This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot search on Google or Yahoo [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a problem with my friend's computer. Google website does not work from IE, Firefox nor Chrome but any other website works fine. I downloaded and executed HijackThis and the result log file is attached. I tried to remove any viruses using Malwarebytes and Microsoft Security Essentials but nothing. Could you please help?
I cannot open Google.com at all. Yahoo page does open but when searching it shows that "โ€ฆpage cannot be displayedโ€ฆ." error. Other website work correctly. Please help
:welcome:

Please do not start any new topics, just reply to this one using ADD REPLY

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]




Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
aswMBR aswMBR version 0.9.8.986 Copyrightยฉ 2011 AVAST Software Run date: 2011-11-29 09:21:04 โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ 09:21:04.472 OS Version: Windows 5.1.2600 Service Pack 3 09:21:04.472 Number of processors: 2 586 0x170A 09:21:04.472 ComputerName: SQ1-PC-053 UserName: sphanor 09:21:10.045 Initialize success 09:21:13.339 AVAST engine defs: 11112901 09:21:14.931 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 09:21:14.931 Disk 0 Vendor: ST325031 CC45 Size: 238418MB BusType: 3 09:21:14.931 Disk 0 MBR read successfully 09:21:14.931 Disk 0 MBR scan 09:21:14.962 Disk 0 Windows VISTA default MBR code 09:21:14.962 Disk 0 scanning sectors +488263545 09:21:15.087 Disk 0 scanning C:\WINDOWS\system32\drivers 09:21:27.592 Service scanning 09:21:27.748 Service ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys **LOCKED** 32 09:21:27.795 Service MpKsl91d718d6 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0597054F-9660-48D1-BE34-C37C550482B0}\MpKsl91d718d6.sys **LOCKED** 32 09:21:28.372 Modules scanning 09:21:38.910 Disk 0 trace - called modules: 09:21:38.926 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys >>UNKNOWN [0x8a2b0e69]<< 09:21:39.441 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8acbc6c8] 09:21:39.441 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8acba028] 09:21:39.894 AVAST engine scan C:\WINDOWS 09:21:57.003 AVAST engine scan C:\WINDOWS\system32 09:24:28.018 AVAST engine scan C:\WINDOWS\system32\drivers 09:24:53.151 AVAST engine scan C:\Documents and Settings\sphanor 09:30:39.554 AVAST engine scan C:\Documents and Settings\All Users 09:31:28.714 Scan finished successfully 09:33:46.509 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\sphanor\My Documents\MBR.dat" 09:33:46.509 The log file has been saved successfully to "C:\Documents and Settings\sphanor\My Documents\aswMBR.txt" ************************************************************* . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 9:36:01 on 2011-11-29 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2323 [GMT -5:00] . AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} AV: Trend Micro Internet Security *Disabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5} FW: Trend Micro Personal Firewall *Disabled* . ============== Running Processes =============== . C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ScanSoft\PaperPort\PPScheduler.exe C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\SearchProtocolHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.bing.com uSearch Bar = hxxp://www.bing.com/sphome.aspx mSearchAssistant = hxxp://www.bing.com/sphome.aspx BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll BHO: Javaโ„ข Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [PPScheduler] c:\program files\scansoft\paperport\PPScheduler.exe uRun: [Adobe Acrobat Synchronizer] "c:\program files\adobe\acrobat 9.0\acrobat\AdobeCollabSync.exe" uRun: [Google Update] "c:\documents and settings\sphanor\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe" mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe" mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe" mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRunOnce: [DBRMTray] c:\dell\dbrm\reminder\TrayApp.exe mPolicies-explorer: NoWelcomeScreen = 1 (0x1) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100 TCP: DhcpNameServer = 192.168.7.2 TCP: Interfaces\{3C9E4DA4-71FF-4660-8D88-FB5BFF04DFD4} : DhcpNameServer = 192.168.7.2 Notify: igfxcui - igfxdev.dll Notify: LMIinit - LMIinit.dll AppInit_DLLs: acaptuser32.dll SSODL: Miduclib - {8F7544C6-B2E9-45B6-B7F6-4A99B0D21A76} - c:\windows\system32\kerigexe.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648] R1 MpKsl91d718d6;MpKsl91d718d6;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0597054f-9660-48d1-be34-c37c550482b0}\MpKsl91d718d6.sys [2011-11-29 28752] R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-6-8 374152] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-1-11 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-6-17 47640] R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [2010-2-26 22016] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2010-7-2 50192] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2009-7-21 36368] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2010-2-26 57248] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2009-7-21 335376] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-2-26 1684736] S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [2010-2-26 28800] S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2010-2-26 17536] S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2010-7-2 488768] S3 tmproxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2010-7-2 648456] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-25 14336] S4 LMIRfsClientNP;LMIRfsClientNP; [x] . =============== Created Last 30 ================ . 2011-11-29 14:19:22 28752 โ€”-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0597054f-9660-48d1-be34-c37c550482b0}\MpKsl91d718d6.sys 2011-11-29 14:19:06 56200 โ€”-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0597054f-9660-48d1-be34-c37c550482b0}\offreg.dll 2011-11-29 14:18:56 6668624 โ€”-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0597054f-9660-48d1-be34-c37c550482b0}\mpengine.dll 2011-11-28 14:03:53 6668624 โ€”-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2011-11-25 22:56:40 222080 โ€”โ€”w- c:\windows\system32\MpSigStub.exe 2011-11-25 22:52:12 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Microsoft Security Client 2011-11-25 22:50:19 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\sphanor\application data\Malwarebytes 2011-11-25 22:30:03 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\all users\application data\Malwarebytes 2011-11-25 22:30:00 22216 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-25 22:30:00 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware 2011-11-02 22:26:00 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\sphanor\local settings\application data\Apple . ==================== Find3M ==================== . 2011-11-16 14:10:02 414368 โ€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-07 12:22:58 83360 โ€”-a-w- c:\windows\system32\LMIRfsClientNP.dll 2011-10-07 12:22:58 52096 โ€”-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2011-10-07 12:22:57 87424 โ€”-a-w- c:\windows\system32\LMIinit.dll 2011-10-07 12:22:57 30592 โ€”-a-w- c:\windows\system32\LMIport.dll . ============= FINISH: 9:36:13.58 ===============
Hi,

Lets do this

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Ken545 apparently it got fixed. Google page is now showing up and search in both Google and Yahoo are working.

Is there anything else I need to do?

I'm attaching the result of the ComboFix run.

Thanks a lot for your help
ComboFix 11-11-29.04 - administrator 11/29/2011 10:32:38.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2392 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Trend Micro Internet Security *Disabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *Disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\jabreu\My Documents\prf17B8.tmp
c:\documents and settings\jabreu\My Documents\prf35A.tmp
c:\documents and settings\jabreu\My Documents\prf35B.tmp
c:\documents and settings\jabreu\prf330.tmp
c:\documents and settings\jabreu\WINDOWS
c:\documents and settings\jabreu\WINDOWS\HPMProp.INI
c:\documents and settings\jabreu\WINDOWS\inifile.upd
c:\documents and settings\jabreu\WINDOWS\win.ctx
c:\documents and settings\jabreu\WINDOWS\win.ini
c:\documents and settings\jabreu_old\g2mdlhlpx.exe
c:\documents and settings\jabreu_old\ntuser.tmp
c:\documents and settings\jabreu_old\prf17D5.tmp
c:\documents and settings\jabreu_old\WINDOWS
c:\documents and settings\jabreu_old\WINDOWS\HPMProp.INI
c:\documents and settings\jabreu_old\WINDOWS\inifile.upd
c:\documents and settings\jabreu_old\WINDOWS\win.ctx
c:\documents and settings\jabreu_old\WINDOWS\win.ini
c:\documents and settings\khughes\com.fonality.hud.edition.lite.application.tmp
c:\documents and settings\khughes\g2mdlhlpx.exe
c:\documents and settings\khughes\WINDOWS
c:\documents and settings\khughes\WINDOWS\HPMProp.INI
c:\windows\CSC\d6
c:\windows\CSC\d6\00000015
c:\windows\CSC\d6\00000155
c:\windows\system32\dotovime.exe
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\drivers\etc\hosts1
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-29 )))))))))))))))))))))))))))))))
.
.
2011-11-29 14:19 . 2011-11-29 14:19 28752 โ€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0597054F-9660-48D1-BE34-C37C550482B0}\MpKsl91d718d6.sys
2011-11-29 14:19 . 2011-11-29 15:28 56200 โ€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0597054F-9660-48D1-BE34-C37C550482B0}\offreg.dll
2011-11-29 14:18 . 2011-10-07 01:48 6668624 โ€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0597054F-9660-48D1-BE34-C37C550482B0}\mpengine.dll
2011-11-28 14:03 . 2011-10-07 01:48 6668624 โ€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-25 22:56 . 2010-10-19 20:51 222080 โ€”โ€”w- c:\windows\system32\MpSigStub.exe
2011-11-25 22:52 . 2011-11-25 22:52 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Microsoft Security Client
2011-11-25 22:50 . 2011-11-25 22:50 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\sphanor\Application Data\Malwarebytes
2011-11-25 22:30 . 2011-11-25 22:30 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\administrator.BTE\Application Data\Malwarebytes
2011-11-25 22:30 . 2011-11-25 22:30 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-25 22:30 . 2011-11-25 22:30 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware
2011-11-25 22:30 . 2011-08-31 22:00 22216 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-25 22:26 . 2011-11-29 15:30 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\administrator.BTE\Tracing
2011-11-25 22:25 . 2011-11-25 22:25 โ€”โ€”โ€“ d-shโ€“w- c:\documents and settings\administrator.BTE\IECompatCache
2011-11-16 17:43 . 2011-11-16 17:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\rundreiner
2011-11-02 22:26 . 2011-11-02 22:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\sphanor\Local Settings\Application Data\Apple
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-16 14:10 . 2011-05-17 17:35 414368 โ€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-07 12:22 . 2011-06-17 14:18 52096 โ€”-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-10-07 12:22 . 2011-06-17 14:18 83360 โ€”-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-10-07 12:22 . 2011-06-17 14:18 30592 โ€”-a-w- c:\windows\system32\LMIport.dll
2011-10-07 12:22 . 2011-06-17 14:18 87424 โ€”-a-w- c:\windows\system32\LMIinit.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-18 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-18 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-18 150040]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-09-07 40376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-11 63048]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2006-05-05 36864]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2006-05-05 40960]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-25 13918208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="c:\dell\DBRM\Reminder\TrayApp.exe" [2009-10-18 7168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Miduclib"= {8F7544C6-B2E9-45B6-B7F6-4A99B0D21A76} - c:\windows\system32\kerigexe.dll [2009-03-21 827392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-10-07 12:22 87424 โ€”-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\acaptuser32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-2666\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-2718\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-2796\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-2883\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-2884\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-2996\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-2999\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-3002\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-3051\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-3094\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-3098\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1957994488-2111687655-839522115-500\Scripts\Logoff\0\0]
"Script"=logoff.cmd
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CANON DR5010C SVC]
2008-10-15 15:27 135168 โ€”-a-w- c:\windows\system32\DR5KSVC.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 โ€”-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DBRMTray]
2009-11-12 16:55 203776 โ€”-a-w- c:\dell\DBRM\Reminder\DbrmTrayicon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2009-08-07 11:29 186904 โ€”-a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-09-25 02:26 13918208 โ€”-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-09-25 02:26 86016 โ€”-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2009-02-05 03:26 128232 โ€”โ€”w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-08-14 13:08 18702336 โ€”-a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-27 00:37 149280 โ€”-a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
2008-04-14 12:00 143360 โ€”-a-w- c:\windows\system32\mobsync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
2009-08-12 23:37 1398024 โ€”-a-w- c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)
"RemoteAddresses"=
.
R1 MpKsl91d718d6;MpKsl91d718d6;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0597054F-9660-48D1-BE34-C37C550482B0}\MpKsl91d718d6.sys [11/29/2011 9:19 AM 28752]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [6/8/2011 12:04 PM 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [2/26/2010 7:38 PM 22016]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [7/2/2010 12:04 PM 50192]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [7/21/2009 6:32 PM 36368]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2/26/2010 9:25 PM 57248]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [7/21/2009 6:32 PM 335376]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2/26/2010 9:25 PM 1684736]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [2/26/2010 7:38 PM 28800]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2/26/2010 7:38 PM 17536]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [7/2/2010 12:04 PM 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [7/2/2010 12:04 PM 648456]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 11:16 AM 14336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-11-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-2111687655-839522115-3098Core.job
- c:\documents and settings\sphanor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-29 21:43]
.
2011-11-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-2111687655-839522115-3098UA.job
- c:\documents and settings\sphanor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-29 21:43]
.
2011-11-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.7.2
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-nwiz - c:\program files\NVIDIA Corporation\nView\nwiz.exe
AddRemove-NVIDIA nView Desktop Manager - c:\program files\NVIDIA Corporation\nView\nViewSetup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-29 10:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes โ€ฆ
.
scanning hidden autostart entries โ€ฆ
.
scanning hidden files โ€ฆ
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
[HKEY_USERS\S-1-5-21-1957994488-2111687655-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2f,6f,d2,d1,d8,e8,c1,46,86,2a,93,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2f,6f,d2,d1,d8,e8,c1,46,86,2a,93,\
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” DLLs Loaded Under Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
- - - - - - - > 'winlogon.exe'(1084)
c:\windows\system32\LMIinit.dll
.
Completion time: 2011-11-29 10:53:48
ComboFix-quarantined-files.txt 2011-11-29 15:53
.
Pre-Run: 206,979,014,656 bytes free
Post-Run: 207,907,127,296 bytes free
.
- - End Of File - - 0F43F0119431B2B09349396F4C504CE8
Hi,

Well, we have a saying around here that the absence of symptoms does not guarantee a clean system. I need to look over your Combofix log real close, in the meantime do this.

Just copy and paste the logs we ask for in lew of attaching them, its easier for us to analyze.


You have Two Anti Virus Programs running, more than one is overkill and can severely hamper system performance. You need to have just one, keep it updated and run regular scans.

You need to uninstall one of these, your call. If you payed for TrendMicro than thats the one I would keep
Microsoft Security Essentials
Trend Micro Internet Security




You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again

c:\windows\system32\kerigexe.dll < This file

If the site is busy you can try this one
http://virusscan.jotti.org/en




You have Malwarebytes installed
, open it, check for updates and run the Quick Scan and post the log



Rerun aswMBR just to scan and post a NEW LOG





OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Tried to upload to both sites the file kerigexe.dll but VirusTotal did'n say anything and jotti replied that the file was empty (0 bytes) even though in the windows folder it has 808Kb

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8242

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

11/29/2011 2:57:10 PM
mbam-log-2011-11-29 (14-57-10).txt

Scan type: Quick scan
Objects scanned: 393901
Time elapsed: 6 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

******************************************************
aswMBR version 0.9.8.986 Copyrightยฉ 2011 AVAST Software
Run date: 2011-11-29 15:00:26
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“
15:00:26.481 OS Version: Windows 5.1.2600 Service Pack 3
15:00:26.481 Number of processors: 2 586 0x170A
15:00:26.481 ComputerName: SQ1-PC-053 UserName:
15:00:28.231 Initialize success
15:00:33.184 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:00:33.184 Disk 0 Vendor: ST325031 CC45 Size: 238418MB BusType: 3
15:00:33.200 Disk 0 MBR read successfully
15:00:33.215 Disk 0 MBR scan
15:00:33.215 Disk 0 Windows VISTA default MBR code
15:00:33.215 Disk 0 scanning sectors +488263545
15:00:33.294 Disk 0 scanning C:\WINDOWS\system32\drivers
15:00:40.934 Service scanning
15:00:41.090 Service ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys **LOCKED** 32
15:00:41.168 Service MpKsla4227d17 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9980B518-1C69-4A40-BF13-17C04CFD6695}\MpKsla4227d17.sys **LOCKED** 32
15:00:41.762 Modules scanning
15:00:45.309 Disk 0 trace - called modules:
15:00:45.324 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys >>UNKNOWN [0x8ad51409]<<
15:00:45.324 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8acceab8]
15:00:45.340 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8ad29028]
15:00:45.340 Scan finished successfully
15:01:04.245 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\administrator.BTE\Desktop\MBR.dat"
15:01:04.245 The log file has been saved successfully to "C:\Documents and Settings\administrator.BTE\Desktop\aswMBR.txt"


OTL logfile created on: 11/29/2011 3:02:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\administrator.BTE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.20 Gb Available Physical Memory | 73.38% Memory free
4.84 Gb Paging File | 4.11 Gb Available in Paging File | 84.94% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.78 Gb Total Space | 193.71 Gb Free Space | 83.22% Space Free | Partition Type: NTFS

Computer Name: SQ1-PC-053 | User Name: administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\administrator.BTE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ()
MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.FRA ()
MOD - C:\WINDOWS\system32\BiImg.dll ()


========== Win32 Services (SafeList) ==========

SRV - (LMIMaint) โ€“ C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) โ€“ C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (MsMpSvc) โ€“ c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) โ€“ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (LogMeIn) โ€“ C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (tmproxy) โ€“ C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (TmPfw) โ€“ C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (SfCtlCom) โ€“ C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (IAANTMON) Intelยฎ โ€“ C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (TMBMServer) โ€“ C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKsla4227d17) โ€“ c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9980B518-1C69-4A40-BF13-17C04CFD6695}\MpKsla4227d17.sys (Microsoft Corporation)
DRV - (LMIRfsClientNP) โ€“ C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) โ€“ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) โ€“ C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (tmxpflt) โ€“ C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) โ€“ C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) โ€“ C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (NVHDA) โ€“ C:\WINDOWS\system32\drivers\nvhda32.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) โ€“ C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (tmcomm) โ€“ C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmactmon) โ€“ C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) โ€“ C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmcfw) โ€“ C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) โ€“ C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (RTLE8023xp) โ€“ C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (RTLVLAN) โ€“ C:\WINDOWS\system32\drivers\RTLVLAN.SYS (Realtek Semiconductor Corporation )
DRV - (RTLTEAMING) โ€“ C:\WINDOWS\system32\drivers\RTLTEAMING.SYS (Realtek Semiconductor Corporation)
DRV - (Ambfilt) โ€“ C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (RtNdPt5x) โ€“ C:\WINDOWS\system32\drivers\RtNdPt5x.sys (Realtek Semiconductor Corporation )
DRV - (ACPI) โ€“ C:\WINDOWS\system32\DRIVERS\ACPI.sys ()
DRV - (Monfilt) โ€“ C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USSMB/1


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USSMB/1
IE - HKU\S-1-5-21-1957994488-2111687655-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



O1 HOSTS File: ([2011/11/29 10:43:23 | 000,000,027 | โ€”- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\RunOnce: [DBRMTray] C:\dell\DBRM\Reminder\TrayApp.exe (Microsoft)
O4 - Startup: C:\Documents and Settings\khughes\Start Menu\Programs\Startup\Fonality HUD.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.7.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = BTE.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C9E4DA4-71FF-4660-8D88-FB5BFF04DFD4}: DhcpNameServer = 192.168.7.2
O20 - AppInit_DLLs: (C:\WINDOWS\system32\acaptuser32.dll) -C:\WINDOWS\system32\acaptuser32.dll (Adobe Systems Incorporated)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O21 - SSODL: Miduclib - {8F7544C6-B2E9-45B6-B7F6-4A99B0D21A76} - C:\WINDOWS\system32\kerigexe.dll File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 16:29:32 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = ComFile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found โ€“ C:\WINDOWS\System32\urlonlib.dll
File not found โ€“ C:\WINDOWS\System32\maculext.dll
File not found โ€“ C:\WINDOWS\System32\kerigexe.dll
File not found โ€“ C:\WINDOWS\System32\bmpuvzip.dll
File not found โ€“ C:\WINDOWS\System32\anselbio.dll
File not found โ€“ C:\WINDOWS\System32\adipdir32.dll
[2011/11/29 15:00:13 | 000,584,192 | โ€”- | C] (OldTimer Tools) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\OTL.exe
[2011/11/29 14:59:36 | 001,916,416 | โ€”- | C] (AVAST Software) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\aswMBR.exe
[2011/11/29 14:59:36 | 000,607,260 | Rโ€” | C] (Swearware) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\dds.scr
[2011/11/29 11:15:15 | 000,000,000 | -HSD | C] โ€“ C:\RECYCLER
[2011/11/29 10:31:24 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\administrator.BTE\Start Menu\Programs\Administrative Tools
[2011/11/29 10:30:47 | 004,321,290 | Rโ€” | C] (Swearware) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\ComboFix.exe
[2011/11/29 10:28:45 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\Minidump
[2011/11/29 10:23:22 | 000,000,000 | RHSD | C] โ€“ C:\cmdcons
[2011/11/29 10:20:38 | 000,518,144 | โ€”- | C] (SteelWerX) โ€“ C:\WINDOWS\SWREG.exe
[2011/11/29 10:20:38 | 000,406,528 | โ€”- | C] (SteelWerX) โ€“ C:\WINDOWS\SWSC.exe
[2011/11/29 10:20:38 | 000,212,480 | โ€”- | C] (SteelWerX) โ€“ C:\WINDOWS\SWXCACLS.exe
[2011/11/29 10:20:38 | 000,060,416 | โ€”- | C] (NirSoft) โ€“ C:\WINDOWS\NIRCMD.exe
[2011/11/29 10:20:31 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\ERDNT
[2011/11/29 10:20:00 | 000,000,000 | โ€”D | C] โ€“ C:\Qoobox
[2011/11/25 17:56:40 | 000,222,080 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\MpSigStub.exe
[2011/11/25 17:52:12 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Microsoft Security Client
[2011/11/25 17:30:06 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\administrator.BTE\Application Data\Malwarebytes
[2011/11/25 17:30:03 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/25 17:30:03 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/11/25 17:30:00 | 000,022,216 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/25 17:30:00 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/25 17:29:47 | 009,852,544 | โ€”- | C] (Malwarebytes Corporation ) โ€“ C:\Documents and Settings\administrator.BTE\My Documents\mbam-setup-1.51.2.1300.exe
[2011/11/25 17:26:52 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\administrator.BTE\Tracing
[2011/11/25 17:25:02 | 000,000,000 | -HSD | C] โ€“ C:\Documents and Settings\administrator.BTE\IECompatCache
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found โ€“ C:\WINDOWS\System32\urlonlib.dll
File not found โ€“ C:\WINDOWS\System32\maculext.dll
File not found โ€“ C:\WINDOWS\System32\kerigexe.dll
File not found โ€“ C:\WINDOWS\System32\bmpuvzip.dll
File not found โ€“ C:\WINDOWS\System32\anselbio.dll
File not found โ€“ C:\WINDOWS\System32\adipdir32.dll
[2011/11/29 15:01:04 | 000,000,512 | โ€”- | M] () โ€“ C:\Documents and Settings\administrator.BTE\Desktop\MBR.dat
[2011/11/29 15:00:15 | 000,584,192 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\OTL.exe
[2011/11/29 14:53:00 | 000,000,986 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-2111687655-839522115-3098UA.job
[2011/11/29 14:51:29 | 000,000,424 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/29 14:47:12 | 000,253,708 | โ€”- | M] () โ€“ C:\WINDOWS\System32\NvApps.xml
[2011/11/29 14:47:06 | 000,001,158 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2011/11/29 14:46:26 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2011/11/29 14:46:22 | 3220,160,512 | -HS- | M] () โ€“ C:\hiberfil.sys
[2011/11/29 14:45:00 | 000,000,327 | RHS- | M] () โ€“ C:\boot.ini
[2011/11/29 14:28:01 | 000,000,036 | โ€”- | M] () โ€“ C:\WINDOWS\iltwain.ini
[2011/11/29 10:43:23 | 000,000,027 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/29 10:13:42 | 004,321,290 | Rโ€” | M] (Swearware) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\ComboFix.exe
[2011/11/29 08:56:45 | 001,916,416 | โ€”- | M] (AVAST Software) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\aswMBR.exe
[2011/11/28 16:06:54 | 000,013,334 | โ€”- | M] () โ€“ C:\WINDOWS\setscan.ini
[2011/11/28 16:04:24 | 000,000,211 | โ€”- | M] () โ€“ C:\Boot.bak
[2011/11/28 15:27:35 | 000,607,260 | Rโ€” | M] (Swearware) โ€“ C:\Documents and Settings\administrator.BTE\Desktop\dds.scr
[2011/11/25 17:52:28 | 000,001,945 | โ€”- | M] () โ€“ C:\WINDOWS\epplauncher.mif
[2011/11/25 17:30:04 | 000,000,786 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/25 17:29:51 | 009,852,544 | โ€”- | M] (Malwarebytes Corporation ) โ€“ C:\Documents and Settings\administrator.BTE\My Documents\mbam-setup-1.51.2.1300.exe
[2011/11/25 05:53:00 | 000,000,934 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-2111687655-839522115-3098Core.job
[2011/11/23 18:26:00 | 000,000,284 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/22 11:25:03 | 000,466,796 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2011/11/22 11:25:03 | 000,079,886 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2011/11/16 09:10:02 | 000,414,368 | โ€”- | M] (Adobe Systems Incorporated) โ€“ C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/29 15:01:04 | 000,000,512 | โ€”- | C] () โ€“ C:\Documents and Settings\administrator.BTE\Desktop\MBR.dat
[2011/11/29 10:23:25 | 000,000,211 | โ€”- | C] () โ€“ C:\Boot.bak
[2011/11/29 10:23:23 | 000,260,272 | RHS- | C] () โ€“ C:\cmldr
[2011/11/29 10:20:38 | 000,256,000 | โ€”- | C] () โ€“ C:\WINDOWS\PEV.exe
[2011/11/29 10:20:38 | 000,208,896 | โ€”- | C] () โ€“ C:\WINDOWS\MBR.exe
[2011/11/29 10:20:38 | 000,098,816 | โ€”- | C] () โ€“ C:\WINDOWS\sed.exe
[2011/11/29 10:20:38 | 000,080,412 | โ€”- | C] () โ€“ C:\WINDOWS\grep.exe
[2011/11/29 10:20:38 | 000,068,096 | โ€”- | C] () โ€“ C:\WINDOWS\zip.exe
[2011/11/28 16:00:53 | 3220,160,512 | -HS- | C] () โ€“ C:\hiberfil.sys
[2011/11/25 17:57:24 | 000,000,424 | -Hโ€“ | C] () โ€“ C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/25 17:52:28 | 000,001,945 | โ€”- | C] () โ€“ C:\WINDOWS\epplauncher.mif
[2011/11/25 17:52:17 | 000,001,682 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/25 17:30:04 | 000,000,786 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/01 13:12:16 | 000,167,072 | โ€”- | C] () โ€“ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/06/17 16:21:15 | 000,000,033 | โ€”- | C] () โ€“ C:\WINDOWS\BiMonitor.ini
[2011/06/17 16:21:14 | 000,030,846 | โ€”- | C] () โ€“ C:\WINDOWS\maxlink.ini
[2011/06/17 16:14:38 | 000,013,334 | โ€”- | C] () โ€“ C:\WINDOWS\setscan.ini
[2011/04/11 10:32:58 | 000,000,056 | โ€”- | C] () โ€“ C:\WINDOWS\Addrfixr.ini
[2011/04/11 10:32:58 | 000,000,036 | โ€”- | C] () โ€“ C:\WINDOWS\iltwain.ini
[2011/04/11 10:32:57 | 000,009,391 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dymourl.ini
[2011/04/11 10:32:34 | 000,061,440 | โ€”- | C] () โ€“ C:\WINDOWS\System32\DYMOCFG.DLL
[2011/04/11 10:32:33 | 000,004,096 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lmmonres.dll
[2011/01/28 08:06:49 | 000,119,808 | โ€”- | C] () โ€“ C:\WINDOWS\System32\cfgagmap.dll
[2011/01/11 17:05:18 | 000,008,592 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ractrlkeyhook.dll
[2010/08/24 09:40:34 | 000,123,135 | โ€”- | C] () โ€“ C:\WINDOWS\HPHins12.dat.temp
[2010/08/24 09:40:34 | 000,014,916 | โ€”- | C] () โ€“ C:\WINDOWS\hphmdl12.dat.temp
[2010/08/24 09:37:01 | 000,122,810 | โ€”- | C] () โ€“ C:\WINDOWS\HPHins12.dat
[2010/08/24 09:37:01 | 000,014,916 | โ€”- | C] () โ€“ C:\WINDOWS\hphmdl12.dat
[2010/08/24 09:36:57 | 000,077,824 | โ€”- | C] () โ€“ C:\WINDOWS\System32\hpzids01.dll
[2010/02/26 21:25:56 | 001,604,482 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvdata.bin
[2010/02/26 21:25:41 | 000,073,728 | โ€”- | C] () โ€“ C:\WINDOWS\System32\RtNicProp32.dll
[2010/02/26 21:25:39 | 002,026,604 | โ€”- | C] () โ€“ C:\WINDOWS\System32\igkrng500.bin
[2010/02/26 21:25:39 | 000,442,964 | โ€”- | C] () โ€“ C:\WINDOWS\System32\igcompkrng500.bin
[2010/02/26 21:25:39 | 000,147,456 | โ€”- | C] () โ€“ C:\WINDOWS\System32\igfxCoIn_v4977.dll
[2010/02/26 21:25:31 | 000,077,824 | โ€”- | C] () โ€“ C:\WINDOWS\setpwr32.exe
[2010/02/26 21:19:19 | 000,001,152 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OEMINFO.INI
[2010/02/26 19:43:39 | 000,000,061 | โ€”- | C] () โ€“ C:\WINDOWS\smscfg.ini
[2008/05/26 22:59:42 | 000,018,904 | โ€”- | C] () โ€“ C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | โ€”- | C] () โ€“ C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/25 16:31:41 | 000,002,048 | โ€“S- | C] () โ€“ C:\WINDOWS\bootstat.dat
[2008/04/25 16:27:18 | 000,021,640 | โ€”- | C] () โ€“ C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 16:26:32 | 000,001,793 | โ€”- | C] () โ€“ C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 11:16:24 | 000,004,569 | โ€”- | C] () โ€“ C:\WINDOWS\System32\secupd.dat
[2008/04/25 11:16:22 | 000,466,796 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2008/04/25 11:16:22 | 000,272,128 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfi009.dat
[2008/04/25 11:16:22 | 000,079,886 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2008/04/25 11:16:22 | 000,028,626 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfd009.dat
[2008/04/25 11:16:22 | 000,004,627 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.dat
[2008/04/25 11:16:21 | 013,107,200 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.bin
[2008/04/25 11:16:20 | 000,000,741 | โ€”- | C] () โ€“ C:\WINDOWS\System32\noise.dat
[2008/04/25 11:16:18 | 000,673,088 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mlang.dat
[2008/04/25 11:16:18 | 000,046,258 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mib.bin
[2008/04/25 11:16:13 | 000,218,003 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dssec.dat
[2008/04/25 11:16:11 | 000,001,804 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Dcache.bin
[2008/04/25 04:22:39 | 000,004,161 | โ€”- | C] () โ€“ C:\WINDOWS\ODBCINST.INI
[2008/04/25 04:21:52 | 000,278,152 | โ€”- | C] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/13 19:06:36 | 000,187,776 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\acpi.sys
[2007/09/27 11:51:02 | 000,020,698 | โ€”- | C] () โ€“ C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | โ€”- | C] () โ€“ C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | โ€”- | C] () โ€“ C:\WINDOWS\System32\gthrctr.ini
[2005/09/07 11:00:44 | 000,257,536 | โ€”- | C] () โ€“ C:\WINDOWS\System32\BiImg.dll
[2005/09/07 11:00:44 | 000,110,592 | โ€”- | C] () โ€“ C:\WINDOWS\System32\JPEG32.DLL

========== LOP Check ==========

[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\aacosta\Application Data\Windows Desktop Search
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\administrator.BTE\Application Data\Windows Desktop Search
[2011/04/08 09:49:08 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\administrator.BTE\Application Data\Windows Search
[2011/11/29 09:08:08 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/06/20 10:59:59 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/08/01 11:58:58 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Winprint HylaFAX Reloaded
[2011/06/17 16:22:11 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\zeon
[2009/08/21 16:35:17 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\cvasquez\Application Data\ICCO
[2010/04/09 08:04:18 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\cvasquez\Application Data\Windows Desktop Search
[2010/04/08 15:50:49 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\cvasquez\Application Data\Windows Search
[2010/09/17 13:39:42 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\ddezmal\Application Data\Downloaded Installations
[2010/06/08 15:25:40 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\ddezmal\Application Data\ICCO
[2011/04/06 14:27:50 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\ddezmal\Application Data\Nitro PDF
[2010/03/26 00:11:17 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\ddezmal\Application Data\Windows Desktop Search
[2010/08/10 11:25:16 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\ddezmal\Application Data\Windows Search
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Default User\Application Data\Windows Desktop Search
[2010/04/07 10:28:07 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jabreu\Application Data\ICCO
[2010/06/29 13:41:19 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jabreu\Application Data\Windows Desktop Search
[2010/06/30 10:41:46 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jabreu\Application Data\Windows Search
[2010/04/07 10:28:07 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jabreu_old\Application Data\ICCO
[2010/06/29 13:41:19 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jabreu_old\Application Data\Windows Desktop Search
[2010/06/30 10:41:46 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jabreu_old\Application Data\Windows Search
[2011/04/04 08:26:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jlattimore\Application Data\ICCO
[2011/04/04 12:20:08 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jlattimore\Application Data\ISIS Drivers
[2011/07/28 12:09:06 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jlattimore\Application Data\Nitro PDF
[2011/04/04 12:19:48 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jlattimore\Application Data\ScanSoft
[2011/07/21 07:44:35 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\jlattimore\Application Data\Windows Search
[2010/12/14 16:21:38 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\keithh\Application Data\ICCO
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\keithh\Application Data\Windows Desktop Search
[2010/12/16 09:14:37 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\keithh\Application Data\Windows Search
[2010/04/07 11:19:31 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\khughes\Application Data\ICCO
[2010/04/07 11:27:06 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\khughes\Application Data\Windows Search
[2010/04/13 08:41:41 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\mlehrer\Application Data\ICCO
[2010/04/14 08:03:10 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\mlehrer\Application Data\Windows Desktop Search
[2010/04/13 09:43:25 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\mlehrer\Application Data\Windows Search
[2010/06/07 14:50:11 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\rschwartz\Application Data\ICCO
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\rschwartz\Application Data\Windows Desktop Search
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\rundreiner\Application Data\Windows Desktop Search
[2011/04/08 16:54:03 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\sphanor\Application Data\ICCO
[2011/06/20 08:36:32 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\sphanor\Application Data\ScanSoft
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\sphanor\Application Data\Windows Desktop Search
[2011/04/11 11:20:55 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\sphanor\Application Data\Windows Search
[2011/08/01 11:58:35 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\sphanor\Application Data\Winprint HylaFAX Reloaded
[2011/06/17 16:22:48 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\sphanor\Application Data\Zeon
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Square One\Application Data\Windows Desktop Search
[2010/03/25 09:41:27 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Square One\Application Data\Windows Search
[2010/03/25 10:20:26 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\vpiscitelli\Application Data\ICCO
[2010/02/26 19:37:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\vpiscitelli\Application Data\Windows Desktop Search
[2010/03/31 16:19:43 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\vpiscitelli\Application Data\Windows Search
[2011/11/29 14:51:29 | 000,000,424 | -Hโ€“ | M] () โ€“ C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



< End of report >


OTL Extras logfile created on: 11/29/2011 3:02:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\administrator.BTE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.20 Gb Available Physical Memory | 73.38% Memory free
4.84 Gb Paging File | 4.11 Gb Available in Paging File | 84.94% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.78 Gb Total Space | 193.71 Gb Free Space | 83.22% Space Free | Partition Type: NTFS

Computer Name: SQ1-PC-053 | User Name: administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ€“ rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
cplfile [cplopen] โ€“ rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] โ€“ "%1" %*
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ€“ %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = LocalSubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = *

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console โ€“ (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02E73E50-6513-4802-8600-B5A5BA185BE3}" = ScanSoft PaperPort 11
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Javaโ„ข 6 Update 17
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57E936AA-62B9-41F6-BFEB-CC53D45A0E07}" = CreditSoft 8
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7236672F-6430-439E-9B27-27EDEAF1D676}" = Realtek Ethernet Diagnostic Utility
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{803259ED-7A67-4CB5-B6D7-281ED371091B}" = LogMeIn
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intelยฎ Matrix Storage Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9D59AC32-B0FA-4CD7-A2EC-4B57C06CD9D9}" = Dell Backup and Recovery Manager
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4065943-D898-4BE6-BFA4-6A5299675F93}" = Canon DR-4010C Driver
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro Internet Security
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Franรงais, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}_946" = Adobe Acrobat 9.4.6 - CPSID_83708
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Franรงais, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AD1D8B40-F83C-41CA-BA08-9DB8D1653316}" = ScanSoft PDF Create! 3.0
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{B34F6EB6-46EF-461A-981A-A19A22897BFF}" = DR-4010C UserManual
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1AE6D4D-C37A-487d-83D8-C333125B2459}" = HP Photosmart and Deskjet 7.0 Software
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F64330DD-1138-4CB4-BF45-87F9168933F6}_is1" = Winprint HylaFAX Reloaded 0.3.1
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DYMO Label Software" = DYMO Label Software
"HDMI" = Intelยฎ Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{57E936AA-62B9-41F6-BFEB-CC53D45A0E07}" = CreditSoft 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"NVIDIA Drivers" = NVIDIA Drivers
"PROPLUS" = Microsoft Office Professional Plus 2007
"Spark 2.5.8" = Spark 2.5.8
"WinLiveSuite_Wave3" = Windows Live Essentials
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/29/2011 11:26:22 AM | Computer Name = SQ1-PC-053 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 11/29/2011 11:31:12 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry MUSIC.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)


Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry PICTURES.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)


Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/29/2011 11:36:36 AM | Computer Name = SQ1-PC-053 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 11/29/2011 12:09:45 PM | Computer Name = SQ1-PC-053 | Source = MsiInstaller | ID = 10005
Description = Product: 32 Bit HP BiDi Channel Components Installer โ€“ The installer
has encountered an unexpected error installing this package. This may indicate
a problem with this package. The error code is 2753. The arguments are: ipm12.CF34E983_546C_421F_A494_3C30281E4CF3,
,

Error - 11/29/2011 1:41:45 PM | Computer Name = SQ1-PC-053 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 3.0.8402.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 11/29/2011 2:24:46 PM | Computer Name = SQ1-PC-053 | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 1.1.7801.0, P3 1.115.2798.0, P4 1.115.2798.0, P5 exploit_win32_cpllnk.a, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

[ OSession Events ]
Error - 7/22/2010 1:33:37 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 365
seconds with 0 seconds of active time. This session ended with a crash.

Error - 4/27/2011 2:21:48 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6548.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 20457
seconds with 2100 seconds of active time. This session ended with a crash.

Error - 6/9/2011 2:45:37 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6548.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8087
seconds with 720 seconds of active time. This session ended with a crash.

Error - 8/1/2011 4:51:56 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.

Error - 8/31/2011 9:37:53 AM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 580
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/4/2011 6:57:52 PM | Computer Name = SQ1-PC-053 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 10/6/2011 6:57:22 PM | Computer Name = SQ1-PC-053 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 11/22/2011 12:01:26 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10010
Description = The server {000209FF-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 11/22/2011 12:04:19 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10010
Description = The server {000209FF-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 11/22/2011 12:04:49 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10010
Description = The server {000209FF-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 11/25/2011 6:49:28 PM | Computer Name = SQ1-PC-053 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.

Error - 11/28/2011 4:55:03 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 11/28/2011 4:56:01 PM | Computer Name = SQ1-PC-053 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm MpFilter tmtdi

Error - 11/28/2011 5:00:16 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 11/29/2011 11:30:18 AM | Computer Name = SQ1-PC-053 | Source = System Error | ID = 1003
Description = Error code 000000ca, parameter1 00000004, parameter2 876391b8, parameter3
00000000, parameter4 00000000.


< End of report >
Hi,

Things are looking pretty good.

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <โ€“Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces





ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
All processes killed
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\administrator.BTE\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\administrator.BTE\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: aacosta
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 321 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 321 bytes

User: administrator.BTE
->Temp folder emptied: 3548 bytes
->Temporary Internet Files folder emptied: 8624384 bytes
->Flash cache emptied: 615 bytes

User: All Users

User: cvasquez
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 51400443 bytes
->Java cache emptied: 22796894 bytes
->Flash cache emptied: 1089 bytes

User: ddezmal
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 10680993 bytes
->Flash cache emptied: 46367 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 321 bytes

User: jabreu
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1036270 bytes
->Java cache emptied: 7140 bytes
->Flash cache emptied: 1649 bytes

User: jabreu_old
->Temp folder emptied: 755954 bytes
->Temporary Internet Files folder emptied: 76015 bytes
->Java cache emptied: 10680337 bytes
->Flash cache emptied: 11201 bytes

User: jlattimore
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 2338 bytes

User: keithh
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 17007865 bytes
->Flash cache emptied: 37047 bytes

User: khughes
->Temp folder emptied: 65536 bytes
->Temporary Internet Files folder emptied: 1091 bytes
->Java cache emptied: 34923055 bytes
->Flash cache emptied: 1125 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: mlehrer
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 46012608 bytes
->Java cache emptied: 24237387 bytes
->Flash cache emptied: 1537 bytes

User: NetworkService
->Temp folder emptied: 5018 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: rschwartz
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 10680297 bytes
->Flash cache emptied: 321 bytes

User: rundreiner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 321 bytes

User: sphanor
->Temp folder emptied: 3360758 bytes
->Temporary Internet Files folder emptied: 882532255 bytes
->Java cache emptied: 1697245 bytes
->Google Chrome cache emptied: 217505835 bytes
->Flash cache emptied: 17187 bytes

User: Square One
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 294871 bytes
->Flash cache emptied: 321 bytes

User: vpiscitelli
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 15125813 bytes
->Java cache emptied: 12118713 bytes
->Flash cache emptied: 17024 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 22733 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,308.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 11292011_165616

Files\Folders moved on Rebootโ€ฆ
File move failed. C:\Documents and Settings\khughes\Local Settings\Temp\hsperfdata_khughes\524 scheduled to be moved on reboot.

Registry entries deleted on Rebootโ€ฆ





NO THREATS FOUND from ESET



THANK YOU!!!
Problem solved. Thanks a lot. I have been looking all over the internet to find a solution to this problem and nothing worked until I found you guys. Very helpful, with quick replies and even when the problem seem to be solved, you made me go and double-check just to make sure the malware has been completely removed and the problem has been solved. You are very dedicated geniuses. Thanks again R@ul
Your very welcome, glad we could help




Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups


  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • WhattheTech
  • GeeksTo Go
  • Dslreports


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI