57 | 000,000,000 | —D | M] (Tabberwocky) – C:\Users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\extensions\[removed]
[2011/07/01 13:42:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/06/26 17:43:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
() (No name found) – C:\USERS\CHERIE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\V5RC9T8Y.DEFAULT\EXTENSIONS\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.XPI
() (No name found) – C:\USERS\CHERIE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\V5RC9T8Y.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\CHERIE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\V5RC9T8Y.DEFAULT\EXTENSIONS\[removed]
[2011/06/26 17:42:50 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\cherie\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\cherie\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\cherie\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\cherie\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: better_facebook.user.js = C:\Users\cherie\AppData\Local\Google\Chrome\User Data\Default\Extensions\fipgimglebdjndecnmmgnadlgkcfaeba\1.0_0\
CHR - Extension: AdBlock = C:\Users\cherie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.4.29_0\
CHR - Extension: Social Fixer = C:\Users\cherie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipjaijdkhejnbfpodmofannadgfokfnm\6.201_0\
CHR - Extension: Save in Delicious = C:\Users\cherie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnaelnkmidnndgikjbiifihgklnocljd\1.0_0\

O1 HOSTS File: ([2011/11/10 15:20:52 | 000,000,854 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 vlgm.local
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (IE Developer Toolbar BHO) - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ISW] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [auditpol] C:\Users\cherie\AppData\Local\auditpol.exe ()
O4 - HKCU..\Run: [TrueCrypt] C:\Program Files\TrueCrypt\TrueCrypt.exe (TrueCrypt Foundation)
O4 - Startup: C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\cherie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastCheck.lnk = C:\Program Files\FastCheck\FastCheck.exe ()
O4 - Startup: C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{337D3C22-51EC-473E-A3FF-DA0D888C7155}: DhcpNameServer = 10.8.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{337D3C22-51EC-473E-A3FF-DA0D888C7155}: NameServer = 10.8.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A16D5DB-AAF7-4772-BF61-CF25BBB03D40}: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A16D5DB-AAF7-4772-BF61-CF25BBB03D40}: NameServer = 192.168.254.254
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\SL_ANET.ACM (Sipro Lab Telecom Inc.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 21:04:05 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\cherie\Desktop\OTL.exe
[2011/11/20 19:05:43 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\Malwarebytes
[2011/11/20 19:05:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/20 19:05:23 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/20 19:04:56 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/11/20 19:04:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/20 18:19:03 | 000,000,000 | —D | C] – C:\Windows\pss
[2011/11/20 15:38:38 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.backup.exe
[2011/11/20 15:38:36 | 000,000,000 | —D | C] – C:\Windows\W7SOC
[2011/11/20 15:27:22 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\B25EF
[2011/11/20 15:26:41 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\E61B2
[2011/11/20 10:31:27 | 000,000,000 | —D | C] – C:\Program Files\zonealarm_security_suite
[2011/11/20 10:30:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
[2011/11/20 09:50:17 | 000,000,000 | —D | C] – C:\Users\cherie\Documents\ForceField Shared Files
[2011/11/20 09:46:12 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\CheckPoint
[2011/11/20 09:45:27 | 000,000,000 | —D | C] – C:\ProgramData\CheckPoint
[2011/11/20 09:44:53 | 000,240,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2011/11/20 09:39:08 | 000,000,000 | —D | C] – C:\Program Files\CheckPoint
[2011/11/19 15:03:34 | 000,000,000 | —D | C] – C:\Program Files\Synergy
[2011/11/14 17:51:02 | 000,000,000 | —D | C] – C:\mysql-c
[2011/11/14 17:42:48 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ruby 1.8.7-p352
[2011/11/14 16:55:52 | 000,000,000 | —D | C] – C:\pik
[2011/11/14 13:43:57 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ruby 1.9.3-p0
[2011/11/14 13:43:38 | 000,000,000 | —D | C] – C:\Ruby
[2011/11/10 21:04:53 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\MySQL
[2011/11/10 21:03:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
[2011/11/10 21:00:01 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2011/11/10 16:54:48 | 000,000,000 | —D | C] – C:\PHP
[2011/11/10 15:35:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PHP 5
[2011/11/09 18:44:03 | 000,000,000 | —D | C] – C:\mongodb
[2011/11/09 15:04:52 | 000,000,000 | —D | C] – C:\ANSICON
[2011/11/09 10:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyLifeOrganized
[2011/11/09 08:06:20 | 002,339,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/11/08 10:36:43 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL
[2011/11/08 10:36:35 | 000,000,000 | —D | C] – C:\Program Files\MySQL
[2011/11/08 10:36:34 | 000,000,000 | —D | C] – C:\ProgramData\MySQL
[2011/11/07 21:46:37 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/11/07 15:42:45 | 000,000,000 | —D | C] – C:\Users\cherie\.gem
[2011/11/07 15:25:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apache HTTP Server 2.2
[2011/11/07 15:24:52 | 000,000,000 | —D | C] – C:\Program Files\Apache Software Foundation
[2011/11/07 11:50:43 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2011/11/07 11:48:43 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/11/05 18:44:04 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2011/11/05 18:44:04 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\IrfanView
[2011/11/05 18:44:04 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2011/11/05 18:19:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2011/11/05 14:09:16 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\XnView
[2011/11/05 14:09:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
[2011/11/05 14:09:08 | 000,000,000 | —D | C] – C:\Program Files\XnView
[2011/11/05 13:47:55 | 000,000,000 | —D | C] – C:\Users\cherie\Documents\AdobeStockPhotos
[2011/11/05 12:08:22 | 000,000,000 | —D | C] – C:\Windows\System32\SDA
[2011/11/05 12:08:22 | 000,000,000 | —D | C] – C:\Program Files\O2Micro Flash Memory Card Driver
[2011/11/05 12:07:35 | 000,000,000 | —D | C] – C:\dell
[2011/11/02 11:27:01 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\IsolatedStorage
[2011/11/02 11:26:52 | 000,000,000 | —D | C] – C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ljArchive
[2011/11/02 11:26:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ljArchive
[2011/11/02 11:26:52 | 000,000,000 | —D | C] – C:\Program Files\ljArchive

========== Files - Modified Within 30 Days ==========

[2011/11/20 21:09:14 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 21:09:14 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 21:06:27 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/11/20 21:06:27 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/11/20 21:04:01 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\cherie\Desktop\OTL.exe
[2011/11/20 21:03:03 | 000,000,064 | —- | M] () – C:\Windows\System32\rp_stats.dat
[2011/11/20 21:03:03 | 000,000,044 | —- | M] () – C:\Windows\System32\rp_rules.dat
[2011/11/20 21:01:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 21:01:52 | 2408,390,656 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 19:21:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4038262297-2028210644-1364963116-1000UA.job
[2011/11/20 16:18:05 | 000,000,382 | —- | M] () – C:\Windows\tasks\At1.job
[2011/11/20 15:38:38 | 000,916,480 | —- | M] () – C:\Windows\expstart.exe
[2011/11/20 13:52:52 | 000,065,536 | -HS- | M] () – C:\Users\cherie\AppData\Local\auditpol.exe
[2011/11/20 13:52:50 | 000,025,088 | -HS- | M] () – C:\Users\cherie\AppData\Local\auditpol.dll
[2011/11/20 10:33:01 | 000,411,107 | —- | M] () – C:\Windows\System32\drivers\vsconfig.xml
[2011/11/20 09:53:03 | 000,001,005 | —- | M] () – C:\Users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/11/20 09:21:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4038262297-2028210644-1364963116-1000Core.job
[2011/11/19 17:15:58 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/11/19 17:14:56 | 001,695,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 21:04:29 | 000,002,012 | —- | M] () – C:\Users\cherie\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/07 20:15:50 | 000,007,605 | —- | M] () – C:\Users\cherie\AppData\Local\Resmon.ResmonCfg
[2011/11/07 15:25:03 | 000,001,340 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
[2011/11/04 13:02:57 | 000,013,133 | —- | M] () – C:\Users\cherie\Application Data\Microsoft\Internet Explorer\Quick Launch\View running processes with Task Manager - Shortcut.lnk

========== Files Created - No Company Name ==========

[2011/11/20 16:17:14 | 000,000,382 | —- | C] () – C:\Windows\tasks\At1.job
[2011/11/20 15:39:09 | 000,916,480 | —- | C] () – C:\Windows\expstart.exe
[2011/11/20 15:30:22 | 000,065,536 | -HS- | C] () – C:\Users\cherie\AppData\Local\auditpol.exe
[2011/11/20 15:30:22 | 000,025,088 | -HS- | C] () – C:\Users\cherie\AppData\Local\auditpol.dll
[2011/11/20 10:31:52 | 000,411,107 | —- | C] () – C:\Windows\System32\drivers\vsconfig.xml
[2011/11/07 15:25:03 | 000,001,340 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
[2011/11/07 11:50:54 | 000,002,491 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2011/11/04 13:02:57 | 000,013,133 | —- | C] () – C:\Users\cherie\Application Data\Microsoft\Internet Explorer\Quick Launch\View running processes with Task Manager - Shortcut.lnk
[2011/10/01 18:11:48 | 000,007,605 | —- | C] () – C:\Users\cherie\AppData\Local\Resmon.ResmonCfg
[2011/08/22 12:16:12 | 000,000,600 | —- | C] () – C:\Users\cherie\AppData\Local\PUTTY.RND
[2011/06/18 18:07:30 | 000,013,396 | —- | C] () – C:\Windows\System32\drivers\MTictwl.sys
[2011/06/10 12:59:44 | 000,000,161 | —- | C] () – C:\Windows\DISPARAM.INI
[2011/06/06 09:54:59 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/06/06 09:54:59 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/06/05 23:35:35 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/06/05 23:19:57 | 000,140,288 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2011/06/05 21:32:28 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/06/05 20:09:09 | 002,463,976 | —- | C] () – C:\Windows\System32\NPSWF32.dll
[2009/09/23 18:16:08 | 002,050,952 | —- | C] () – C:\Windows\System32\igkrng400.bin
[2009/07/13 23:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 23:33:53 | 001,695,792 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 21:05:48 | 000,624,178 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 21:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 21:05:48 | 000,106,522 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 21:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 21:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 21:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 19:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 18:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2011/10/02 15:00:21 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\Audacity
[2011/11/20 20:06:36 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\B25EF
[2011/08/13 15:47:00 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\calibre
[2011/11/20 09:46:12 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\CheckPoint
[2011/06/07 12:29:36 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\com.myweather.desk.topapp
[2011/11/20 21:02:45 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\Dropbox
[2011/11/20 20:29:45 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\E61B2
[2011/11/15 17:49:39 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\FileZilla
[2011/06/10 13:01:39 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\Fujitsu
[2011/08/20 09:51:33 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\HandBrake
[2011/06/05 21:25:08 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\Helios
[2011/11/05 18:44:04 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\IrfanView
[2011/11/02 11:27:01 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\IsolatedStorage
[2011/11/10 21:04:53 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\MySQL
[2011/10/10 14:09:52 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\NetMeter
[2011/07/17 09:59:32 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\PFU
[2011/10/01 09:15:01 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\SecondLife
[2011/11/10 10:17:29 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\SSH
[2011/09/20 09:00:47 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\Thunderbird
[2011/06/10 08:46:36 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\Trillian
[2011/10/26 20:02:09 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\TrueCrypt
[2011/11/05 18:24:27 | 000,000,000 | —D | M] – C:\Users\cherie\AppData\Roaming\XnView
[2011/11/20 16:18:05 | 000,000,382 | —- | M] () – C:\Windows\Tasks\At1.job
[2009/07/13 23:53:46 | 000,010,402 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/06/05 21:34:32 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/11/20 21:01:52 | 2408,390,656 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 21:01:55 | 3211,190,272 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 20:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/13 20:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 14:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/05 23:52:52 | 000,000,470 | -HS- | M] () – C:\Users\cherie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/11/20 21:04:01 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\cherie\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-18 14:22:23

< End of report >

——————————————————————————————————————————————————————————————————————————————————–
Extras.Txt

OTL Extras logfile created on: 11/20/2011 9:05:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\cherie\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 65.25% Memory free
5.98 Gb Paging File | 4.87 Gb Available in Paging File | 81.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50.00 Gb Total Space | 7.41 Gb Free Space | 14.81% Space Free | Partition Type: NTFS
Drive D: | 99.04 Gb Total Space | 9.73 Gb Free Space | 9.82% Space Free | Partition Type: NTFS
Drive E: | 1.06 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 111.78 Gb Total Space | 1.67 Gb Free Space | 1.50% Space Free | Partition Type: NTFS

Computer Name: CHERIE-LAPTOP | User Name: cherie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox 7\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with &IrfanView;] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{029A95A8-E814-4760-B5A1-0D46E2D62FB1}" = PHP 5.2.17
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{15B5294C-1D82-476C-B287-E86A0CC6D6DC}" = MySQL Workbench 5.2 CE
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server {ko_KR}
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D0ED490-BFAB-46F8-9AFB-0DAE0C90AC9E}" = calibre
"{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DC49A9A-6DD0-40D2-A851-527764DA8379}" = Adobe Setup
"{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
"{5BBDED0C-4DB7-4113-9D57-1E257DFDDD19}" = MySQL Server 5.5
"{5E453519-60F6-4A4D-A0BF-16663F9B3536}" = Safari
"{60B28ECA-78BC-4D18-AB63-4A9A93BF881D}" = Adobe Creative Suite 3 Master Collection
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{73E81E9B-7319-43AD-B7CC-1C61405E5089}" = Adobe After Effects CS3 Template Projects & Footage
"{74E2CD0C-D4A2-11D3-95A6-0000E86CFDE5}" = SSH Secure Shell
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{7DFC1012-D346-46CE-B03E-FF79125AE029}" = Adobe Fireworks CS3
"{7ECEF10B-F1C2-4FD5-861F-A3FCB4653304}" = Adobe After Effects CS3 Third Party Content
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
"{85262A06-2D8C-4BC1-B6ED-5A705D09CFFC}" = Apache HTTP Server 2.2.21
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8E7F1A90-032B-012E-9C85-0022FA95C22F}" = Pik
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{92A300C0-E97B-48CC-9702-AB1AAED167E1}" = Adobe Soundbooth CS3 Scores
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{96056420-DDF3-46A7-AA8D-BC2D1AE5290B}" = Microsoft IntelliType Pro 8.1
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AF1B2B2E-03E3-458A-9DEB-32F8C7637374}" = ZoneAlarm Security
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C180FAEF-61D5-4A03-8328-A58D9CDD1C4C}" = ZoneAlarm Firewall
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
"{DBCDB997-EEEB-4BE9-BAFF-26B4094DBDE6}" = ScanSnap Manager
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2867240-F889-4D76-9AAF-252D9A1A623E}" = O2Micro Flash Memory Card Reader Driver (x86)
"{E58F3B88-3B3E-4F85-9323-04789D979C15}" = ScanSnap Organizer
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E7081891-BC7F-43F9-9CE6-B5DD2F497156}" = Internet Explorer Developer Toolbar
"{E9FC7AE6-75D3-4626-9362-763448C3DC1D}" = ScanSnap Organizer
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{EB0202F7-016A-410C-ADE4-40F848CCC661}" = Adobe After Effects CS3
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1D93F5B-881F-49E3-BA56-B4B8FA991059}" = Adobe Encore CS3 Library
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}" = Adobe Contribute CS3
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.1.5 Professional
"Adobe Acrobat 8 Professional_815" = Adobe Acrobat 8.1.5 - CPSID_49013
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"Adobe_915239ded2552e78978d0dbab7657a5" = Add or Remove Adobe Creative Suite 3 Master Collection
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"AudibleManager" = AudibleManager
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.18
"CrossFont_is1" = CrossFont version 5.4
"FastCheck" = FastCheck (remove only)
"FFmpeg for Audacity_is1" = FFmpeg v0.6.2 for Audacity
"FileZilla Client" = FileZilla Client 3.5.1
"HandBrake" = HandBrake 0.9.5
"HDMI" = Intel® Graphics Media Accelerator Driver
"IrfanView" = IrfanView (remove only)
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"ljArchive" = ljArchive
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliType Pro 8.1" = Microsoft IntelliType Pro 8.1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"Mozilla Thunderbird (6.0.2)" = Mozilla Thunderbird (6.0.2)
"MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
"MyLife Organized" = MyLifeOrganized v. 3.6.1
"NetMeter_is1" = NetMeter 1.1.3
"PdaNet_is1" = PdaNet for Android 3.02
"Picasa 3" = Picasa 3
"PS3 Media Server-SHB" = PS3 Media Server
"TreePadBiz" = TreePad Business Edition 7.6
"Trillian" = Trillian
"TrueCrypt" = TrueCrypt
"TVWiz" = Intel® TV Wizard
"VLC media player" = VLC media player 1.1.4
"WinLiveSuite" = Windows Live Essentials
"WinMerge_is1" = WinMerge 2.12.4
"XnView_is1" = XnView 1.98.2
"ZoneAlarm Pro" = ZoneAlarm Pro
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{17E73B15-62D2-43FD-B851-ACF86A8C9D25}_is1" = Ruby 1.9.3-p0
"{F6377277-9DF1-4a1f-A487-CB5D34DCD793}_is1" = Ruby 1.8.7-p352
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"MusicManager" = Music Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/20/2011 9:16:38 PM | Computer Name = cherie-laptop | Source = Application Error | ID = 1000
Description = Faulting application name: rundll32.exe_gcswf32.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bc637 Faulting module name: gcswf32.dll, version: 11.1.102.55,
time stamp: 0x4eaf862f Exception code: 0xc0000005 Fault offset: 0x001cb58b Faulting
process id: 0x3ec Faulting application start time: 0x01cca7eb2d3630d7 Faulting application
path: C:\Windows\system32\rundll32.exe Faulting module path: C:\Users\cherie\AppData\Local\Google\Chrome\APPLIC~1\150874~1.121\gcswf32.dll
Report
Id: 75dede30-13de-11e1-a171-002170e7885d

Error - 11/20/2011 9:23:14 PM | Computer Name = cherie-laptop | Source = Apache Service | ID = 3299
Description = The Apache service named reported the following error: >>> Syntax
error on line 52 of C:/Program Files/Apache Software Foundation/Apache2.2/conf/extra/httpd-vhosts.conf:
.

Error - 11/20/2011 9:23:14 PM | Computer Name = cherie-laptop | Source = Apache Service | ID = 3299
Description = The Apache service named reported the following error: >>> DocumentRoot
must be a directory .

Error - 11/20/2011 9:23:37 PM | Computer Name = cherie-laptop | Source = Application Error | ID = 1000
Description = Faulting application name: GoogleUpdate.exe, version: 1.2.183.21,
time stamp: 0x4b95e661 Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x00033fd0 Faulting
process id: 0xa48 Faulting application start time: 0x01cca7ec2538b225 Faulting application
path: C:\Users\cherie\AppData\Local\Google\Update\GoogleUpdate.exe Faulting module
path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 6f752018-13df-11e1-9c01-002170e7885d

Error - 11/20/2011 9:38:17 PM | Computer Name = cherie-laptop | Source = Application Error | ID = 1000
Description = Faulting application name: GoogleUpdate.exe, version: 1.2.183.21,
time stamp: 0x4b95e661 Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x00033fd0 Faulting
process id: 0x139c Faulting application start time: 0x01cca7ee3d341ab3 Faulting application
path: C:\Users\cherie\AppData\Local\Google\Update\GoogleUpdate.exe Faulting module
path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 7c0da0e4-13e1-11e1-9c01-002170e7885d

Error - 11/20/2011 9:40:55 PM | Computer Name = cherie-laptop | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.163_none_0c187ef99ee1d25a\MFC80U.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/20/2011 9:40:55 PM | Computer Name = cherie-laptop | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.163_none_0c187ef99ee1d25a\MFC80U.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/20/2011 9:45:15 PM | Computer Name = cherie-laptop | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.31.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 14c8 Start Time:
01cca7eea2a54e5d Termination Time: 8 Application Path: C:\Users\cherie\Desktop\OTL.exe

Report
Id:

Error - 11/20/2011 10:02:08 PM | Computer Name = cherie-laptop | Source = Apache Service | ID = 3299
Description = The Apache service named reported the following error: >>> Syntax
error on line 52 of C:/Program Files/Apache Software Foundation/Apache2.2/conf/extra/httpd-vhosts.conf:
.

Error - 11/20/2011 10:02:08 PM | Computer Name = cherie-laptop | Source = Apache Service | ID = 3299
Description = The Apache service named reported the following error: >>> DocumentRoot
must be a directory .

[ System Events ]
Error - 11/20/2011 8:22:41 PM | Computer Name = cherie-laptop | Source = DCOM | ID = 10005
Description =

Error - 11/20/2011 8:22:41 PM | Computer Name = cherie-laptop | Source = DCOM | ID = 10005
Description =

Error - 11/20/2011 8:22:39 PM | Computer Name = cherie-laptop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 11/20/2011 8:22:39 PM | Computer Name = cherie-laptop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 11/20/2011 8:22:39 PM | Computer Name = cherie-laptop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 11/20/2011 8:22:42 PM | Computer Name = cherie-laptop | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1068

Error - 11/20/2011 8:26:20 PM | Computer Name = cherie-laptop | Source = DCOM | ID = 10005
Description =

Error - 11/20/2011 8:26:20 PM | Computer Name = cherie-laptop | Source = DCOM | ID = 10005
Description =

Error - 11/20/2011 9:23:14 PM | Computer Name = cherie-laptop | Source = Service Control Manager | ID = 7024
Description = The Apache2.2 service terminated with service-specific error %%1.

Error - 11/20/2011 10:02:08 PM | Computer Name = cherie-laptop | Source = Service Control Manager | ID = 7024
Description = The Apache2.2 service terminated with service-specific error %%1.


< End of report >
Hi Oh carp**!,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
===================================================

Download aswMBR.exe ( 1.8mb ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan

[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply

===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Also, can you please post any Malwarebytes logs that you have? I would like to see what it removed.

You can find them here: C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd
Out of curiosity, should gmer.exe still be running after 10+ hours? I made sure the settings are exactly as you described. (I'm amused that your forum edits my username. That's really considered a curse word?)
Hi Oh carp**!, No it shouldn't take longer than an hour. Close GMER or restart your computer if your system is frozen and post just the aswMBR and MBAM logs. I didn't realize that… That's pretty funny :lol:
Someone renamed me "Oh Gosh!" :D That's cute. Although I'd have gone with Gosh Darn It! Or Oh, Fiddlesticks! (Believe me, the words I actually said when I realized this was happening would DEFINITELY not have made it past your filters! I wish there was some way to tell the owner of the site that they're infected. I found it on a design blog and have been there a number of times, so I can't imagine it's something they intentionally added. But I'm sure not going back there!) I'm re-running GMER this morning after a reboot to see if it goes better. It wasn't frozen, but it's taking forever on the Windows\SoftwareDistribution\Download files. If those are something I can delete (and if there are other similar files I could delete), we may be able to get a log file out of it. Sorry for a slightly useless response. I'm writing from another computer. I've been keeping networking turned off as much as possible on the infected laptop, and don't want to risk affecting GMER by turning it back on and opening a browser to post the other files. Oh, one thing I did want to ask. When I ran aswMBR, it asked me if I wanted to download updated Avast! definitions or something like that. I said no, since you didn't tell me to do so.
Hi Oh Gosh!, :rofl: Don't worry about GMER if it won't run. As for aswMBR, it is not necessary to download the definitions. Please post the log.
Oh gosh darn fiddlesticks. Ok, here's the copy of aswMBR.txt. There's also a MBR.dat, but it isn't readable. .aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-21 09:04:47 —————————– 09:04:47.375 OS Version: Windows 6.1.7600 09:04:47.375 Number of processors: 2 586 0x1706 09:04:47.391 ComputerName: CHERIE-LAPTOP UserName: cherie 09:04:47.750 Initialize success 09:05:17.738 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 09:05:17.738 Disk 0 Vendor: WDC_WD1600BJKT-75F4T0 11.01A11 Size: 152627MB BusType: 3 09:05:19.766 Disk 0 MBR read successfully 09:05:19.766 Disk 0 MBR scan 09:05:19.766 Disk 0 Windows 7 default MBR code 09:05:19.782 Disk 0 scanning sectors +312560640 09:05:19.813 Disk 0 malicious Win32:MBRoot code @ sector 312560643 ! 09:05:19.813 Disk 0 PE file @ sector 312560665 ! 09:05:19.844 Disk 0 scanning C:\Windows\system32\drivers 09:05:23.698 Service scanning 09:05:25.086 Modules scanning 09:05:30.874 Disk 0 trace - called modules: 09:05:30.889 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys 09:05:30.889 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8617b7d0] 09:05:30.905 3 CLASSPNP.SYS[8b39759e] -> nt!IofCallDriver -> [0x860b47e0] 09:05:30.905 5 ACPI.sys[8ae253b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x860ad908] 09:05:30.920 Scan finished successfully 09:09:15.795 Disk 0 MBR has been saved successfully to "C:\Users\cherie\Desktop\MBR.dat" 09:09:15.810 The log file has been saved successfully to "C:\Users\cherie\Desktop\aswMBR.txt" I also attached Gmer.txt. I didn't want to clutter up my post with it if it wasn't useful, but if you wanted to glance at how far it got, it does refer to "malicious Win32:MBRoot" at the bottom. Here are the logs from Malwarebytes. There are five of them. If I'm remembering correctly, I ran the first three in safe mode, booted into Windows normally, everything exploded again, so I went back into safe mode, ran it again to get the fourth, and then booted back into Windows normally and ran it again to get the fifth. All of these say "safe mode" in them, though, so maybe a log didn't get created for that one? But I know it found one more copy of privacy.exe when I ran it the last time in regular mode. The reason the first couple don't show a lot of infected items is that I had manually gone through and deleted the files and entries before I had any idea what a nasty bug I was dealing with. When I booted back into Windows without safe mode, it recreated all of them. By the way, I found those in C:\Users\cherie\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs. There weren't any logs in the location you mentioned. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7622 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 11/20/2011 7:09:06 PM mbam-log-2011-11-20 (19-09-06).txt Scan type: Flash scan Objects scanned: 113663 Time elapsed: 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\cherie\AppData\Roaming\chrome.exe (Trojan.Agent) -> Quarantined and deleted successfully. ———————————————————————————————————————————————————— Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7622 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 11/20/2011 7:14:27 PM mbam-log-2011-11-20 (19-14-27).txt Scan type: Quick scan Objects scanned: 185769 Time elapsed: 4 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ———————————————————————————————————————————————————— Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8202 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 11/20/2011 8:04:48 PM mbam-log-2011-11-20 (20-04-48).txt Scan type: Quick scan Objects scanned: 0 Time elapsed: 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ———————————————————————————————————————————————————— Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8203 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 11/20/2011 8:06:36 PM mbam-log-2011-11-20 (20-06-36).txt Scan type: Flash scan Objects scanned: 117128 Time elapsed: 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Privacy Protection (Rogue.PrvacyProtect) -> Value: Privacy Protection -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Backdoor.CycBot) -> Value: Load -> Delete on reboot. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Dropper) -> Bad: (C:\Users\cherie\AppData\Roaming\B25EF\lvvm.exe) Good: () -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\Users\cherie\AppData\Roaming\B25EF\lvvm.exe (Trojan.Dropper) -> Quarantined and deleted successfully. c:\Users\cherie\Desktop\privacy protection.lnk (Malware.Trace) -> Quarantined and deleted successfully. c:\Users\cherie\AppData\Roaming\privacy.exe (Rogue.PrvacyProtect) -> Quarantined and deleted successfully. ———————————————————————————————————————————————————— Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8203 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 11/20/2011 8:18:19 PM mbam-log-2011-11-20 (20-18-19).txt Scan type: Quick scan Objects scanned: 184700 Time elapsed: 8 minute(s), 57 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 6 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\cherie\AppData\Local\Temp\4F50.tmp (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\cherie\AppData\Local\Temp\4F51.tmp (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\cherie\AppData\Local\Temp\4F8F.tmp (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\cherie\AppData\Local\Temp\62B1.tmp (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\cherie\AppData\Local\Temp\CFA2.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. c:\Users\cherie\local settings\temporary internet files\Content.IE5\P0TXI16S\3[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully. Oh, I also found these "protection-log" files under C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\Logs: 19:19:38 cherie MESSAGE Protection started successfully 19:19:42 cherie MESSAGE IP Protection started successfully 20:25:35 cherie MESSAGE Protection started successfully 20:25:39 cherie MESSAGE IP Protection started successfully 20:29:44 cherie DETECTION C:\USERS\CHERIE\APPDATA\ROAMING\E61B2\E7885.EXE Trojan.Dropper QUARANTINE 20:44:59 cherie DETECTION C:\USERS\CHERIE\APPDATA\ROAMING\E61B2\E7885.EXE Trojan.Dropper DENY 21:04:14 cherie MESSAGE Protection started successfully 21:04:18 cherie MESSAGE IP Protection started successfully ———————————————————————————————————————————————————— 08:53:13 cherie MESSAGE Protection started successfully 08:53:17 cherie MESSAGE IP Protection started successfully 09:04:18 cherie MESSAGE IP Protection stopped ———————————————————————————————————————————————————— 08:22:12 cherie MESSAGE Protection started successfully 08:22:16 cherie MESSAGE IP Protection started successfully 08:25:09 cherie MESSAGE IP Protection stopped

Attachments:

Hi Oh Gosh!,

Thanks for the logs.

Please Re-Run aswMBR 

Click Scan

On completion of the scan

Click the   Fix for TDL4 or FIXMBR for Whistler   Button Select as appropriate

[external image: Posted Image]

[external image: Posted Image]

Save the log as before and post in your next reply.
It didn't list either of the two you mentioned by name, but the "Fix" button was the enabled one. Log: aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-22 14:13:30 —————————– 14:13:30.189 OS Version: Windows 6.1.7600 14:13:30.189 Number of processors: 2 586 0x1706 14:13:30.191 ComputerName: CHERIE-LAPTOP UserName: cherie 14:13:31.752 Initialize success 14:13:49.717 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 14:13:49.717 Disk 0 Vendor: WDC_WD1600BJKT-75F4T0 11.01A11 Size: 152627MB BusType: 3 14:13:51.950 Disk 0 MBR read successfully 14:13:51.950 Disk 0 MBR scan 14:13:51.950 Disk 0 Windows 7 default MBR code 14:13:52.106 Disk 0 scanning sectors +312560640 14:13:52.215 Disk 0 malicious Win32:MBRoot code @ sector 312560643 ! 14:13:52.262 Disk 0 PE file @ sector 312560665 ! 14:13:52.480 Disk 0 scanning C:\Windows\system32\drivers 14:16:01.487 Service scanning 14:16:02.563 Modules scanning 14:19:26.675 Disk 0 trace - called modules: 14:19:26.769 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys 14:19:26.785 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8617a3f0] 14:19:27.315 3 CLASSPNP.SYS[8b38b59e] -> nt!IofCallDriver -> [0x8608d918] 14:19:27.331 5 ACPI.sys[8aeb33b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x860a0338] 14:19:27.331 Scan finished successfully 14:33:09.818 Disk 0 MBR read successfully 14:33:10.614 Disk 0 scanning sectors +312560640 14:33:10.817 Disk 0 malicious Win32:MBRoot code @ sector 312560643 ! 14:33:10.848 Disk 0 PE file @ sector 312560665 ! 14:33:10.941 Disk 0 sector 312560643 cleaned 14:33:11.035 Disk 0 sector 312560665 cleaned 14:33:11.035 Verifying disinfection 14:33:24.139 Infection fixed successfully - please reboot ASAP 14:33:40.504 Disk 0 MBR has been saved successfully to "C:\Users\cherie\Desktop\MBR.dat" 14:33:40.519 The log file has been saved successfully to "C:\Users\cherie\Desktop\aswMBR.txt"
Hi Oh Gosh!,

Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
It's log, log, it's big, it's heavy, it's wood… According to this, ZoneAlarm is enabled. It shouldn't be, I closed it and it's not showing up in processes. I'm not sure what Windows Defender is… ComboFix 11-11-22.01 - cherie 11/22/2011 15:13:12.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3062.1939 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe FW: ZoneAlarm Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\cherie\AppData\Local\auditpol.dll c:\users\cherie\AppData\Local\auditpol.exe . . ((((((((((((((((((((((((( Files Created from 2011-10-22 to 2011-11-22 ))))))))))))))))))))))))))))))) . . 2011-11-22 20:22 . 2011-11-22 20:22 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-22 13:23 . 2011-11-22 13:23 100864 —-a-w- C:\kwdiqkob.sys 2011-11-21 00:05 . 2011-11-21 00:05 ——– d—–w- c:\users\cherie\AppData\Roaming\Malwarebytes 2011-11-21 00:05 . 2011-11-21 00:05 ——– d—–w- c:\programdata\Malwarebytes 2011-11-21 00:04 . 2011-11-21 00:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-11-21 00:04 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-20 20:39 . 2011-11-20 20:38 916480 —-a-w- c:\windows\expstart.exe 2011-11-20 20:38 . 2009-10-31 05:45 2614272 —-a-w- c:\windows\explorer.backup.exe 2011-11-20 20:38 . 2011-11-20 21:11 ——– d—–w- c:\windows\W7SOC 2011-11-20 20:27 . 2011-11-21 01:06 ——– d—–w- c:\users\cherie\AppData\Roaming\B25EF 2011-11-20 20:26 . 2011-11-21 01:29 ——– d—–w- c:\users\cherie\AppData\Roaming\E61B2 2011-11-20 15:31 . 2011-11-20 15:31 ——– d—–w- c:\program files\zonealarm_security_suite 2011-11-20 14:46 . 2011-11-20 14:46 ——– d—–w- c:\users\cherie\AppData\Roaming\CheckPoint 2011-11-20 14:45 . 2011-11-20 14:45 ——– d—–w- c:\programdata\CheckPoint 2011-11-20 14:44 . 2010-04-09 07:24 240008 —-a-w- c:\windows\system32\drivers\netio.sys 2011-11-20 14:39 . 2011-11-20 15:31 ——– d—–w- c:\program files\CheckPoint 2011-11-19 20:03 . 2011-11-19 22:42 ——– d—–w- c:\program files\Synergy 2011-11-18 14:21 . 2011-10-07 03:48 6668624 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6FAAF419-7A62-456E-9B8E-277B403D43D1}\mpengine.dll 2011-11-14 22:51 . 2011-11-14 22:51 ——– d—–w- C:\mysql-c 2011-11-14 21:55 . 2011-11-14 22:27 ——– d—–w- C:\pik 2011-11-14 18:43 . 2011-11-14 22:42 ——– d—–w- C:\Ruby 2011-11-11 02:04 . 2011-11-11 02:04 ——– d—–w- c:\users\cherie\AppData\Roaming\MySQL 2011-11-11 02:00 . 2011-11-11 02:00 ——– d—–w- c:\program files\Microsoft.NET 2011-11-10 21:54 . 2011-11-10 22:43 ——– d—–w- C:\PHP 2011-11-09 23:44 . 2011-11-10 00:41 ——– d—–w- C:\mongodb 2011-11-09 20:04 . 2011-11-09 20:04 ——– d—–w- C:\ANSICON 2011-11-09 13:06 . 2011-09-29 15:43 1285488 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-09 13:06 . 2011-10-01 04:43 708608 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-09 13:06 . 2011-09-29 04:20 2339840 —-a-w- c:\windows\system32\win32k.sys 2011-11-08 15:36 . 2011-11-11 02:03 ——– d—–w- c:\program files\MySQL 2011-11-08 15:36 . 2011-11-08 15:36 ——– d—–w- c:\programdata\MySQL 2011-11-08 02:46 . 2011-11-08 02:46 ——– d—–w- c:\windows\Downloaded Installations 2011-11-07 20:42 . 2011-11-08 00:42 ——– d—–w- c:\users\cherie\.gem 2011-11-07 20:24 . 2011-11-07 20:24 ——– d—–w- c:\program files\Apache Software Foundation 2011-11-07 16:50 . 2011-11-07 16:50 ——– d—–w- c:\program files\Safari 2011-11-07 16:48 . 2011-11-07 16:48 ——– d—–w- c:\program files\Apple Software Update 2011-11-05 23:44 . 2011-11-05 23:44 ——– d—–w- c:\users\cherie\AppData\Roaming\IrfanView 2011-11-05 23:44 . 2011-11-05 23:44 ——– d—–w- c:\program files\IrfanView 2011-11-05 19:09 . 2011-11-05 23:24 ——– d—–w- c:\users\cherie\AppData\Roaming\XnView 2011-11-05 19:09 . 2011-11-05 19:09 ——– d—–w- c:\program files\XnView 2011-11-05 17:08 . 2011-11-05 17:08 ——– d—–w- c:\windows\system32\SDA 2011-11-05 17:08 . 2011-11-05 17:08 ——– d—–w- c:\program files\O2Micro Flash Memory Card Driver 2011-11-05 17:07 . 2011-11-05 17:07 ——– d—–w- C:\dell 2011-11-02 16:27 . 2011-11-02 16:27 ——– d—–w- c:\users\cherie\AppData\Roaming\IsolatedStorage 2011-11-02 16:26 . 2011-11-02 16:26 ——– d—–w- c:\program files\ljArchive . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-19 22:15 . 2011-06-06 14:06 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-07 14:51 . 2011-03-28 22:36 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-10-01 02:59 . 2011-10-13 13:24 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-08-31 04:05 . 2011-08-31 04:05 83816 —-a-w- c:\windows\system32\dns-sd.exe 2011-08-31 04:05 . 2011-08-31 04:05 73064 —-a-w- c:\windows\system32\dnssd.dll 2011-08-31 04:05 . 2011-08-31 04:05 50536 —-a-w- c:\windows\system32\jdns_sd.dll 2011-08-31 04:05 . 2011-08-31 04:05 178536 —-a-w- c:\windows\system32\dnssdX.dll 2011-08-27 04:43 . 2011-10-13 13:24 571904 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-27 04:43 . 2011-10-13 13:24 233472 —-a-w- c:\windows\system32\oleacc.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\cherie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\cherie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\cherie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TrueCrypt"="c:\program files\TrueCrypt\TrueCrypt.exe" [2011-06-05 1496528] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "RtHDVCpl"="RtHDVCpl.exe" [2008-02-04 4907008] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-04-13 1298320] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-07-22 72336] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608] . c:\users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\cherie\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-10-31 24241928] FastCheck.lnk - c:\program files\FastCheck\FastCheck.exe [2010-12-11 2334720] PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-8-27 480880] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Conversion to PDF with ScanSnap Organizer.lnk - c:\program files\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe [2011-7-16 24576] Monitor Apache Servers.lnk - c:\program files\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe [2011-9-9 41051] ScanSnap Manager.lnk - c:\program files\PFU\ScanSnap\Driver\PfuSsMon.exe [2011-6-10 1159168] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "HideSCAHealth"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^cherie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyWeather Desktop.lnk] path=c:\users\cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyWeather Desktop.lnk backup=c:\windows\pss\MyWeather Desktop.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0] 2008-10-15 01:38 623992 —-a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-09-27 12:22 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-04-27 05:22 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MusicManager] 2011-11-12 00:54 13222400 —-a-w- c:\users\cherie\AppData\Local\Programs\Google\MusicManager\MusicManager.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-11-29 21:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2011-10-13 13:27 17351304 —-a-r- c:\program files\Skype\Phone\Skype.exe . R2 Apache2.2;Apache2.2;c:\program files\Apache Software Foundation\Apache2.2\bin\httpd.exe [2011-09-09 20549] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-09-02 2152152] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-08 1343400] S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2008-02-04 77824] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2010-11-09 21992] S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2011-07-25 27016] S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2011-07-25 493184] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216] S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2008-07-29 51288] S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sd.sys [2008-06-12 43608] S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 13312] . . Contents of the 'Scheduled Tasks' folder . 2011-11-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4038262297-2028210644-1364963116-1000Core.job - c:\users\cherie\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-19 16:54] . 2011-11-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4038262297-2028210644-1364963116-1000UA.job - c:\users\cherie\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-19 16:54] . . ——- Supplementary Scan ——- . uStart Page = about:blank uInternet Settings,ProxyOverride = *.local uInternet Settings,ProxyServer = http=127.0.0.1:53212 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.254.254 TCP: Interfaces\{337D3C22-51EC-473E-A3FF-DA0D888C7155}: NameServer = 10.8.0.1 TCP: Interfaces\{3A16D5DB-AAF7-4772-BF61-CF25BBB03D40}: NameServer = 192.168.254.254 FF - ProfilePath - c:\users\cherie\AppData\Roaming\Mozilla\Firefox\Profiles\v5rc9t8y.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.sidereel.com/users . - - - - ORPHANS REMOVED - - - - . HKCU-Run-auditpol - c:\users\cherie\AppData\Local\auditpol.exe HKLM-Run-ISW - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL] "ImagePath"="\"c:\program files\MySQL\MySQL Server 5.5\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.5\my.ini\" MySQL" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-4038262297-2028210644-1364963116-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4B1D5830-CE5C-C253-1279-7AFAB8005208}*] "oadlepofnbgkpjnibpmhhncjlelogg"=hex:6a,61,70,64,6d,6b,68,6f,6a,62,6a,68,6f,63, 70,67,64,6b,67,6b,00,00 "najmogelgoamngdnmpibknelefgf"=hex:6a,61,70,64,6d,6b,68,6f,6a,62,6a,68,6f,63, 70,67,64,6b,67,6b,00,00 "gblocfpnefkcehgkejhhjjamjhhlmibidhlbebhodjigob"=hex:6d,61,61,6c,63,65,6e,66, 6d,66,6e,6f,69,68,70,6e,6e,69,66,68,6b,62,63,6c,67,6e,00,00 "bbbnampeegefjjlkhhonjlfnnecpicmkicep"=hex:68,62,66,6c,66,6e,70,6c,6c,67,61,61, 61,6a,6d,6e,6b,6f,63,6d,70,6e,68,67,6f,6d,65,61,61,63,6c,6d,66,66,65,64,6c,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'lsass.exe'(536) c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll . Completion time: 2011-11-22 15:24:35 ComboFix-quarantined-files.txt 2011-11-22 20:24 . Pre-Run: 9,817,808,896 bytes free Post-Run: 12,694,253,568 bytes free . - - End Of File - - 64D93406F10C38800554611ACF8D5056
Hi Oh Gosh!,

That is the correct log, thank you.

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and browse to the following file: C:\kwdiqkob.sys
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.
Not quite sure how to post them properly without a screencap. Is there a way to get them in a more readable format? Here's the rather hard to read copy and paste:

Antivirus Version Last Update Result
AhnLab-V3 2011.11.22.00 2011.11.22 -
AntiVir 7.11.18.11 2011.11.22 -
Antiy-AVL 2.0.3.7 2011.11.22 -
Avast 6.0.1289.0 2011.11.22 -
AVG 10.0.0.1190 2011.11.22 -
BitDefender 7.2 2011.11.23 -
ByteHero 1.0.0.1 2011.11.14 -
CAT-QuickHeal 12.00 2011.11.22 -
ClamAV 0.97.3.0 2011.11.22 -
Commtouch 5.3.2.6 2011.11.22 -
Comodo 10781 2011.11.22 -
DrWeb 5.0.2.03300 2011.11.22 -
Emsisoft 5.1.0.11 2011.11.22 -
eSafe 7.0.17.0 2011.11.22 -
eTrust-Vet 37.0.9582 2011.11.22 -
F-Prot 4.6.5.141 2011.11.22 -
F-Secure 9.0.16440.0 2011.11.22 -
Fortinet 4.3.370.0 2011.11.22 -
GData 22.285/22.523 2011.11.22 -
Ikarus T3.1.1.109.0 2011.11.22 -
Jiangmin 13.0.900 2011.11.22 -
K7AntiVirus 9.119.5516 2011.11.22 -
Kaspersky 9.0.0.837 2011.11.22 -
McAfee 5.400.0.1158 2011.11.23 -
McAfee-GW-Edition 2010.1D 2011.11.22 -
Microsoft 1.7801 2011.11.22 -
NOD32 6652 2011.11.23 -
Norman 6.07.13 2011.11.22 -
nProtect 2011-11-22.01 2011.11.22 -
Panda 10.0.3.5 2011.11.22 -
PCTools 8.0.0.5 2011.11.23 -
Prevx 3.0 2011.11.23 -
Rising 23.85.01.02 2011.11.22 -
Sophos 4.71.0 2011.11.22 -
SUPERAntiSpyware 4.40.0.1006 2011.11.22 -
Symantec 20111.2.0.82 2011.11.23 -
TheHacker 6.7.0.1.346 2011.11.22 -
TrendMicro 9.500.0.1008 2011.11.22 -
TrendMicro-HouseCall 9.500.0.1008 2011.11.23 -
VBA32 3.12.16.4 2011.11.22 -
VIPRE 11120 2011.11.22 -
ViRobot 2011.11.22.4787 2011.11.22 -
VirusBuster 14.1.79.0 2011.11.22 -
Additional informationShow all
MD5 : 577c37fbeb973390e61b654d0ac1bebd
SHA1 : d63afbc87838239d816942e81db56cbe237ad1d1
SHA256: 49c9df7fb2200e3e20aedb8f8a69aa28bf858adfbc3ae286957d2479832abb8b
ssdeep: 1536:PhQy2GDoTNx3l7mhrKB3rJ1ucBZsKV5phBuj2pCNsiDjyRHnMcs+Zg5rcS5yZBT:5ABl1u
sVf6Nui2nMcsYgJcS5yT
File size : 100864 bytes
First seen: 2011-07-17 05:09:05
Last seen : 2011-11-22 23:28:29
TrID:
Win32 Executable Generic (58.4%)
Clipper DOS Executable (13.8%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.7%)
VXD Driver (0.2%)
sigcheck:
publisher….: GMER
copyright….: Copyright © GMER 2003-2009
product……: GMER
description..: GMER Driver http://www.gmer.net
original name: gmer.sys
internal name: gmer.sys
file version.: 1, 0, 15, 4918 built by: WinDDK
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x16005
timedatestamp….: 0x4E21F298 (Sat Jul 16 20:20:40 2011)
machinetype……: 0x14c (I386)

[[ 7 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x480, 0xEA2C, 0xEA80, 6.45, a0ffd8d7e67fda16d045b3b9c0142509
.rwtext, 0xEF00, 0x51, 0x80, 1.71, c00d6d7ba9be2d7a526fdd7311b1247f
.rdata, 0xEF80, 0x2FBC, 0x3000, 5.14, d5bbf44c1f811f2d9f8454ba69b8c008
.data, 0x11F80, 0x4044, 0x4080, 0.34, 74ff1bbfb8e0ed1825669d220a13bc03
INIT, 0x16000, 0xAA8, 0xB00, 5.43, 619c6618a9e220cb810a7c9a63a55a26
.rsrc, 0x16B00, 0x370, 0x380, 3.35, c0c6d76b43cfd61d2ad6fb7fc4b40a16
.reloc, 0x16E80, 0x1B1A, 0x1B80, 6.44, 278d1556f5baf102668f4df3707ad15b

[[ 2 import(s) ]]
ntoskrnl.exe: ExFreePoolWithTag, ExAllocatePool, ZwReadFile, ZwQueryInformationFile, ZwOpenFile, memcpy, KeQuerySystemTime, PsLookupProcessByProcessId, ObfDereferenceObject, ObReferenceObjectByHandle, KeDetachProcess, KeAttachProcess, MmIsAddressValid, memset, ZwSetInformationFile, RtlInitUnicodeString, ObOpenObjectByPointer, IofCompleteRequest, IoDeleteDevice, IoDeleteSymbolicLink, RtlUnicodeStringToAnsiString, PsTerminateSystemThread, PsCreateSystemThread, KeInitializeEvent, wcsstr, IoCreateSymbolicLink, IoCreateDevice, PsGetVersion, strrchr, KeGetCurrentThread, KeBugCheckEx, IoFreeIrp, _wcsnicmp, IoAllocateIrp, IoGetBaseFileSystemDeviceObject, ZwWriteFile, ZwCreateFile, strncmp, IoGetCurrentProcess, strncpy, _vsnprintf, PsGetCurrentProcessId, _snprintf, RtlTimeToTimeFields, ExSystemTimeToLocalTime, _stricmp, ZwQuerySystemInformation, _strnicmp, RtlCopyUnicodeString, ZwQueryValueKey, ZwOpenKey, ZwSetValueKey, _snwprintf, ZwClose, MmUnlockPages, MmProbeAndLockPages, IoAllocateMdl, ZwEnumerateKey, PsLookupThreadByThreadId, RtlAnsiStringToUnicodeString, RtlInitAnsiString, _strupr, _strlwr, KeDelayExecutionThread, RtlVolumeDeviceToDosName, ObfReferenceObject, IoGetDeviceObjectPointer, wcschr, wcsncmp, KeInsertQueueDpc, KeSetTargetProcessorDpc, KeInitializeDpc, KeNumberProcessors, MmMapLockedPagesSpecifyCache, KeServiceDescriptorTable, _wcsicmp, wcsrchr, strchr, strstr, wcsncpy, IoCreateNotificationEvent, ZwQuerySection, RtlInitString, ZwRequestWaitReplyPort, ZwConnectPort, MmMapLockedPages, MmGetSystemRoutineAddress, ObReferenceObjectByName, IoDriverObjectType, ZwDeleteFile, KeTickCount, NtClose, IofCallDriver, RtlCompareUnicodeString, IoBuildSynchronousFsdRequest, _alldiv, RtlEqualUnicodeString, ZwQueryDirectoryObject, ZwOpenDirectoryObject, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, IoGetDeviceInterfaces, KeBugCheck, KeSetEvent, KeWaitForSingleObject, IoFreeMdl, KeClearEvent, RtlUnwind
HAL.dll: KfLowerIrql, KeGetCurrentIrql, KfRaiseIrql
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 62976
CompanyName: GMER
EntryPoint: 0x16005
FileDescription: GMER Driver http://www.gmer.net
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 98 kB
FileSubtype: 7
FileType: Win32 EXE
FileVersion: 1, 0, 15, 4918 built by: WinDDK
FileVersionNumber: 1.0.15.4918
ImageVersion: 6.0
InitializedDataSize: 36736
InternalName: gmer.sys
LanguageCode: English (U.S.)
LegalCopyright: Copyright © GMER 2003-2009
LinkerVersion: 8.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 6.0
ObjectFileType: Driver
OriginalFilename: gmer.sys
PEType: PE32
ProductName: GMER
ProductVersion: 1, 0, 15, 4918
ProductVersionNumber: 1.0.15.4918
Subsystem: Native
SubsystemVersion: 5.1
TimeStamp: 2011:07:16 22:20:40+02:00
UninitializedDataSize: 0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI