This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

tdss and google redirect please help!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hijack this log pasted here:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:37:26 AM, on 12/5/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\2X\Client\TUXCredProv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\ATT-SST\McciTrayApp.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\2X\Client\APPServerClient.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*
R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Ad-Aware Security Toolbar - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111115100022.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: SoyDominicano.NET Toolbar - {5bdea838-df85-40de-85c0-af50e1024f0d} - C:\Program Files\SoyDominicano.NET\prxtbSoy0.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Ad-Aware Security Toolbar - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll
O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe"
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SpeetItUpFree] "C:\Program Files\SpeedItup Free\speeditupfree.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.894
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: 2X Client.lnk = C:\Program Files\2X\Client\APPServerClient.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files\Savevid\redirect.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1236398655031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1237315749827
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O20 - AppInit_DLLs: C:\PROGRA~1\WI0498~1\Datamngr\datamngr.dll C:\PROGRA~1\WI0498~1\Datamngr\IEBHO.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: 2X SSO Service - 2X Software Ltd. - C:\Program Files\2X\Client\\TUXCredProv.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: Google Update Service (gupdate1c99ee7e995cd34) (gupdate1c99ee7e995cd34) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe
O23 - Service: Toolbar Updater Service - Unknown owner - C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 16260 bytes


thank you very much for reading this and trying to respond to it. I appreciate you so much!

astooks2
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hello! Thank you so much for responding to my plea for help. I dowloaded combofix as you said, and disabled my anti-spyware, etc. Then I tried to run it. It did great for a while, and said that it found something called zeroaccess rootkit? Then after about an hour, I discovered that my computer had frozen. I tried again early this morning and it froze again. it didn't give me a log to post….. so I need help again! Again, thanks…. Ann
This is a very nasty infection and it is possible that we will not be able to clean it,we will try though before reformat is necessary.

See if you can find the log from Combofix,it would be at C:/Combofix.txt.

Delete the Tdsskiller you have,download a fresh one and follow the instructions below,if it still will not run,try ti run it in safe mode.


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Hello again!

I'm surprised that I am able to reply to this from my home computer, as the last time i tried to get here i was redirected elsewhere, quite firmly, by this virus or whatever.
So here's what's going on…I did delete tdsskiller and re-installed it. It still would not run. I re-named it. I re-booted into safe mode and tried it. same result. It still would not run. :angry:
I then tried combofix again. My computer froze after 10 minutes. I re-booted into safe mode and tried it again. Same result. *sigh*

I did try to find the combofix logfile for you, but the virus has changed either its location or its icon, and kept directing me to "my documents". I am sorry.

I wasn't sure what else to try to do, and so i just ran another hijack this log, hoping that would be helpful, and I am going to paste it below:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:43:34 AM, on 12/7/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\2X\Client\TUXCredProv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\ATT-SST\McciTrayApp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\2X\Client\APPServerClient.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*
R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Ad-Aware Security Toolbar - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111115100022.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: SoyDominicano.NET Toolbar - {5bdea838-df85-40de-85c0-af50e1024f0d} - C:\Program Files\SoyDominicano.NET\prxtbSoy0.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: Ad-Aware Security Toolbar - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll
O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe"
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SpeetItUpFree] "C:\Program Files\SpeedItup Free\speeditupfree.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.894
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Privacy Protection] C:\Documents and Settings\All Users\Application Data\privacy.exe
O4 - Startup: 2X Client.lnk = C:\Program Files\2X\Client\APPServerClient.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files\Savevid\redirect.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1236398655031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1237315749827
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: 2X SSO Service - 2X Software Ltd. - C:\Program Files\2X\Client\\TUXCredProv.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: Google Update Service (gupdate1c99ee7e995cd34) (gupdate1c99ee7e995cd34) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe
O23 - Service: Toolbar Updater Service - Unknown owner - C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 15911 bytes

Again, thank you so much for your patience and for trying to help me. I am feeling more desperate by the minute, and i appreciate you so much!

Ann
If we can't get TDSSKiller or Combofix to run I don't know of any other way to clean this infection,try to run Combofix as below.

Delete the copy you have now and download a fresh one from the links below,rename it to svchost.exe and save it directly to your C drive,then try to run it from there.

Leave it to run for a good hour or so if needed.


Link 1
Link 2
Hello again! :wavey: I don't know what happened, but I wanted to let you know that I was able to both install and run last night, on my computer, BOTH TDSSKiller and combofix. When I get home today I will try to find the appropriate logs and post them here for you. *whew!* Ann
Hello again! :notworthy:
I am happy to report that I have found both the logs form combofix and tdsskiller, and I am going to post them below for your perusal. and have I said Thank you very much yet? Well, Thanks! :thumbup:

ComboFix 11-12-08.01 - Owner 12/08/2011 22:57:30.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3574.3057 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Desktop\Privacy Protection.lnk
c:\documents and settings\Owner\WINDOWS
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_Toolbar_Updater_Service
——-\Service_Toolbar Updater Service
.
.
((((((((((((((((((((((((( Files Created from 2011-11-09 to 2011-12-09 )))))))))))))))))))))))))))))))
.
.
2011-12-09 04:33 . 2011-12-09 04:33 4984 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2011-12-09 04:30 . 2011-12-09 04:31 51852 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2011-12-09 04:29 . 2011-12-09 04:30 20719 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2011-12-09 04:28 . 2011-12-09 04:29 23327 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2011-12-09 04:28 . 2011-12-09 04:28 7271 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2011-12-09 04:28 . 2011-12-09 04:28 8782 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2011-12-09 04:28 . 2011-12-09 04:28 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-12-04 19:49 . 2011-12-04 19:49 ——– d—–w- c:\documents and settings\Owner\Application Data\PCTools
2011-12-04 13:06 . 2011-12-04 13:06 ——– d—–w- c:\program files\File Type Assistant
2011-12-04 13:06 . 2011-12-04 13:06 ——– d—–w- c:\documents and settings\Owner\Application Data\BitZipper
2011-12-04 13:06 . 2011-12-04 13:06 ——– d—–w- c:\program files\BitZipper
2011-12-03 22:03 . 2011-11-22 23:20 574424 –s—w- c:\windows\system32\drivers\TfSysMon.sys
2011-12-03 22:03 . 2011-11-22 23:20 35264 –s—w- c:\windows\system32\drivers\TfNetMon.sys
2011-12-03 22:03 . 2011-11-22 23:20 54328 –s—w- c:\windows\system32\drivers\TfFsMon.sys
2011-12-03 21:48 . 2011-12-03 21:48 ——– d—–w- c:\documents and settings\NetworkService\Application Data\adawaretb
2011-12-03 08:05 . 2011-09-28 18:14 56840 —-a-w- c:\windows\system32\drivers\PCTBD.sys
2011-12-03 06:29 . 2011-11-23 00:42 185560 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2011-12-03 06:27 . 2011-12-03 22:03 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2011-12-03 06:27 . 2011-12-03 06:27 ——– d—–w- c:\documents and settings\Owner\Application Data\TestApp
2011-12-03 06:16 . 2011-12-03 06:16 ——– d—–w- c:\program files\7-Zip
2011-12-02 05:18 . 2011-12-02 04:56 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-12-02 04:34 . 2011-12-02 04:35 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\adaware
2011-12-02 04:34 . 2011-12-09 03:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Ad-Aware Browsing Protection
2011-12-02 04:34 . 2011-12-02 04:34 ——– d—–w- c:\program files\Toolbar Cleaner
2011-12-02 04:33 . 2011-12-03 03:45 ——– d—–w- c:\documents and settings\Owner\Application Data\adawaretb
2011-12-02 04:33 . 2011-12-02 04:34 ——– d—–w- c:\program files\adawaretb
2011-12-02 04:33 . 2011-11-03 17:06 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-12-02 04:32 . 2011-12-02 04:32 ——– d—–w- c:\program files\Lavasoft
2011-12-01 22:53 . 2011-12-04 01:31 ——– d—–w- C:\sh4ldr
2011-12-01 22:53 . 2011-12-01 22:53 ——– d—–w- c:\program files\Enigma Software Group
2011-12-01 22:53 . 2011-12-04 01:31 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-12-01 22:53 . 2011-12-01 22:53 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2011-11-25 03:53 . 2011-11-25 03:53 ——– d—–w- c:\program files\Common Files\Motorola Shared
2011-11-25 03:53 . 2011-11-25 03:53 ——– d—–w- c:\program files\Motorola
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-29 01:02 . 2011-06-29 12:01 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 19:32 . 2011-04-27 04:29 150856 —-a-w- c:\windows\system32\mfevtps.exe
2011-10-15 18:16 . 2011-04-27 04:29 9608 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-10-15 18:16 . 2011-04-27 04:29 89792 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-10-15 18:16 . 2011-04-27 04:29 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-10-15 18:16 . 2011-04-27 04:29 83856 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2011-10-15 18:16 . 2011-04-27 04:29 59456 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2011-10-15 18:16 . 2011-04-27 04:29 57600 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-10-15 18:16 . 2011-04-27 04:29 464176 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2011-10-15 18:16 . 2011-04-27 04:29 338176 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-10-15 18:16 . 2011-04-27 04:29 180816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-10-15 18:16 . 2011-04-27 04:29 121256 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-10-10 14:22 . 2009-01-23 16:57 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-08 17:07 . 2011-10-08 17:07 18944 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe
2011-09-28 07:06 . 2008-04-14 09:41 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2007-10-09 17:03 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-12 12:25 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-12 12:25 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2011-10-21 09:10 87440 —-a-w- c:\program files\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5bdea838-df85-40de-85c0-af50e1024f0d}"= "c:\program files\SoyDominicano.NET\prxtbSoy0.dll" [2011-01-17 175912]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files\adawaretb\adawareDx.dll" [2011-10-21 87440]
.
[HKEY_CLASSES_ROOT\clsid\{5bdea838-df85-40de-85c0-af50e1024f0d}]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5BDEA838-DF85-40DE-85C0-AF50E1024F0D}"= "c:\program files\SoyDominicano.NET\prxtbSoy0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{5bdea838-df85-40de-85c0-af50e1024f0d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\documents and settings\Owner\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-15 137536]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-07 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-24 118784]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-03-28 57344]
"ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2008-09-19 1529856]
"ISW.exe"="c:\program files\AT&T;\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-09-16 1318552]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-02 190808]
"Nikon Message Center 2"="c:\program files\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-25 619008]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"Ad-Aware Browsing Protection"="c:\documents and settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe" [2011-10-21 198032]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...r=9.0.894" [?]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
2X Client.lnk - c:\program files\2X\Client\APPServerClient.exe [2011-12-1 2012040]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-09-14 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\2X\\Client\\TSClient.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Windows Savevid Toolbar\\Datamngr\\ToolBar\\dtUser.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\adawaretb\\dtUser.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/1/2011 11:33 PM 64512]
R0 pctBTFix;PC Tools Boot Fix Driver;c:\windows\system32\drivers\pctBTFix.sys [12/3/2011 3:01 AM 17848]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/3/2011 1:30 AM 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [12/3/2011 1:30 AM 341656]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [12/3/2011 1:30 AM 660992]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [12/3/2011 5:03 PM 54328]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [12/3/2011 5:03 PM 574424]
R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [6/11/2010 7:21 PM 4064]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/26/2011 11:29 PM 89792]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [12/3/2011 3:02 AM 253096]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [12/3/2011 1:29 AM 185560]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/17/2010 1:25 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [5/4/2011 12:54 PM 116608]
R2 2X SSO Service;2X SSO Service;c:\program files\2X\Client\TUXCredProv.exe [12/1/2011 12:17 PM 687496]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [12/3/2011 3:05 AM 546768]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/26/2011 11:28 PM 214904]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/26/2011 11:28 PM 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/26/2011 11:28 PM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/26/2011 11:29 PM 160608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [4/26/2011 11:29 PM 150856]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [4/1/2011 12:11 AM 428640]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/26/2011 11:29 PM 57600]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [11/3/2011 12:06 PM 2152152]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/26/2011 11:29 PM 338176]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [4/26/2011 11:29 PM 83856]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [12/3/2011 3:05 AM 56840]
S2 gupdate1c99ee7e995cd34;Google Update Service (gupdate1c99ee7e995cd34);c:\program files\Google\Update\GoogleUpdate.exe [3/7/2009 12:45 AM 133104]
S2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [4/26/2011 3:23 PM 223088]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys –> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/7/2009 12:45 AM 133104]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [11/3/2011 12:06 PM 15232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/26/2011 11:29 PM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/26/2011 11:29 PM 87656]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [12/3/2011 3:01 AM 70536]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools\PC Tools Security\pctsAuxs.exe [12/3/2011 3:00 AM 402336]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [12/3/2011 5:03 PM 35264]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools\PC Tools Security\TFEngine\TFService.exe service –> c:\program files\PC Tools\PC Tools Security\TFEngine\TFService.exe service [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/14/2008 4:42 AM 14336]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-11-03 17:06]
.
2011-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-12-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-1682526488-1606980848-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-08-23 16:00]
.
2011-12-09 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-1682526488-1606980848-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-08-23 16:00]
.
2011-12-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-07 11:01]
.
2011-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-07 05:45]
.
2011-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-07 05:45]
.
2011-11-25 c:\windows\Tasks\MotoHelper MUM.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-04-26 20:23]
.
2011-12-09 c:\windows\Tasks\MotoHelper Routing.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-04-26 20:23]
.
2011-11-25 c:\windows\Tasks\MotoHelper Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-04-26 20:23]
.
2011-12-08 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\progra~1\NORTON~1\Engine\351~1.6\Nss.exe [2011-10-08 04:47]
.
2011-12-09 c:\windows\Tasks\User_Feed_Synchronization-{2C5D2369-05C8-4720-B088-78D1B8DB9F44}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
2011-12-08 c:\windows\Tasks\vtscheduletask.job
- c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2011-06-09 18:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Settings,ProxyOverride = *.local;192.168.*.*
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Save video on Savevid.com - c:\program files\Savevid\redirect.htm
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: 0.0.0.0
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: motive.com\patttbc.att
TCP: DhcpNameServer = 192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Privacy Protection - c:\documents and settings\All Users\Application Data\privacy.exe
HKLM-Run-SpeetItUpFree - c:\program files\SpeedItup Free\speeditupfree.exe
SafeBoot-WinDefend
MSConfigStartUp-CTFMON - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-08 23:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1100)
c:\program files\2X\Client\TUXCredProv.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'lsass.exe'(1156)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
- - - - - - - > 'explorer.exe'(1664)
c:\windows\system32\WININET.dll
c:\documents and settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\windows\system32\rundll32.exe
c:\program files\Lexmark X1100 Series\lxbkbmon.exe
c:\program files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\program files\iPod\bin\iPodService.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Completion time: 2011-12-08 23:44:36 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-09 04:44
ComboFix2.txt 2011-07-14 01:59
.
Pre-Run: 357,984,309,248 bytes free
Post-Run: 358,257,479,680 bytes free
.
- - End Of File - - 4BAA4CE281300B767C1A8E9123664B2B


22:27:19.0312 1512 TDSS rootkit removing tool [removed] Dec 7 2011 13:21:06
22:27:20.0656 1512 ============================================================
22:27:20.0656 1512 Current date / time: 2011/12/08 22:27:20.0656
22:27:20.0656 1512 SystemInfo:
22:27:20.0656 1512
22:27:20.0656 1512 OS Version: 5.1.2600 ServicePack: 3.0
22:27:20.0656 1512 Product type: Workstation
22:27:20.0656 1512 ComputerName: OWNER-84FDF6F64
22:27:20.0656 1512 UserName: Owner
22:27:20.0656 1512 Windows directory: C:\WINDOWS
22:27:20.0656 1512 System windows directory: C:\WINDOWS
22:27:20.0656 1512 Processor architecture: Intel x86
22:27:20.0656 1512 Number of processors: 2
22:27:20.0656 1512 Page size: 0x1000
22:27:20.0656 1512 Boot type: Normal boot
22:27:20.0656 1512 ============================================================
22:27:21.0375 1512 Initialize success
22:27:26.0156 4124 ============================================================
22:27:26.0156 4124 Scan started
22:27:26.0156 4124 Mode: Manual;
22:27:26.0156 4124 ============================================================
22:27:27.0703 4124 Abiosdsk - ok
22:27:27.0718 4124 abp480n5 - ok
22:27:27.0765 4124 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:27:27.0781 4124 ACPI - ok
22:27:27.0812 4124 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
22:27:27.0828 4124 ACPIEC - ok
22:27:27.0843 4124 adpu160m - ok
22:27:27.0890 4124 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
22:27:27.0906 4124 aec - ok
22:27:27.0968 4124 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
22:27:28.0093 4124 AFD - ok
22:27:28.0109 4124 Aha154x - ok
22:27:28.0125 4124 aic78u2 - ok
22:27:28.0140 4124 aic78xx - ok
22:27:28.0156 4124 AliIde - ok
22:27:28.0171 4124 amsint - ok
22:27:28.0187 4124 asc - ok
22:27:28.0203 4124 asc3350p - ok
22:27:28.0218 4124 asc3550 - ok
22:27:28.0296 4124 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:27:28.0296 4124 AsyncMac - ok
22:27:28.0359 4124 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:27:28.0359 4124 atapi - ok
22:27:28.0375 4124 Atdisk - ok
22:27:28.0406 4124 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:27:28.0421 4124 Atmarpc - ok
22:27:28.0468 4124 ATMhelpr (3ef1db7f168851914517d4ed36b57c04) C:\WINDOWS\system32\drivers\ATMhelpr.sys
22:27:28.0562 4124 ATMhelpr - ok
22:27:28.0609 4124 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:27:28.0625 4124 audstub - ok
22:27:28.0640 4124 b57w2k (241474d01380e9ed41d4c07f4f5fd401) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
22:27:28.0718 4124 b57w2k - ok
22:27:28.0765 4124 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:27:28.0781 4124 Beep - ok
22:27:28.0921 4124 catchme - ok
22:27:28.0953 4124 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:27:28.0968 4124 cbidf2k - ok
22:27:28.0984 4124 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:27:29.0000 4124 CCDECODE - ok
22:27:29.0015 4124 cd20xrnt - ok
22:27:29.0046 4124 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:27:29.0046 4124 Cdaudio - ok
22:27:29.0109 4124 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
22:27:29.0109 4124 Cdfs - ok
22:27:29.0140 4124 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:27:29.0140 4124 Cdrom - ok
22:27:29.0203 4124 cfwids (1dcb5209601a70e36c70fe8d197d62cb) C:\WINDOWS\system32\drivers\cfwids.sys
22:27:29.0265 4124 cfwids - ok
22:27:29.0281 4124 Changer - ok
22:27:29.0296 4124 CmdIde - ok
22:27:29.0312 4124 Cpqarray - ok
22:27:29.0328 4124 dac2w2k - ok
22:27:29.0343 4124 dac960nt - ok
22:27:29.0437 4124 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
22:27:29.0437 4124 Disk - ok
22:27:29.0515 4124 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
22:27:29.0578 4124 dmboot - ok
22:27:29.0593 4124 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
22:27:29.0593 4124 dmio - ok
22:27:29.0609 4124 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:27:29.0625 4124 dmload - ok
22:27:29.0656 4124 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
22:27:29.0656 4124 DMusic - ok
22:27:29.0671 4124 dpti2o - ok
22:27:29.0687 4124 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
22:27:29.0687 4124 drmkaud - ok
22:27:29.0796 4124 esgiguard - ok
22:27:29.0843 4124 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
22:27:29.0859 4124 Fastfat - ok
22:27:29.0890 4124 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
22:27:29.0890 4124 Fdc - ok
22:27:29.0906 4124 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
22:27:29.0921 4124 Fips - ok
22:27:29.0921 4124 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
22:27:29.0937 4124 Flpydisk - ok
22:27:29.0984 4124 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:27:29.0984 4124 FltMgr - ok
22:27:30.0046 4124 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:27:30.0046 4124 Fs_Rec - ok
22:27:30.0062 4124 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:27:30.0062 4124 Ftdisk - ok
22:27:30.0109 4124 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
22:27:30.0171 4124 GEARAspiWDM - ok
22:27:30.0234 4124 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:27:30.0234 4124 Gpc - ok
22:27:30.0328 4124 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:27:30.0328 4124 hidusb - ok
22:27:30.0343 4124 hpn - ok
22:27:30.0406 4124 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
22:27:30.0406 4124 HTTP - ok
22:27:30.0421 4124 i2omgmt - ok
22:27:30.0437 4124 i2omp - ok
22:27:30.0468 4124 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\drivers\i8042prt.sys
22:27:30.0468 4124 i8042prt - ok
22:27:30.0531 4124 ialm (0f0194c4b635c10c3f785e4fee52d641) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
22:27:30.0734 4124 ialm - ok
22:27:30.0812 4124 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:27:30.0812 4124 Imapi - ok
22:27:30.0828 4124 ini910u - ok
22:27:30.0843 4124 IntelIde - ok
22:27:30.0859 4124 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:27:30.0859 4124 intelppm - ok
22:27:30.0890 4124 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:27:30.0906 4124 Ip6Fw - ok
22:27:30.0937 4124 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:27:30.0953 4124 IpFilterDriver - ok
22:27:30.0968 4124 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:27:30.0984 4124 IpInIp - ok
22:27:31.0015 4124 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:27:31.0031 4124 IpNat - ok
22:27:31.0046 4124 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:27:31.0062 4124 IPSec - ok
22:27:31.0093 4124 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:27:31.0093 4124 IRENUM - ok
22:27:31.0140 4124 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:27:31.0140 4124 isapnp - ok
22:27:31.0187 4124 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:27:31.0187 4124 Kbdclass - ok
22:27:31.0203 4124 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:27:31.0218 4124 kbdhid - ok
22:27:31.0234 4124 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
22:27:31.0250 4124 kmixer - ok
22:27:31.0281 4124 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
22:27:31.0281 4124 KSecDD - ok
22:27:31.0390 4124 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
22:27:31.0468 4124 Lavasoft Kernexplorer - ok
22:27:31.0484 4124 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
22:27:31.0500 4124 Lbd - ok
22:27:31.0500 4124 lbrtfdc - ok
22:27:31.0578 4124 LVPr2Mon (8be71d7edb8c7494913722059f760dd0) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
22:27:31.0734 4124 LVPr2Mon - ok
22:27:31.0796 4124 LVRS (b6e1ccd6572984adcae68439afd07011) C:\WINDOWS\system32\DRIVERS\lvrs.sys
22:27:31.0937 4124 LVRS - ok
22:27:32.0078 4124 LVUVC (6c42815dd57e397f0cd988304b5eb4b3) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
22:27:32.0265 4124 LVUVC - ok
22:27:32.0375 4124 mfeapfk (36b47b1e9c537f8f2b4481084b8f7d22) C:\WINDOWS\system32\drivers\mfeapfk.sys
22:27:32.0500 4124 mfeapfk - ok
22:27:32.0531 4124 mfeavfk (cde41293db871a75cd99eb0ce781356b) C:\WINDOWS\system32\drivers\mfeavfk.sys
22:27:32.0625 4124 mfeavfk - ok
22:27:32.0640 4124 mfeavfk01 - ok
22:27:32.0703 4124 mfebopk (e22385f64bdf0ad81157479496e33c4a) C:\WINDOWS\system32\drivers\mfebopk.sys
22:27:32.0812 4124 mfebopk - ok
22:27:32.0859 4124 mfefirek (215666a8a85023ef019b510cbb67f678) C:\WINDOWS\system32\drivers\mfefirek.sys
22:27:32.0937 4124 mfefirek - ok
22:27:33.0000 4124 mfehidk (56d330981866a72f061dd16cc5004513) C:\WINDOWS\system32\drivers\mfehidk.sys
22:27:33.0000 4124 mfehidk - ok
22:27:33.0015 4124 mfendisk (62acda4e958e2a392557ba3c6c754a58) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
22:27:33.0093 4124 mfendisk - ok
22:27:33.0109 4124 mfendiskmp (62acda4e958e2a392557ba3c6c754a58) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
22:27:33.0109 4124 mfendiskmp - ok
22:27:33.0156 4124 mferkdet (89b564d63c53fc0c6782ab07eea63acf) C:\WINDOWS\system32\drivers\mferkdet.sys
22:27:33.0296 4124 mferkdet - ok
22:27:33.0578 4124 mfetdi2k (922e64ca38e38106498fb3435a8e399d) C:\WINDOWS\system32\drivers\mfetdi2k.sys
22:27:33.0671 4124 mfetdi2k - ok
22:27:33.0734 4124 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:27:33.0734 4124 mnmdd - ok
22:27:33.0781 4124 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
22:27:33.0781 4124 Modem - ok
22:27:33.0859 4124 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:27:33.0859 4124 Mouclass - ok
22:27:33.0921 4124 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:27:33.0937 4124 mouhid - ok
22:27:34.0015 4124 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
22:27:34.0015 4124 MountMgr - ok
22:27:34.0015 4124 mraid35x - ok
22:27:34.0140 4124 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
22:27:34.0250 4124 MREMP50 - ok
22:27:34.0250 4124 MREMP50a64 - ok
22:27:34.0250 4124 MREMPR5 - ok
22:27:34.0265 4124 MRENDIS5 - ok
22:27:34.0281 4124 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
22:27:34.0375 4124 MRESP50 - ok
22:27:34.0390 4124 MRESP50a64 - ok
22:27:34.0437 4124 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:27:34.0437 4124 MRxDAV - ok
22:27:34.0484 4124 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:27:34.0484 4124 MRxSmb - ok
22:27:34.0515 4124 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
22:27:34.0515 4124 Msfs - ok
22:27:34.0546 4124 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:27:34.0546 4124 MSKSSRV - ok
22:27:34.0562 4124 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:27:34.0578 4124 MSPCLOCK - ok
22:27:34.0593 4124 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
22:27:34.0593 4124 MSPQM - ok
22:27:34.0625 4124 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:27:34.0640 4124 mssmbios - ok
22:27:34.0687 4124 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
22:27:34.0687 4124 MSTEE - ok
22:27:34.0734 4124 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
22:27:34.0734 4124 Mup - ok
22:27:34.0796 4124 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:27:34.0796 4124 NABTSFEC - ok
22:27:34.0859 4124 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
22:27:34.0859 4124 NDIS - ok
22:27:34.0906 4124 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:27:34.0906 4124 NdisIP - ok
22:27:34.0937 4124 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:27:35.0015 4124 NdisTapi - ok
22:27:35.0046 4124 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:27:35.0062 4124 Ndisuio - ok
22:27:35.0078 4124 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:27:35.0078 4124 NdisWan - ok
22:27:35.0140 4124 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
22:27:35.0218 4124 NDProxy - ok
22:27:35.0250 4124 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:27:35.0250 4124 NetBIOS - ok
22:27:35.0281 4124 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:27:35.0281 4124 NetBT - ok
22:27:35.0328 4124 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
22:27:35.0328 4124 Npfs - ok
22:27:35.0343 4124 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
22:27:35.0359 4124 Ntfs - ok
22:27:35.0390 4124 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:27:35.0406 4124 Null - ok
22:27:35.0437 4124 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:27:35.0437 4124 NwlnkFlt - ok
22:27:35.0453 4124 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:27:35.0453 4124 NwlnkFwd - ok
22:27:35.0515 4124 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
22:27:35.0515 4124 Parport - ok
22:27:35.0546 4124 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
22:27:35.0546 4124 PartMgr - ok
22:27:35.0562 4124 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
22:27:35.0562 4124 ParVdm - ok
22:27:35.0593 4124 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
22:27:35.0593 4124 PCI - ok
22:27:35.0609 4124 PCIDump - ok
22:27:35.0625 4124 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:27:35.0625 4124 PCIIde - ok
22:27:35.0640 4124 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
22:27:35.0656 4124 Pcmcia - ok
22:27:35.0703 4124 PCTBD (3a0262b85b5bb4d4cfc096ea00ed610b) C:\WINDOWS\system32\Drivers\PCTBD.sys
22:27:35.0828 4124 PCTBD - ok
22:27:35.0875 4124 pctBTFix (7a88a2ebf975103be7fdf5b288ecfdcd) C:\WINDOWS\system32\Drivers\pctBTFix.sys
22:27:35.0875 4124 pctBTFix - ok
22:27:35.0906 4124 PCTCore (0edb74bd0d52d6d94cf862322e48b94e) C:\WINDOWS\system32\drivers\PCTCore.sys
22:27:35.0921 4124 PCTCore - ok
22:27:35.0968 4124 pctDS (af08ec0f2093867ab955e24121ee7002) C:\WINDOWS\system32\drivers\pctDS.sys
22:27:35.0968 4124 pctDS - ok
22:27:36.0000 4124 pctEFA (4b1b0cd45a047c0941f6b6151f6fb3c1) C:\WINDOWS\system32\drivers\pctEFA.sys
22:27:36.0015 4124 pctEFA - ok
22:27:36.0078 4124 pctgntdi (44fd6a1042c766df69bc6ba55780019d) C:\WINDOWS\system32\drivers\pctgntdi.sys
22:27:36.0171 4124 pctgntdi - ok
22:27:36.0218 4124 pctplsg (b5d22f79943e156bf8fabf1e4888820c) C:\WINDOWS\system32\drivers\pctplsg.sys
22:27:36.0359 4124 pctplsg - ok
22:27:36.0390 4124 PCTSD (86b9af53e46d0618d230608aed82622f) C:\WINDOWS\system32\Drivers\PCTSD.sys
22:27:36.0546 4124 PCTSD - ok
22:27:36.0562 4124 PDCOMP - ok
22:27:36.0562 4124 PDFRAME - ok
22:27:36.0578 4124 PDRELI - ok
22:27:36.0593 4124 PDRFRAME - ok
22:27:36.0609 4124 perc2 - ok
22:27:36.0625 4124 perc2hib - ok
22:27:36.0687 4124 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:27:36.0703 4124 PptpMiniport - ok
22:27:36.0718 4124 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
22:27:36.0718 4124 PSched - ok
22:27:36.0765 4124 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:27:36.0765 4124 Ptilink - ok
22:27:36.0781 4124 ql1080 - ok
22:27:36.0781 4124 Ql10wnt - ok
22:27:36.0796 4124 ql12160 - ok
22:27:36.0812 4124 ql1240 - ok
22:27:36.0828 4124 ql1280 - ok
22:27:36.0859 4124 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:27:36.0875 4124 RasAcd - ok
22:27:36.0890 4124 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:27:36.0890 4124 Rasl2tp - ok
22:27:36.0906 4124 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:27:36.0921 4124 RasPppoe - ok
22:27:36.0937 4124 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:27:36.0937 4124 Raspti - ok
22:27:36.0968 4124 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:27:36.0968 4124 Rdbss - ok
22:27:37.0015 4124 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:27:37.0031 4124 RDPCDD - ok
22:27:37.0078 4124 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:27:37.0093 4124 rdpdr - ok
22:27:37.0140 4124 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
22:27:37.0359 4124 RDPWD - ok
22:27:37.0484 4124 SABProcEnum - ok
22:27:37.0546 4124 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
22:27:37.0625 4124 SASDIFSV - ok
22:27:37.0640 4124 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
22:27:37.0703 4124 SASKUTIL - ok
22:27:37.0812 4124 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:27:37.0812 4124 Secdrv - ok
22:27:37.0890 4124 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys
22:27:37.0984 4124 senfilt - ok
22:27:38.0015 4124 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
22:27:38.0031 4124 serenum - ok
22:27:38.0046 4124 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
22:27:38.0046 4124 Serial - ok
22:27:38.0125 4124 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
22:27:38.0125 4124 sfdrv01 - ok
22:27:38.0125 4124 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
22:27:38.0140 4124 sfhlp02 - ok
22:27:38.0156 4124 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:27:38.0171 4124 Sfloppy - ok
22:27:38.0187 4124 sfsync02 (efebbc1d13fdb77a6af4eddfc7232edf) C:\WINDOWS\system32\drivers\sfsync02.sys
22:27:38.0187 4124 sfsync02 - ok
22:27:38.0203 4124 sfvfs02 (9ef50060cc7e6953bab83f2a42ccc421) C:\WINDOWS\system32\drivers\sfvfs02.sys
22:27:38.0203 4124 sfvfs02 - ok
22:27:38.0218 4124 Simbad - ok
22:27:38.0265 4124 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
22:27:38.0281 4124 SLIP - ok
22:27:38.0328 4124 smwdm (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys
22:27:38.0343 4124 smwdm - ok
22:27:38.0359 4124 Sparrow - ok
22:27:38.0390 4124 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
22:27:38.0406 4124 splitter - ok
22:27:38.0437 4124 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
22:27:38.0437 4124 sr - ok
22:27:38.0468 4124 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
22:27:38.0468 4124 Srv - ok
22:27:38.0515 4124 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\WINDOWS\system32\drivers\StarOpen.sys
22:27:38.0593 4124 StarOpen - ok
22:27:38.0671 4124 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:27:38.0687 4124 streamip - ok
22:27:38.0734 4124 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:27:38.0734 4124 swenum - ok
22:27:38.0750 4124 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
22:27:38.0765 4124 swmidi - ok
22:27:38.0781 4124 symc810 - ok
22:27:38.0796 4124 symc8xx - ok
22:27:38.0796 4124 sym_hi - ok
22:27:38.0812 4124 sym_u3 - ok
22:27:38.0828 4124 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
22:27:38.0843 4124 sysaudio - ok
22:27:38.0906 4124 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:27:38.0921 4124 Tcpip - ok
22:27:38.0953 4124 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:27:38.0968 4124 TDPIPE - ok
22:27:38.0968 4124 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
22:27:38.0984 4124 TDTCP - ok
22:27:39.0031 4124 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:27:39.0031 4124 TermDD - ok
22:27:39.0093 4124 TfFsMon (754f8fd78ea7fa2b9a0cb8a69e0f0822) C:\WINDOWS\system32\drivers\TfFsMon.sys
22:27:39.0093 4124 TfFsMon - ok
22:27:39.0125 4124 TfNetMon (697f66899b4f0c2d8ae3e7473b4b6244) C:\WINDOWS\system32\drivers\TfNetMon.sys
22:27:39.0265 4124 TfNetMon - ok
22:27:39.0312 4124 TFSysMon (e02f47b841be86bfdf4d7269ed0b95e4) C:\WINDOWS\system32\drivers\TfSysMon.sys
22:27:39.0312 4124 TFSysMon - ok
22:27:39.0343 4124 TosIde - ok
22:27:39.0406 4124 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
22:27:39.0421 4124 Udfs - ok
22:27:39.0437 4124 ultra - ok
22:27:39.0500 4124 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
22:27:39.0515 4124 Update - ok
22:27:39.0562 4124 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys
22:27:39.0703 4124 USBAAPL - ok
22:27:39.0734 4124 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
22:27:39.0750 4124 usbaudio - ok
22:27:39.0812 4124 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:27:39.0812 4124 usbccgp - ok
22:27:39.0828 4124 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:27:39.0843 4124 usbehci - ok
22:27:39.0890 4124 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:27:39.0906 4124 usbhub - ok
22:27:39.0953 4124 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:27:39.0968 4124 usbprint - ok
22:27:40.0000 4124 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:27:40.0015 4124 usbscan - ok
22:27:40.0046 4124 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:27:40.0062 4124 USBSTOR - ok
22:27:40.0078 4124 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:27:40.0078 4124 usbuhci - ok
22:27:40.0125 4124 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
22:27:40.0125 4124 usbvideo - ok
22:27:40.0171 4124 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
22:27:40.0187 4124 VgaSave - ok
22:27:40.0187 4124 ViaIde - ok
22:27:40.0218 4124 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
22:27:40.0218 4124 VolSnap - ok
22:27:40.0250 4124 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:27:40.0265 4124 Wanarp - ok
22:27:40.0265 4124 WDICA - ok
22:27:40.0296 4124 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
22:27:40.0296 4124 wdmaud - ok
22:27:40.0390 4124 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
22:27:40.0390 4124 WpdUsb - ok
22:27:40.0406 4124 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
22:27:40.0421 4124 WS2IFSL - ok
22:27:40.0437 4124 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:27:40.0453 4124 WSTCODEC - ok
22:27:40.0484 4124 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:27:40.0500 4124 WudfPf - ok
22:27:40.0750 4124 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:27:40.0781 4124 WudfRd - ok
22:27:40.0828 4124 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
22:27:40.0843 4124 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - infected
22:27:40.0859 4124 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.b (0)
22:27:40.0859 4124 Boot (0x1200) (f70796c98baf68813ccb0e9f4cfbf4dc) \Device\Harddisk0\DR0\Partition0
22:27:40.0859 4124 \Device\Harddisk0\DR0\Partition0 - ok
22:27:40.0859 4124 ============================================================
22:27:40.0859 4124 Scan finished
22:27:40.0859 4124 ============================================================
22:27:40.0875 4952 Detected object count: 1
22:27:40.0875 4952 Actual detected object count: 1
22:27:48.0187 4952 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - will be cured on reboot
22:27:48.0187 4952 \Device\Harddisk0\DR0 - ok
22:27:48.0187 4952 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Cure
22:27:59.0500 2352 Deinitialize success

Again, THANKS so much!

Ann

AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}


You have 2 antivirus installed.pleas remove 1 as they conflict and is probably why Combofix struggled to run properly.



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please













Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
Hello! :thumbup: Ok, I was able to get both programs insstalled and working, and the logs will be posted below, again, for your perusal. Thank you! C:\Program Files\FoxTabAudioConverter\AudioConverter.exe a variant of Win32/InstallCore.A application cleaned by deleting - quarantined C:\Program Files\Yontoo Layers\YontooIEClient.dll Win32/Adware.Yontoo.A application cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\c9e5f2\67.mof.vir Win32/RogueAV.A trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Program Files\Search Toolbar\SearchToolbar.dll.vir Win32/Toolbar.Zugo application cleaned by deleting - quarantined C:\System Volume Information\_restore{B1E6D8AF-3DB6-4648-A904-39C7E61D5064}\RP105\A0027330.rbf a variant of Win32/SlowPCfighter application cleaned by deleting - quarantined C:\System Volume Information\_restore{B1E6D8AF-3DB6-4648-A904-39C7E61D5064}\RP158\A0059135.exe a variant of Win32/InstallCore.A application cleaned by deleting - quarantined C:\System Volume Information\_restore{B1E6D8AF-3DB6-4648-A904-39C7E61D5064}\RP158\A0059136.dll Win32/Adware.Yontoo.A application cleaned by deleting - quarantined Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8346 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/10/2011 12:35:04 AM mbam-log-2011-12-10 (00-35-04).txt Scan type: Quick scan Objects scanned: 169229 Time elapsed: 2 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thanks again, so much! My computer seems to be running much better now– right now i'm not getting the redirects, which is cool, and I can still access this site. the green background screen which appeared when I was first infected though, is still present. At least I can now see all my icons, which is also cool. Thank you for reading this, and please let me know what other steps I may need to take. I *did* delete McAfee by the way, which did not seem to be doing me much good anyway. Have a wonderful evening. Ann

the green background screen which appeared when I was first infected though, is still present

Can you not change it back to your normal desktop background?



  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi there! :clap: You are awesome!
Ok, I did as you said, and the logfiles are posted below:

OTL Notepad first:

OTL logfile created on: 12/10/2011 10:05:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.49 Gb Total Physical Memory | 2.63 Gb Available Physical Memory | 75.23% Memory free
4.82 Gb Paging File | 4.29 Gb Available in Paging File | 89.05% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.61 Gb Total Space | 333.59 Gb Free Space | 89.53% Space Free | Partition Type: NTFS

Computer Name: OWNER-84FDF6F64 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\2X\Client\TUXCredProv.exe (2X Software Ltd.)
PRC - C:\Program Files\2X\Client\APPServerClient.exe (2X Software Ltd.)
PRC - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\ATT-SST\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AT&T\Internet Security Wizard\ISW.exe (AT&T)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\PC Tools\PC Tools Security\BDT\BSPatch.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Program Files\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll ()
MOD - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\AmvTransform.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBKPP5C.DLL ()
MOD - C:\Program Files\Lexmark X1100 Series\ConvDIB.dll ()


========== Win32 Services (SafeList) ==========

SRV - (mfevtp) – File not found
SRV - (mfefire) – File not found
SRV - (McShield) – File not found
SRV - (2X SSO Service) – C:\Program Files\2X\Client\\TUXCredProv.exe ()
SRV - (sdCoreService) – C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (0050001323483531mcinstcleanup) McAfee Application Installer Cleanup (0050001323483531) – C:\Documents and Settings\Owner\Local Settings\temp\0050001323483531mcinst.exe (McAfee, Inc.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (mfetdi2k) – File not found
DRV - (mfehidk) – File not found
DRV - (mfeavfk) – File not found
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctBTFix) – C:\WINDOWS\System32\Drivers\pctBTFix.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TFSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (PCTBD) – C:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVUVC) Logitech HD Webcam C270(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (sfvfs02) StarForce Protection VFS Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (ATMhelpr) – C:\WINDOWS\System32\drivers\ATMHELPR.SYS (Adobe Systems Incorporated)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Owner\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/03/17 01:00:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2011/12/03 03:05:21 | 000,000,000 | —D | M]

[2011/02/15 20:12:56 | 000,002,047 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml

O1 HOSTS File: ([2011/12/08 23:29:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Ad-Aware Security Toolbar) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SoyDominicano.NET Toolbar) - {5bdea838-df85-40de-85c0-af50e1024f0d} - C:\Program Files\SoyDominicano.NET\prxtbSoy0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Toolbar) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (SoyDominicano.NET Toolbar) - {5BDEA838-DF85-40DE-85C0-AF50E1024F0D} - C:\Program Files\SoyDominicano.NET\prxtbSoy0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ATT-SST_McciTrayApp] C:\Program Files\ATT-SST\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [ISW.exe] C:\Program Files\AT&T\Internet Security Wizard\ISW.exe (AT&T)
O4 - HKLM..\Run: [Lexmark X1100 Series] C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\Owner\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\2X Client.lnk = C:\Program Files\2X\Client\APPServerClient.exe (2X Software Ltd.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files\Savevid\redirect.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: 0.0.0.0 ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1236398655031 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237315749827 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0B48736E-D654-47FB-8CBE-239F7B7E764E}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (C:\Program Files\2X\Client\\TUXCredProv.dll) -C:\Program Files\2X\Client\\TUXCredProv.dll ()
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/23 12:00:22 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/10 10:04:23 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/09 21:34:32 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/12/09 21:19:43 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/12/09 15:40:45 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2011/12/09 15:40:38 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/08 23:28:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/08 22:52:29 | 004,331,207 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2011/12/08 22:27:08 | 001,577,776 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\tdsskiller.exe
[2011/12/08 00:24:58 | 004,331,784 | R— | C] (Swearware) – C:\ComboFix.exe
[2011/12/05 02:36:12 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/04 20:16:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GooredFix Backups
[2011/12/04 20:16:16 | 000,071,398 | —- | C] (jpshortstuff) – C:\Documents and Settings\Owner\Desktop\GooredFix.exe
[2011/12/04 20:14:41 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
[2011/12/04 19:57:12 | 000,204,496 | —- | C] (Malwarebytes) – C:\Documents and Settings\Owner\Desktop\StartUpLite.exe
[2011/12/04 19:39:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\2X
[2011/12/04 14:49:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/12/04 08:13:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\My Extracted Files
[2011/12/04 08:06:36 | 000,000,000 | —D | C] – C:\Program Files\File Type Assistant
[2011/12/04 08:06:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\BitZipper
[2011/12/04 08:06:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\BitZipper
[2011/12/04 08:06:12 | 000,000,000 | —D | C] – C:\Program Files\BitZipper
[2011/12/04 00:18:05 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/03 17:03:51 | 000,574,424 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011/12/03 17:03:51 | 000,054,328 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011/12/03 17:03:51 | 000,035,264 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011/12/03 16:57:03 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/03 16:57:01 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/03 16:48:57 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\adawaretb
[2011/12/03 03:05:16 | 000,056,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTBD.sys
[2011/12/03 03:05:14 | 002,246,608 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/12/03 03:05:14 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/12/03 03:05:14 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/12/03 03:02:12 | 000,253,096 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2011/12/03 03:01:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/12/03 03:01:47 | 000,017,848 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctBTFix.sys
[2011/12/03 03:01:16 | 000,070,536 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2011/12/03 03:00:30 | 000,000,000 | —D | C] – C:\Program Files\PC Tools
[2011/12/03 01:30:18 | 000,660,992 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2011/12/03 01:30:18 | 000,341,656 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/12/03 01:30:06 | 000,331,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2011/12/03 01:30:05 | 000,162,584 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2011/12/03 01:29:58 | 000,185,560 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTSD.sys
[2011/12/03 01:29:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2011/12/03 01:27:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2011/12/03 01:27:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\TestApp
[2011/12/03 01:16:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2011/12/03 01:16:47 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2011/12/02 22:43:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/01 23:34:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\adaware
[2011/12/01 23:34:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2011/12/01 23:34:27 | 000,000,000 | —D | C] – C:\Program Files\Toolbar Cleaner
[2011/12/01 23:33:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\adawaretb
[2011/12/01 23:33:31 | 000,000,000 | —D | C] – C:\Program Files\adawaretb
[2011/12/01 23:33:20 | 000,064,512 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2011/12/01 23:32:46 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2011/12/01 17:53:50 | 000,000,000 | —D | C] – C:\sh4ldr
[2011/12/01 17:53:50 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2011/12/01 17:53:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2011/11/24 22:53:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Motorola Shared
[2011/11/24 22:53:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Motorola
[2011/11/24 22:53:23 | 000,000,000 | —D | C] – C:\Program Files\Motorola
[2011/11/20 19:18:08 | 029,918,440 | —- | C] (IObit ) – C:\Documents and Settings\Owner\Desktop\asc-setup.exe
[2011/11/20 03:38:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/10 10:04:32 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/10 10:02:01 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/12/10 10:01:34 | 000,002,515 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Word.lnk
[2011/12/10 09:32:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/10 09:05:03 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-1682526488-1606980848-1003UA.job
[2011/12/10 05:02:13 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2C5D2369-05C8-4720-B088-78D1B8DB9F44}.job
[2011/12/09 23:04:08 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/09 22:53:05 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\MotoHelper Routing.job
[2011/12/09 21:32:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/09 21:25:10 | 000,000,802 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/12/09 21:25:10 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/09 20:55:52 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/09 14:51:17 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Owner.job
[2011/12/09 12:05:01 | 000,000,976 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-1682526488-1606980848-1003Core.job
[2011/12/09 01:46:18 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/09 01:45:44 | 000,001,664 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\2X Client.lnk
[2011/12/09 01:45:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/08 23:34:45 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/12/08 23:29:16 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/08 22:52:29 | 004,331,207 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2011/12/08 22:27:08 | 001,577,776 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\tdsskiller.exe
[2011/12/08 00:24:58 | 004,331,784 | R— | M] (Swearware) – C:\ComboFix.exe
[2011/12/06 02:04:59 | 000,657,086 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/12/05 02:36:14 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/04 23:55:49 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2011/12/04 23:55:49 | 000,000,044 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2011/12/04 20:16:16 | 000,071,398 | —- | M] (jpshortstuff) – C:\Documents and Settings\Owner\Desktop\GooredFix.exe
[2011/12/04 20:14:41 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
[2011/12/04 19:57:14 | 000,204,496 | —- | M] (Malwarebytes) – C:\Documents and Settings\Owner\Desktop\StartUpLite.exe
[2011/12/04 19:39:43 | 000,000,764 | —- | M] () – C:\Documents and Settings\All Users\Desktop\2X Client.lnk
[2011/12/04 08:08:41 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner\Desktop\settings.dat
[2011/12/04 08:08:16 | 000,000,696 | —- | M] () – C:\Documents and Settings\Owner\Desktop\BitZipper.lnk
[2011/12/04 08:06:17 | 000,000,712 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\BitZipper.lnk
[2011/12/03 16:27:16 | 000,013,374 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\iecmrf5r3icp7iqw6puv2e758t1u
[2011/12/03 16:27:16 | 000,013,374 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\iecmrf5r3icp7iqw6puv2e758t1u
[2011/12/03 03:01:51 | 000,001,809 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor.lnk
[2011/12/01 23:56:54 | 000,016,432 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2011/12/01 17:59:23 | 000,001,490 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spider Solitaire.lnk
[2011/11/28 20:02:56 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/24 22:53:58 | 000,000,370 | —- | M] () – C:\WINDOWS\tasks\MotoHelper Update.job
[2011/11/24 22:53:57 | 000,000,358 | —- | M] () – C:\WINDOWS\tasks\MotoHelper MUM.job
[2011/11/22 19:43:02 | 000,070,536 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2011/11/22 19:42:40 | 000,185,560 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\PCTSD.sys
[2011/11/22 19:41:28 | 000,017,848 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\pctBTFix.sys
[2011/11/22 19:38:04 | 000,253,096 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2011/11/22 18:20:06 | 000,574,424 | –S- | M] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011/11/22 18:20:06 | 000,035,264 | –S- | M] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011/11/22 18:20:04 | 000,054,328 | –S- | M] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011/11/20 19:18:10 | 029,918,440 | —- | M] (IObit ) – C:\Documents and Settings\Owner\Desktop\asc-setup.exe
[2011/11/20 03:38:58 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/11/14 16:07:06 | 000,149,456 | —- | M] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/11/14 16:07:04 | 002,246,608 | —- | M] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/11/14 16:07:04 | 001,681,360 | —- | M] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/11/14 16:06:54 | 000,767,952 | —- | M] () – C:\WINDOWS\BDTSupport.dll
[2011/11/14 15:12:26 | 000,331,880 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2011/11/14 15:12:24 | 000,162,584 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2011/11/12 19:06:29 | 000,040,448 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/11 03:19:55 | 000,444,016 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/11 03:19:55 | 000,072,274 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/09 21:25:10 | 000,000,802 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/12/04 19:53:52 | 000,001,664 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\2X Client.lnk
[2011/12/04 19:39:43 | 000,000,764 | —- | C] () – C:\Documents and Settings\All Users\Desktop\2X Client.lnk
[2011/12/04 08:08:41 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Desktop\settings.dat
[2011/12/04 08:06:17 | 000,000,712 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\BitZipper.lnk
[2011/12/04 08:06:17 | 000,000,696 | —- | C] () – C:\Documents and Settings\Owner\Desktop\BitZipper.lnk
[2011/12/03 03:57:11 | 000,013,374 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\iecmrf5r3icp7iqw6puv2e758t1u
[2011/12/03 03:57:11 | 000,013,374 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\iecmrf5r3icp7iqw6puv2e758t1u
[2011/12/03 03:05:15 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2011/12/03 03:05:14 | 000,003,488 | —- | C] () – C:\WINDOWS\UDB.zip
[2011/12/03 03:05:14 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2011/12/03 03:05:14 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2011/12/03 03:05:14 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2011/12/03 03:01:51 | 000,001,809 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor.lnk
[2011/12/02 22:43:51 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/12/02 22:43:51 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/12/02 22:43:51 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/12/02 22:43:51 | 000,001,703 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ViewNX 2.lnk
[2011/12/02 22:43:51 | 000,001,695 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Panorama Maker 5.lnk
[2011/12/02 22:43:51 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/12/02 22:43:51 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/12/02 22:43:51 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CDBurnerXP.lnk
[2011/12/02 22:43:51 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/12/02 22:43:51 | 000,001,261 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Logitech Webcam Software .lnk
[2011/12/02 22:43:51 | 000,000,970 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton Security Scan.lnk
[2011/12/02 22:43:51 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/02 22:43:51 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/02 22:43:47 | 000,002,045 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Dave Ramsey's Financial Peace Financial Software.lnk
[2011/12/02 22:43:47 | 000,000,815 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/02 22:43:47 | 000,000,800 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/12/02 22:43:47 | 000,000,792 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/12/02 22:43:47 | 000,000,533 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire.lnk
[2011/12/02 22:43:47 | 000,000,079 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/02 22:43:36 | 000,002,347 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/12/02 22:43:36 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/12/02 22:43:36 | 000,002,071 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Dave Ramsey's Personal Finance Software 5.4.lnk
[2011/12/02 22:43:36 | 000,001,986 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/12/02 22:43:36 | 000,001,556 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\CDBurnerXP.lnk
[2011/12/02 22:43:36 | 000,001,077 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live ID.lnk
[2011/12/02 22:43:36 | 000,000,955 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk
[2011/12/02 22:43:36 | 000,000,786 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/12/02 22:43:35 | 000,001,681 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\ABBYY FineReader 5.0 Sprint.lnk
[2011/12/02 22:43:35 | 000,000,738 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Acrobat_com.lnk
[2011/12/02 00:18:21 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/12/01 23:33:24 | 000,000,797 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2011/11/24 22:53:58 | 000,000,370 | —- | C] () – C:\WINDOWS\tasks\MotoHelper Update.job
[2011/11/24 22:53:57 | 000,000,358 | —- | C] () – C:\WINDOWS\tasks\MotoHelper MUM.job
[2011/11/24 22:53:56 | 000,000,354 | —- | C] () – C:\WINDOWS\tasks\MotoHelper Routing.job
[2011/07/13 20:45:51 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/07/13 20:45:51 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/07/13 20:45:51 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/07/13 20:45:51 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/07/13 20:45:51 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/07 15:48:46 | 000,059,560 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/22 22:54:03 | 000,000,000 | —- | C] () – C:\WINDOWS\ViewNX2.INI
[2011/05/22 22:41:42 | 000,000,268 | R— | C] () – C:\Documents and Settings\All Users\Application Data\Booms
[2011/05/22 22:41:42 | 000,000,268 | R— | C] () – C:\Documents and Settings\Owner\Application Data\Bass
[2011/05/22 22:41:41 | 000,000,268 | R— | C] () – C:\Documents and Settings\All Users\Application Data\BookService
[2011/05/22 22:41:41 | 000,000,268 | R— | C] () – C:\Documents and Settings\Owner\Application Data\Basics
[2011/05/22 22:41:41 | 000,000,020 | —- | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2011/05/22 22:41:40 | 000,000,268 | R— | C] () – C:\Documents and Settings\All Users\Application Data\Bass Reduction
[2011/05/22 22:41:40 | 000,000,268 | R— | C] () – C:\Documents and Settings\Owner\Application Data\Basic Track
[2011/05/22 22:41:40 | 000,000,020 | —- | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2011/05/22 22:41:39 | 000,000,020 | —- | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2011/05/19 22:21:49 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/26 16:40:44 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/26 16:40:44 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/03/22 22:58:22 | 000,014,168 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/02/06 03:10:42 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/11/09 21:45:32 | 000,102,744 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/11/09 21:45:30 | 010,877,272 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2010/11/09 21:45:20 | 000,331,608 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2010/11/09 21:31:42 | 000,027,872 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/10/26 23:29:09 | 000,004,212 | —- | C] () – C:\WINDOWS\System32\zllictbl.dat
[2010/10/26 16:02:50 | 000,000,014 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2010/10/26 15:49:21 | 000,000,018 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/10/26 15:49:21 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2010/09/10 20:28:04 | 000,000,584 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/06/11 19:18:47 | 000,000,153 | —- | C] () – C:\WINDOWS\ACROREAD.INI
[2010/06/11 19:15:41 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2010/06/11 19:15:41 | 000,000,177 | —- | C] () – C:\WINDOWS\kpcms.ini
[2010/06/11 19:15:39 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ImgLibLead.dll
[2010/06/11 19:15:38 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\Dc50ip32.dll
[2010/05/07 17:43:30 | 000,025,824 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/11/04 04:48:53 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/10/13 14:48:47 | 000,000,023 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/10/05 17:55:12 | 000,001,100 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/09/04 20:25:39 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/01 20:07:16 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/03/20 10:59:49 | 000,040,448 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/07 06:43:27 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2009/03/06 22:25:33 | 000,000,462 | —- | C] () – C:\WINDOWS\lexstat.ini
[2009/01/23 12:02:47 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/23 11:57:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/01/23 06:47:41 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/23 06:46:20 | 000,405,408 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/14 04:55:28 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2006/12/31 06:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/03/06 10:41:02 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\AMV_DecDLL.dll
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/12 07:36:06 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/12 07:36:06 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/12 07:26:08 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/12 07:26:07 | 000,444,016 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/12 07:26:06 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/12 07:26:05 | 000,072,274 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/12 07:24:57 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/12 07:22:08 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/12 07:22:01 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/12 07:18:55 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2003/03/28 09:26:24 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\LXBKIH.EXE
[2003/03/28 09:17:32 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\LXBKLCNP.DLL
[2002/11/13 11:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbkvs.dll
[2002/09/13 07:40:06 | 000,000,266 | —- | C] () – C:\WINDOWS\System32\lxbkcoin.ini
[2001/01/19 11:50:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\INSTMON.EXE

========== LOP Check ==========

[2011/01/21 05:06:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\183E
[2010/12/03 20:14:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2A131
[2011/09/15 20:24:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\373D8
[2011/12/09 01:47:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2011/03/20 00:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/03/06 20:50:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T
[2009/07/17 16:41:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATTToolbar
[2011/04/16 12:14:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/03/06 22:26:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/02/06 03:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/01/17 21:33:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Chat Republic Games
[2011/03/15 07:48:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/10/15 09:35:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Easybits GO
[2011/05/22 22:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/10/06 19:07:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fighters
[2011/04/26 18:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2010/11/28 10:14:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/05/22 22:41:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nature
[2011/05/24 05:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/05/22 22:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PDEs
[2011/05/22 22:41:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Perl
[2010/10/26 15:49:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/06/08 19:03:02 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\SSGGUS
[2011/12/09 01:45:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/22 22:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/10/15 09:54:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2009/06/18 20:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2011/07/06 22:18:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/09/12 20:44:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{ACFC9F59-F1AE-43D2-8CFE-E2F1E0F82ABA}
[2010/08/12 16:29:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\2XClient
[2011/12/02 22:45:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\adawaretb
[2009/03/07 08:30:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2009/03/06 20:50:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AT&T
[2009/07/08 08:06:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ATTToolbar
[2011/12/04 08:06:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitZipper
[2011/02/06 03:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canneverbe Limited
[2010/06/30 16:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\cerasus.media
[2010/10/26 23:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CheckPoint
[2010/05/14 17:30:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.example.main.52A93B964BBEB0902CC01E05810570B8BA16AEC8.1
[2011/10/09 20:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.amazon.music.uploader
[2011/10/08 12:17:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.moasis
[2011/10/13 15:47:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Fighters
[2011/06/05 21:26:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2011/10/15 09:34:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\go
[2011/07/20 20:28:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2011/02/08 19:56:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\imeshbandmltbpi
[2010/08/06 18:10:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ImgBurn
[2011/07/07 18:52:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ImTOO
[2011/05/19 20:46:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2011/10/03 17:57:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nikon
[2009/03/08 22:04:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2011/12/04 14:49:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/10/31 17:58:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Personal Finance Software
[2011/09/12 20:35:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchquband
[2011/09/12 20:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchqutoolbar
[2011/12/03 01:27:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TestApp
[2010/06/25 10:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuxPaint
[2010/04/02 20:23:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Unity
[2009/10/13 14:32:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2011/12/08 23:34:45 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/12/09 12:05:01 | 000,000,976 | —- | M] () – C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-1682526488-1606980848-1003Core.job
[2011/12/10 09:05:03 | 000,000,998 | —- | M] () – C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-1682526488-1606980848-1003UA.job
[2011/11/24 22:53:57 | 000,000,358 | —- | M] () – C:\WINDOWS\Tasks\MotoHelper MUM.job
[2011/12/09 22:53:05 | 000,000,354 | —- | M] () – C:\WINDOWS\Tasks\MotoHelper Routing.job
[2011/11/24 22:53:58 | 000,000,370 | —- | M] () – C:\WINDOWS\Tasks\MotoHelper Update.job
[2011/12/10 05:02:13 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{2C5D2369-05C8-4720-B088-78D1B8DB9F44}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2011/12/08 00:24:58 | 004,331,784 | R— | M] (Swearware) – C:\ComboFix.exe


< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 04:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/14 04:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 04:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/04/14 04:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/14 04:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 04:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 187 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84

< End of report >

OTL Extras now:

OTL Extras logfile created on: 12/10/2011 10:05:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.49 Gb Total Physical Memory | 2.63 Gb Available Physical Memory | 75.23% Memory free
4.82 Gb Paging File | 4.29 Gb Available in Paging File | 89.05% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.61 Gb Total Space | 333.59 Gb Free Space | 89.53% Space Free | Partition Type: NTFS

Computer Name: OWNER-84FDF6F64 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htafile [open] – "%1" %*
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"ANTIVIRUSDISABLENOTIFY" = 0
"FIREWALLDISABLENOTIFY" = 0
"UPDATESDISABLENOTIFY" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ATT-HSI\McciBrowser.exe" = C:\Program Files\ATT-HSI\McciBrowser.exe:*:Enabled:motivebrowser.exe – (Motive Communications, Inc.)
"C:\Program Files\2X\Client\TSClient.exe" = C:\Program Files\2X\Client\TSClient.exe:*:Enabled:TSClient Application – (2X Software Ltd.)
"C:\Program Files\Windows Savevid Toolbar\Datamngr\ToolBar\dtUser.exe" = C:\Program Files\Windows Savevid Toolbar\Datamngr\ToolBar\dtUser.exe:*:Enabled:DTX broker – (Visicom Media Inc.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin – (Skype Limited)
"C:\Program Files\adawaretb\dtUser.exe" = C:\Program Files\adawaretb\dtUser.exe:*:Enabled:Ad-Aware Security Toolbar DTX Broker – (Visicom Media Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{385DD1DD-65AA-408D-8E70-74601C2DB7E6}" = Ad-Aware
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}" = MP3 Player Utilities 4.05
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981405}" = SaveVid Plug-in
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{932D0FC7-6DF1-4136-A2EC-166E8DEFD6A4}" = Ad-Aware
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A651161D-4D8C-435A-8637-6517D12D8151}" = 2X Client
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{ACEB2BAF-96DF-48FD-ADD5-43842D4C443D}" = Adobe AIR
"{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C35CCBEB-5A54-4DD8-9EC8-110F2A8154B3}" = Motorola Mobile Drivers Installation 5.1.0
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{D1E7142C-6BC3-49EB-A71A-E5D7ADAC7599}" = Nikon File Uploader 2
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{DDD62492-32A7-412B-8AF1-2CF032AD42E3}" = ViewNX 2
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}" = ArcSoft Panorama Maker 5
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.22beta
"adawaretb" = Ad-Aware Security Toolbar
"Adobe Acrobat Reader 3.01" = Adobe Acrobat Reader 3.01
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe Type Manager 4.0" = Adobe Type Manager 4.0
"Amazon Kindle" = Amazon Kindle
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.12
"ATT-SST" = AT&T Self Support Tool
"ATTToolbar" = AT&T Toolbar
"AVS Image Converter_is1" = AVS Image Converter [removed]
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"BitZipper_is1" = BitZipper 2010
"Browser Defender_is1" = Browser Defender 4.0
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dave Ramsey's Financial Peace Financial Software 5.45.4" = Dave Ramsey's Financial Peace Financial Software 5.4.1
"Dave Ramsey's Financial Peace Financial Software5.3" = Dave Ramsey's Financial Peace Financial Software
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"Google Updater" = Google Updater
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"InterActual Player" = InterActual Player
"Lexmark X1100 Series" = Lexmark X1100 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MotoHelper" = MotoHelper 2.0.51 Driver 5.1.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSS" = Norton Security Scan
"RadialpointClientGateway_is1" = AT&T Internet Security Wizard 1.5.11
"SaveVid Plug-in" = SaveVid Plug-in
"Searchqu 405 MediaBar" = Windows Savevid Toolbar
"SoyDominicano.NET Toolbar" = SoyDominicano.NET Toolbar
"Spyware Doctor" = PC Tools Spyware Doctor 9.0
"Trusted Software Assistant_is1" = File Type Assistant
"Tux Paint_is1" = Tux Paint 0.9.21
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! IE Suggest" = Yahoo! Search Suggest Add-on for IE7
"Yahoo! Mail" = AT&T Yahoo! Internet Mail
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/9/2011 12:28:11 AM | Computer Name = OWNER-84FDF6F64 | Source = JavaQuickStarterService | ID = 1
Description =

Error - 12/9/2011 12:28:25 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:28:52 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:29:36 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:29:59 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 1:05:14 AM | Computer Name = OWNER-84FDF6F64 | Source = Google Update | ID = 20
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5004
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5022
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5004
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5022
Description =

[ Application Events ]
Error - 12/9/2011 12:28:11 AM | Computer Name = OWNER-84FDF6F64 | Source = JavaQuickStarterService | ID = 1
Description =

Error - 12/9/2011 12:28:25 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:28:52 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:29:36 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:29:59 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 1:05:14 AM | Computer Name = OWNER-84FDF6F64 | Source = Google Update | ID = 20
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5004
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5022
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5004
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5022
Description =

[ Application Events ]
Error - 12/9/2011 12:28:11 AM | Computer Name = OWNER-84FDF6F64 | Source = JavaQuickStarterService | ID = 1
Description =

Error - 12/9/2011 12:28:25 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:28:52 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:29:36 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 12:29:59 AM | Computer Name = OWNER-84FDF6F64 | Source = Application Error | ID = 1000
Description = Faulting application MotoHelperService.exe, version 2.0.51.0, faulting
module MotoHelperService.exe, version 2.0.51.0, fault address 0x000054df.

Error - 12/9/2011 1:05:14 AM | Computer Name = OWNER-84FDF6F64 | Source = Google Update | ID = 20
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5004
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5022
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5004
Description =

Error - 12/9/2011 10:19:41 PM | Computer Name = OWNER-84FDF6F64 | Source = McLogEvent | ID = 5022
Description =

[ OSession Events ]
Error - 9/7/2011 3:15:57 AM | Computer Name = OWNER-84FDF6F64 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 21649
seconds with 1500 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 12/4/2011 12:55:21 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:55:23 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:55:26 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:55:27 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:56:30 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:19 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:34 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:47 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:55 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:57 AM | Computer Name = OWNER-84FDF6F64 | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

[ System Events ]
Error - 12/4/2011 12:55:21 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:55:23 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:55:26 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:55:27 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:56:30 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:19 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:34 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:47 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:55 AM | Computer Name = OWNER-84FDF6F64 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/4/2011 12:57:57 AM | Computer Name = OWNER-84FDF6F64 | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.


< End of report >

Again, Thanks so much!

Ann
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
    [2011/09/12 20:35:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchquband
    [2011/09/12 20:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchqutoolbar
    [2011/12/03 03:57:11 | 000,013,374 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\iecmrf5r3icp7iqw6puv2e758t1u
    [2011/12/03 03:57:11 | 000,013,374 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\iecmrf5r3icp7iqw6puv2e758t1u
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )





After doing the above,please let me know if there are any other problems,if not we can clean up the tools we have used.
Hey there, i think we're getting there! :clap: Here is the latest log, after following your instructions: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29}\ not found. C:\Documents and Settings\Owner\Application Data\searchquband folder moved successfully. C:\Documents and Settings\Owner\Application Data\searchqutoolbar\weather folder moved successfully. C:\Documents and Settings\Owner\Application Data\searchqutoolbar\coupons folder moved successfully. C:\Documents and Settings\Owner\Application Data\searchqutoolbar folder moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\iecmrf5r3icp7iqw6puv2e758t1u moved successfully. C:\Documents and Settings\All Users\Application Data\iecmrf5r3icp7iqw6puv2e758t1u moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56516 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 361695 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 618560 bytes ->Java cache emptied: 28 bytes ->Flash cache emptied: 5858 bytes User: Owner ->Temp folder emptied: 22631647 bytes ->Temporary Internet Files folder emptied: 24906410 bytes ->Java cache emptied: 15 bytes ->Flash cache emptied: 57673 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 3861137 bytes %systemroot%\System32 .tmp files removed: 3770897 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 41623 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 342406854 bytes Total Files Cleaned = 380.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 12102011_142517 Files\Folders moved on Reboot… C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UYI6B18G\view[1].html moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UYI6B18G\xframe-proxy_20110602[1].html moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UYI6B18G\yimapp[1].html moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QCEO9RXV\get[1].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QCEO9RXV\iframe[2].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QCEO9RXV\xframe-proxy_20110602[1].html moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\N62QR72O\01[1].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\N62QR72O\aceUAC[2].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\N62QR72O\controller[1].html moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\N62QR72O\launch[2].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\N62QR72O\plusone_gadget[1].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\D44G5X0Q\blank[2].html moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\D44G5X0Q\ext-render-secure[2].html moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\D44G5X0Q\fc[2].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\D44G5X0Q\index[1].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot… **************************** And so far, I haven't seen any other problems……….. so let me know what else we need to do to clean this up. You're awesome, and thank you for helping me! Ann
You appear clean of infections,please do the following.


Delete TDSSKiller,ESET and any logs you have.




ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.












[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 and save it to your desktop.
  • Scroll down to where it says JDK 7 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 7 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI