This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

High CPU usage, Ping.exe, browsers redirect [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Please run the following:

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
HI, I've run the scans as requested, files are attached. Pasting the files into the post didn't work last time, hence why I've attached them. Also, I don't have Winzip, and now I can't get it to install, so I had to put the .dat file in a zip folder. I hope this works.
Hi,

Please do the following:


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=121493

Collect::
c:\windows\system32\6Pj82B.com

AtJob::

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16509:UDP"=-
"12234:TCP"=-
"24512:UDP"=-
"19667:TCP"=-
ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save Asโ€ฆ Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save โ€ฆ

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <โ€“ very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Combofix file attached. Other logs below. MBAM log - Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8351 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 11/12/2011 5:05:30 PM mbam-log-2011-12-11 (17-05-30).txt Scan type: Quick scan Objects scanned: 221400 Time elapsed: 7 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSCAN log - C:\Documents and Settings\Jolene\Local Settings\Temp\081808202513\z4barSpInstall.exe a variant of Win32/AdInstaller application C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.7.2356.exe Win32/OpenCandy application C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.7.2423.exe Win32/OpenCandy application C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2474.exe Win32/OpenCandy application C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2523.exe Win32/OpenCandy application C:\Documents and Settings\Scotty\Desktop\winzip160.exe Win32/OpenCandy application C:\Qoobox\Quarantine\[4]-Submit_2011-12-11_15.38.35.zip a variant of Win32/Kryptik.WXT trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\gPVFPXyb.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\gPVFPXyb.ini2.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\oYFedfii.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\oYFedfii.ini2.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\ssrYaccf.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\ssrYaccf.ini2.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\stELkUtv.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\stELkUtv.ini2.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\TBIRCcdd.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\TBIRCcdd.ini2.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\WFLUvyay.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\WFLUvyay.ini2.vir Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP232\A0075143.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP233\A0076143.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP233\A0077143.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP233\A0077164.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP234\A0077176.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP234\A0078176.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP234\A0079176.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP234\A0080176.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP234\A0080190.sys a variant of Win32/Rootkit.Kryptik.FW trojan C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP235\A0080250.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP235\A0080251.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP235\A0080252.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP235\A0080253.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP235\A0080254.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{FF4E0ABF-23FC-4265-80BE-F35329A93E84}\RP235\A0080255.ini Win32/Adware.Virtumonde.NEO application
Hi

We need to give that another try,

please make certain your security programs are disabled so they don't interfere with the fix

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::

AtJob::

File::
c:\windows\system32\6Pj82B.com
C:\Documents and Settings\Jolene\Local Settings\Temp\081808202513\z4barSpInstall.exe
C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.7.2356.exe 
C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.7.2423.exe 
C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2474.exe 
C:\Documents and Settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2523.exe 
C:\Documents and Settings\Scotty\Desktop\winzip160.exe 

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save Asโ€ฆ Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save โ€ฆ

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please advise how the computer is running now and if there are any outstanding issues
I'm having trouble shutting down my antivirus scanner. I have Symantec Antivirus Corporate Edition, and there's no shield symbol down the bottom right of screen to close. If I open the antivirus software, there doesn't seem to be an option to close the live scanning. I tried running msconfig, and un-checked the only Symantec file I could see running at start up, but Combofix still said it was running.

Anyway, I ran Combofix and the log is below. Ping.exe has not reared its ugly head for a since I ran Combofix the first time, and the random browser page opening has stopped. But I do get a popup saying I'm entering a secure website, then another saying I'm leaving a secure website, quite often.


ComboFix 11-12-11.02 - Scotty 12/12/2011 8:35.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.627 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Scotty\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: ZoneAlarm Free Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
FILE ::
"c:\documents and settings\Jolene\Local Settings\Temp\081808202513\z4barSpInstall.exe"
"c:\documents and settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.7.2356.exe"
"c:\documents and settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.7.2423.exe"
"c:\documents and settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2474.exe"
"c:\documents and settings\Jolene\Local Settings\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2523.exe"
"c:\documents and settings\Scotty\Desktop\winzip160.exe"
"c:\windows\system32\6Pj82B.com"
.
.
((((((((((((((((((((((((( Files Created from 2011-11-11 to 2011-12-11 )))))))))))))))))))))))))))))))
.
.
2011-12-11 07:47 . 2011-12-11 07:47 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\ESET
2011-12-11 06:57 . 2011-12-11 06:57 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Scotty\Application Data\Malwarebytes
2011-12-11 06:57 . 2011-12-11 06:57 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-11 06:57 . 2011-12-11 06:57 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware
2011-12-11 06:57 . 2011-08-31 07:00 22216 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-08 13:09 . 2011-12-08 13:09 32256 โ€”-a-w- c:\windows\system32\6Pj82B.com
2011-11-28 00:09 . 2011-11-28 00:09 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\iPod
2011-11-22 12:11 . 2011-12-10 22:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\Internet Logs
2011-11-22 12:09 . 2011-12-05 11:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\ZoneAlarm_Security
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 23:10 . 2004-08-03 13:14 162816 โ€”-a-w- c:\windows\system32\drivers\netbt.sys
2011-10-10 14:22 . 2008-02-02 00:52 692736 โ€”-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-03 14:56 599040 โ€”-a-w- c:\windows\system32\crypt32.dll
2011-09-26 01:41 . 2008-07-29 09:59 611328 โ€”-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 01:41 . 2001-08-18 12:00 220160 โ€”-a-w- c:\windows\system32\oleacc.dll
2011-09-26 01:41 . 2001-08-18 12:00 20480 โ€”-a-w- c:\windows\system32\oleaccrc.dll
1997-07-22 02:30 1045776 -csha-w- c:\windows\system32\Msjet35.dll
1997-06-23 10:00 123664 -csha-w- c:\windows\system32\Msjint35.dll
1997-06-23 19:06 24848 -csha-w- c:\windows\system32\Msjter35.dll
1997-06-23 19:06 252176 -csha-w- c:\windows\system32\Msrd2x35.dll
1997-06-23 19:06 287504 -csha-w- c:\windows\system32\Msxbse35.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-11_00.50.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-11 22:49 . 2009-04-30 06:01 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
- 2011-12-11 00:34 . 2009-04-30 06:01 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZon2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2011-05-09 09:49 176936 โ€”-a-w- c:\program files\ZoneAlarm_Security\prxtbZon2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZon2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}"= "c:\program files\ZoneAlarm_Security\prxtbZon2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.17\AsRunHelp.exe" [2006-11-13 363008]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-26 59240]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-11-03 738944]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-09 73360]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AutoLaunch"="c:\program files\Lavasoft\Ad-Aware\AutoLaunch.exe" [2011-06-09 669936]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
2011-06-09 12:02 528832 โ€”-a-w- c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-14 15:04 39792 โ€”-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 02:48 58656 โ€”-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-23 08:05 143360 โ€”-a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2007-03-12 04:51 663552 -cโ€”-w- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2006-07-19 09:26 52896 โ€”-a-w- c:\program files\Common Files\Symantec Shared\ccApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2007-01-26 05:58 65536 -cโ€”-w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
2011-06-21 21:18 225280 -cโ€“a-w- c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2007-01-29 11:10 46632 -cโ€“a-w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-11-12 14:24 421736 โ€”-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-05-08 00:35 2780432 โ€”-a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 12:12 3872080 โ€”-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2005-12-14 06:51 7323648 โ€”-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2005-12-14 06:51 86016 -cโ€“a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2005-12-14 06:51 1519616 -cโ€“a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2007-01-29 11:12 30248 -cโ€“a-w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 08:36 421888 โ€”-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-09-22 03:36 14854144 -cโ€“a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-24 23:03 210472 -cโ€“a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-11-09 13:34 32881 -cโ€“a-w- c:\program files\Java\j2re1.4.2_19\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2006-09-27 10:33 125168 -cโ€“a-w- c:\progra~1\SYMANT~1\VPTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16/04/2009 10:02 PM 64160]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [4/11/2011 12:44 AM 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [4/11/2011 12:44 AM 497280]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [10/03/2009 5:06 AM 1036104]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/11/2011 4:42 PM 106104]
S2 gupdate1ca91239e0cc3c0;Google Update Service (gupdate1ca91239e0cc3c0);c:\program files\Google\Update\GoogleUpdate.exe [9/01/2010 10:02 PM 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/01/2010 10:02 PM 133104]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 10:49 PM 227232]
S3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [24/02/2008 9:13 AM 513152]
S3 MusCVideo32;MusCVideo32;c:\windows\system32\drivers\MusCVideo32.sys [24/02/2008 9:13 AM 3768]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [9/02/2008 10:09 AM 47360]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/09/2006 8:33 PM 116464]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 12:02]
.
2011-11-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 07:57]
.
2011-12-08 c:\windows\Tasks\At1.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At11.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At13.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At15.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-09 c:\windows\Tasks\At17.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-09 c:\windows\Tasks\At19.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At21.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At23.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At25.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At27.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At29.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At3.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-10 c:\windows\Tasks\At31.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At33.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At35.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At37.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At39.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\At41.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At43.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At45.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-09 c:\windows\Tasks\At47.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At5.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At7.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-08 c:\windows\Tasks\At9.job
- c:\windows\system32\6Pj82B.com [2011-12-08 13:09]
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-09 12:02]
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-09 12:02]
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
uStart Page = hxxp://www.google.com.au/
mStart Page = hxxp://search.myheritage.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-12 08:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes โ€ฆ
.
scanning hidden autostart entries โ€ฆ
.
scanning hidden files โ€ฆ
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” DLLs Loaded Under Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
- - - - - - - > 'winlogon.exe'(756)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(812)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(2632)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2011-12-12 09:01:49 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-11 23:01
ComboFix2.txt 2011-12-11 06:41
.
Pre-Run: 84,870,152,192 bytes free
Post-Run: 84,879,069,184 bytes free
.
- - End Of File - - 56BE64D153F25295495718BA5CD55994
There is a stubborn file that is refusing to delete, let's try a different tool

Please do the following:

1. Please download The Avenger2 by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract Allโ€ฆ"
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Begin copying here:

Files to delete:
c:\windows\Tasks\At1.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At25.job
c:\windows\Tasks\At27.job
c:\windows\Tasks\At29.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At31.job
c:\windows\Tasks\At33.job
c:\windows\Tasks\At35.job
c:\windows\Tasks\At37.job
c:\windows\Tasks\At39.job
c:\windows\Tasks\At41.job
c:\windows\Tasks\At43.job
c:\windows\Tasks\At45.job
c:\windows\Tasks\At47.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At7.job
c:\windows\system32\6Pj82B.com 
c:\windows\Tasks\At9.job

Note: the above code was created specifically for this user.  If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the Avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V), or click on the third button under the menu to paste it from the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete" or "Drivers to Disable", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avengerโ€™s actions.  This log file will be located at  C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply



NEXT


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
I couldn't find the Extras file for some reason. Would it be different to the one in my first post?

Logfile of The Avenger Version 2.0, ยฉ by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "c:\windows\Tasks\At1.job" deleted successfully.
File "c:\windows\Tasks\At11.job" deleted successfully.
File "c:\windows\Tasks\At13.job" deleted successfully.
File "c:\windows\Tasks\At15.job" deleted successfully.
File "c:\windows\Tasks\At17.job" deleted successfully.
File "c:\windows\Tasks\At19.job" deleted successfully.
File "c:\windows\Tasks\At21.job" deleted successfully.
File "c:\windows\Tasks\At23.job" deleted successfully.
File "c:\windows\Tasks\At25.job" deleted successfully.
File "c:\windows\Tasks\At27.job" deleted successfully.
File "c:\windows\Tasks\At29.job" deleted successfully.
File "c:\windows\Tasks\At3.job" deleted successfully.
File "c:\windows\Tasks\At31.job" deleted successfully.
File "c:\windows\Tasks\At33.job" deleted successfully.
File "c:\windows\Tasks\At35.job" deleted successfully.
File "c:\windows\Tasks\At37.job" deleted successfully.
File "c:\windows\Tasks\At39.job" deleted successfully.
File "c:\windows\Tasks\At41.job" deleted successfully.
File "c:\windows\Tasks\At43.job" deleted successfully.
File "c:\windows\Tasks\At45.job" deleted successfully.
File "c:\windows\Tasks\At47.job" deleted successfully.
File "c:\windows\Tasks\At5.job" deleted successfully.
File "c:\windows\Tasks\At7.job" deleted successfully.
File "c:\windows\system32\6Pj82B.com" deleted successfully.
File "c:\windows\Tasks\At9.job" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.


OTL logfile created on: 12/12/2011 1:08:09 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Scotty\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1023.17 Mb Total Physical Memory | 524.50 Mb Available Physical Memory | 51.26% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.30% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 117.19 Gb Total Space | 79.05 Gb Free Space | 67.46% Space Free | Partition Type: NTFS
Drive D: | 115.69 Gb Total Space | 23.46 Gb Free Space | 20.28% Space Free | Partition Type: NTFS
Drive E: | 4.38 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: SCOTT | User Name: Scotty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Scotty\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\Resources.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\unrar.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Adobe\Reader 8.0\Reader\ViewerPS.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) โ€“ File not found
SRV - (vsmon) โ€“ C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) โ€“ C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (Lavasoft Ad-Aware Service) โ€“ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (getPlusHelper) getPlusยฎ โ€“ C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (McComponentHostService) โ€“ C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Autodesk Licensing Service) โ€“ C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (NMSAccessU) โ€“ C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (LVPrcSrv) โ€“ C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (ServiceLayer) โ€“ C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SavRoam) โ€“ C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) โ€“ C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) โ€“ C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (LiveUpdate) โ€“ C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE (Symantec Corporation)
SRV - (SNDSrvc) โ€“ C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) โ€“ C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SPBBCSvc) โ€“ C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (ATKKeyboardService) โ€“ C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) โ€“ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111210.007\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) โ€“ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111210.007\NAVENG.SYS (Symantec Corporation)
DRV - (Vsdatant) โ€“ C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (eeCtrl) โ€“ C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) โ€“ C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (ISWKL) โ€“ C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (StarOpen) โ€“ C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (FilterService) โ€“ C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech Webcam 300(UVC) โ€“ C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) โ€“ C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (lvpopflt) โ€“ C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) โ€“ C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (Lbd) โ€“ C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MusCDriverV32) โ€“ C:\WINDOWS\system32\drivers\MusCDriverV32.sys (Windows ยฎ 2000/XP)
DRV - (MusCVideo32) โ€“ C:\WINDOWS\system32\drivers\MusCVideo32.sys (Windows ยฎ 2000 DDK provider)
DRV - (AtcL002) โ€“ C:\WINDOWS\system32\drivers\l251x86.sys (Atheros Communications)
DRV - (AsIO) โ€“ C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (SymEvent) โ€“ C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SAVRT) โ€“ C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) โ€“ C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SYMTDI) โ€“ C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) โ€“ C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) โ€“ C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (AgereSoftModem) โ€“ C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (EIO) โ€“ C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (asuskbnt) โ€“ C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) โ€“ C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (MTsensor) โ€“ C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (CYGF32X) โ€“ C:\WINDOWS\system32\drivers\CygF32x.sys (Cygnal Integrated Products)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-839522115-1647877149-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKU\S-1-5-21-839522115-1647877149-682003330-1003\..\URLSearchHook: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-839522115-1647877149-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/11/22 22:09:13 | 000,000,000 | โ€”D | M]


O1 HOSTS File: ([2011/12/12 08:54:42 | 000,000,027 | โ€”- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\S-1-5-21-839522115-1647877149-682003330-1003\..\Toolbar\WebBrowser: (ZoneAlarm Security Toolbar) - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-839522115-1647877149-682003330-1003\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe ()
O4 - HKLM..\Run: [ISW] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKU\.DEFAULT..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O4 - HKU\S-1-5-18..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-839522115-1647877149-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-839522115-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-839522115-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-839522115-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1โ€ฆtoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Faceboโ€ฆtoUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.fujifilmimagine.com/imagine/ax/ImageUploader5.cab (Image Uploader Control)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} http://www.myheritage.com/Genoogle/Componeโ€ฆEngineQuery.dll (CSEQueryObject Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0โ€ฆoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.4.2/jinโ€ฆindows-i586.cab (Java Plug-in 1.4.2_19)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A2505C6C-6F17-456F-89D2-4301FBDC6EC7} https://pbshares.pbworldnet.com/nortel_cacheable/iewiper.cab (Iewiper Control)
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} http://www.trendsecure.com/easy_install/_aโ€ฆasyInstallX.CAB (TSEasyInstallX Control)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messeโ€ฆnt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodlโ€ฆindows-i586.cab (Java Plug-in 1.4.2_19)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shocโ€ฆash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Faceboโ€ฆUploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photoโ€ฆol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://remote.pb.com.au/dana-cached/sc/Junโ€ฆSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BFB488A4-E8AF-42D6-9416-CACC1EBFFF01}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Scotty\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/02 10:54:04 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = ComFile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/12 10:21:28 | 000,000,000 | โ€”D | C] โ€“ C:\Avenger
[2011/12/12 09:12:24 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Scotty\Application Data\Juniper Networks
[2011/12/11 17:47:19 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\ESET
[2011/12/11 16:57:24 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Scotty\Application Data\Malwarebytes
[2011/12/11 16:57:07 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/11 16:57:06 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/12/11 16:57:02 | 000,022,216 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/11 16:57:02 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Malwarebytes' Anti-Malware
[2011/12/11 16:56:01 | 009,852,544 | โ€”- | C] (Malwarebytes Corporation ) โ€“ C:\Documents and Settings\Scotty\Desktop\mbam-setup-1.51.2.1300.exe
[2011/12/11 09:49:22 | 000,000,000 | RHSD | C] โ€“ C:\cmdcons
[2011/12/11 09:26:51 | 000,518,144 | โ€”- | C] (SteelWerX) โ€“ C:\WINDOWS\SWREG.exe
[2011/12/11 09:26:51 | 000,406,528 | โ€”- | C] (SteelWerX) โ€“ C:\WINDOWS\SWSC.exe
[2011/12/11 09:26:51 | 000,212,480 | โ€”- | C] (SteelWerX) โ€“ C:\WINDOWS\SWXCACLS.exe
[2011/12/11 09:26:51 | 000,060,416 | โ€”- | C] (NirSoft) โ€“ C:\WINDOWS\NIRCMD.exe
[2011/12/11 09:26:38 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\ERDNT
[2011/12/11 09:22:38 | 000,000,000 | โ€”D | C] โ€“ C:\Qoobox
[2011/12/11 09:21:08 | 004,337,036 | Rโ€” | C] (Swearware) โ€“ C:\Documents and Settings\Scotty\Desktop\ComboFix.exe
[2011/12/11 09:08:07 | 001,577,776 | โ€”- | C] (Kaspersky Lab ZAO) โ€“ C:\Documents and Settings\Scotty\Desktop\TDSSKiller.exe
[2011/12/10 08:36:31 | 001,916,416 | โ€”- | C] (AVAST Software) โ€“ C:\Documents and Settings\Scotty\Desktop\aswMBR.exe
[2011/12/09 19:49:06 | 000,584,192 | โ€”- | C] (OldTimer Tools) โ€“ C:\Documents and Settings\Scotty\Desktop\OTL.exe
[2011/12/08 23:44:15 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/08 19:11:31 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/08 19:11:26 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/28 10:13:55 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/11/28 10:09:55 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\iPod
[2011/11/28 09:53:03 | 000,000,000 | โ€”D | C] โ€“ C:\Config.Msi
[2011/11/22 22:11:57 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\Internet Logs
[2011/11/22 22:09:02 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\ZoneAlarm_Security
[2011/11/22 22:08:16 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Check Point
[2008/02/09 10:09:22 | 000,047,360 | โ€”- | C] (VSO Software) โ€“ C:\Documents and Settings\Scotty\Application Data\pcouffin.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/12 12:56:01 | 000,000,886 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/12 10:31:27 | 000,002,206 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2011/12/12 10:31:22 | 000,000,882 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/12 10:22:06 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2011/12/12 10:20:12 | 000,135,168 | โ€”- | M] () โ€“ C:\zip.exe
[2011/12/12 10:20:12 | 000,019,286 | โ€”- | M] () โ€“ C:\cleanup.exe
[2011/12/12 10:20:12 | 000,000,574 | โ€”- | M] () โ€“ C:\cleanup.bat
[2011/12/12 10:18:45 | 000,724,952 | โ€”- | M] () โ€“ C:\Documents and Settings\Scotty\Desktop\avenger.zip
[2011/12/12 09:29:14 | 000,000,327 | RHS- | M] () โ€“ C:\boot.ini
[2011/12/12 08:54:42 | 000,000,027 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/12 08:26:25 | 004,337,036 | Rโ€” | M] (Swearware) โ€“ C:\Documents and Settings\Scotty\Desktop\ComboFix.exe
[2011/12/11 16:57:09 | 000,000,784 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/11 16:56:01 | 009,852,544 | โ€”- | M] (Malwarebytes Corporation ) โ€“ C:\Documents and Settings\Scotty\Desktop\mbam-setup-1.51.2.1300.exe
[2011/12/11 11:39:32 | 000,000,069 | โ€”- | M] () โ€“ C:\WINDOWS\NeroDigital.ini
[2011/12/11 09:09:44 | 000,000,664 | โ€”- | M] () โ€“ C:\WINDOWS\System32\d3d9caps.dat
[2011/12/11 09:06:31 | 001,557,928 | โ€”- | M] () โ€“ C:\Documents and Settings\Scotty\Desktop\tdsskiller.zip
[2011/12/10 16:52:40 | 000,000,511 | โ€”- | M] () โ€“ C:\Documents and Settings\Scotty\Desktop\MBR.zip
[2011/12/10 16:50:14 | 000,053,760 | โ€”- | M] () โ€“ C:\Documents and Settings\Scotty\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/10 14:14:44 | 054,703,432 | โ€”- | M] () โ€“ C:\Documents and Settings\Scotty\Desktop\winzip160.exe
[2011/12/10 09:36:46 | 000,000,512 | โ€”- | M] () โ€“ C:\Documents and Settings\Scotty\Desktop\MBR.dat
[2011/12/10 08:36:31 | 001,916,416 | โ€”- | M] (AVAST Software) โ€“ C:\Documents and Settings\Scotty\Desktop\aswMBR.exe
[2011/12/09 19:49:07 | 000,584,192 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Scotty\Desktop\OTL.exe
[2011/12/08 23:09:23 | 000,000,000 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Application Data\I03I1M7LM.dat
[2011/12/08 22:02:29 | 000,000,472 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/12/07 13:22:02 | 001,577,776 | โ€”- | M] (Kaspersky Lab ZAO) โ€“ C:\Documents and Settings\Scotty\Desktop\TDSSKiller.exe
[2011/11/30 20:21:25 | 000,000,211 | โ€”- | M] () โ€“ C:\Boot.bak
[2011/11/28 20:08:47 | 000,415,916 | โ€”- | M] () โ€“ C:\WINDOWS\System32\vsconfig.xml
[2011/11/28 10:13:56 | 000,001,542 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/11/22 09:57:51 | 000,001,813 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/12 10:20:12 | 000,135,168 | โ€”- | C] () โ€“ C:\zip.exe
[2011/12/12 10:20:12 | 000,019,286 | โ€”- | C] () โ€“ C:\cleanup.exe
[2011/12/12 10:20:12 | 000,000,574 | โ€”- | C] () โ€“ C:\cleanup.bat
[2011/12/12 10:19:04 | 000,731,136 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Desktop\avenger.exe
[2011/12/12 10:18:38 | 000,724,952 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Desktop\avenger.zip
[2011/12/11 16:57:08 | 000,000,784 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/11 09:49:32 | 000,000,211 | โ€”- | C] () โ€“ C:\Boot.bak
[2011/12/11 09:49:25 | 000,260,272 | RHS- | C] () โ€“ C:\cmldr
[2011/12/11 09:26:51 | 000,256,000 | โ€”- | C] () โ€“ C:\WINDOWS\PEV.exe
[2011/12/11 09:26:51 | 000,208,896 | โ€”- | C] () โ€“ C:\WINDOWS\MBR.exe
[2011/12/11 09:26:51 | 000,098,816 | โ€”- | C] () โ€“ C:\WINDOWS\sed.exe
[2011/12/11 09:26:51 | 000,080,412 | โ€”- | C] () โ€“ C:\WINDOWS\grep.exe
[2011/12/11 09:26:51 | 000,068,096 | โ€”- | C] () โ€“ C:\WINDOWS\zip.exe
[2011/12/11 09:06:19 | 001,557,928 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Desktop\tdsskiller.zip
[2011/12/10 16:52:40 | 000,000,511 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Desktop\MBR.zip
[2011/12/10 14:14:33 | 054,703,432 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Desktop\winzip160.exe
[2011/12/10 09:36:46 | 000,000,512 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Desktop\MBR.dat
[2011/12/08 23:09:23 | 000,000,000 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\I03I1M7LM.dat
[2011/11/28 10:13:56 | 000,001,542 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/11/22 22:11:42 | 000,415,916 | โ€”- | C] () โ€“ C:\WINDOWS\System32\vsconfig.xml
[2011/03/11 18:26:11 | 000,000,022 | -HS- | C] () โ€“ C:\Documents and Settings\Scotty\Application Data\Sys2662.Config.Repository.bin
[2010/11/14 17:08:14 | 000,001,907 | โ€”- | C] () โ€“ C:\WINDOWS\PAScreen.ini
[2010/11/14 17:05:57 | 000,000,652 | โ€”- | C] () โ€“ C:\WINDOWS\bsc.ini
[2010/11/14 17:05:44 | 000,068,096 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lfplt11n.dll
[2010/11/14 17:05:43 | 000,118,784 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Lfkodak.dll
[2010/10/23 22:48:08 | 000,203,424 | โ€”- | C] () โ€“ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/19 19:58:00 | 000,082,289 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\lvcoinst.ini
[2010/08/08 17:59:07 | 000,000,323 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Local Settings\Application Data\CastleLinkProps.dat
[2010/05/09 08:57:34 | 000,000,520 | โ€”- | C] () โ€“ C:\WINDOWS\Viewer.INI
[2010/03/04 06:52:53 | 000,000,664 | โ€”- | C] () โ€“ C:\WINDOWS\System32\d3d9caps.dat
[2010/01/10 08:34:58 | 000,000,056 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\ezsidmv.dat
[2009/12/17 06:42:24 | 000,077,448 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\mlfcache.dat
[2009/10/05 12:52:42 | 000,007,168 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/08/03 15:07:42 | 000,403,816 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGAEXEC.exe
[2009/05/10 22:44:02 | 000,045,163 | โ€”- | C] () โ€“ C:\WINDOWS\System32\javaw.exe
[2009/05/10 22:44:02 | 000,045,161 | โ€”- | C] () โ€“ C:\WINDOWS\System32\java.exe
[2009/05/08 10:13:04 | 000,013,584 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/04/30 16:00:12 | 000,025,624 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/04/18 12:29:59 | 000,015,880 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lsdelete.exe
[2008/10/13 16:57:41 | 000,000,028 | โ€”- | C] () โ€“ C:\WINDOWS\ODBC.INI
[2008/06/08 21:55:31 | 000,001,558 | โ€”- | C] () โ€“ C:\WINDOWS\MyHeritage.INI
[2008/06/08 21:55:07 | 000,454,656 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PaintX.dll
[2008/04/25 15:44:27 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\VPC32.INI
[2008/04/20 18:54:26 | 000,000,327 | โ€”- | C] () โ€“ C:\WINDOWS\wininit.ini
[2008/03/30 17:23:35 | 000,000,213 | โ€”- | C] () โ€“ C:\WINDOWS\Brpfx04a.ini
[2008/03/30 17:23:35 | 000,000,094 | โ€”- | C] () โ€“ C:\WINDOWS\brpcfx.ini
[2008/03/30 17:23:35 | 000,000,050 | โ€”- | C] () โ€“ C:\WINDOWS\System32\bridf07a.dat
[2008/03/30 17:22:34 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\brdfxspd.dat
[2008/03/30 17:21:16 | 000,031,567 | โ€”- | C] () โ€“ C:\WINDOWS\maxlink.ini
[2008/03/30 17:19:13 | 000,000,425 | โ€”- | C] () โ€“ C:\WINDOWS\BRWMARK.INI
[2008/03/30 17:19:13 | 000,000,027 | โ€”- | C] () โ€“ C:\WINDOWS\BRPP2KA.INI
[2008/02/09 12:40:29 | 000,000,069 | โ€”- | C] () โ€“ C:\WINDOWS\NeroDigital.ini
[2008/02/09 10:52:23 | 000,053,760 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/09 10:09:22 | 000,007,887 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Application Data\pcouffin.cat
[2008/02/09 10:09:22 | 000,001,144 | โ€”- | C] () โ€“ C:\Documents and Settings\Scotty\Application Data\pcouffin.inf
[2008/02/04 19:18:29 | 000,044,544 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Gif89.dll
[2008/02/02 20:42:53 | 000,004,161 | โ€”- | C] () โ€“ C:\WINDOWS\ODBCINST.INI
[2008/02/02 20:42:02 | 000,351,384 | โ€”- | C] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2008/02/02 11:32:06 | 000,010,496 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ATKOSDMini.DLL
[2008/02/02 11:32:06 | 000,000,018 | โ€”- | C] () โ€“ C:\WINDOWS\System32\atkid.ini
[2008/02/02 11:32:05 | 000,046,592 | โ€”- | C] () โ€“ C:\WINDOWS\System32\asfrench.dll
[2008/02/02 11:32:05 | 000,046,080 | โ€”- | C] () โ€“ C:\WINDOWS\System32\asrussian.dll
[2008/02/02 11:32:05 | 000,046,080 | โ€”- | C] () โ€“ C:\WINDOWS\System32\asgerman.dll
[2008/02/02 11:32:05 | 000,046,080 | โ€”- | C] () โ€“ C:\WINDOWS\System32\aseng.dll
[2008/02/02 11:32:05 | 000,045,568 | โ€”- | C] () โ€“ C:\WINDOWS\System32\askorean.dll
[2008/02/02 11:32:05 | 000,045,568 | โ€”- | C] () โ€“ C:\WINDOWS\System32\asjapan.dll
[2008/02/02 11:32:05 | 000,045,568 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ASCHT.dll
[2008/02/02 11:32:05 | 000,045,568 | โ€”- | C] () โ€“ C:\WINDOWS\System32\aschs.dll
[2008/02/02 11:28:26 | 000,024,576 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\AsIO.dll
[2008/02/02 11:28:26 | 000,012,664 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\drivers\AsIO.sys
[2008/02/02 11:28:24 | 000,012,096 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2008/02/02 11:28:24 | 000,010,304 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2008/02/02 11:21:05 | 000,010,051 | โ€”- | C] () โ€“ C:\WINDOWS\Ascd_tmp.ini
[2008/02/02 11:21:05 | 000,005,810 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/02/02 11:20:57 | 000,010,288 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/02 10:55:45 | 000,002,048 | โ€“S- | C] () โ€“ C:\WINDOWS\bootstat.dat
[2008/02/02 10:51:48 | 000,021,640 | โ€”- | C] () โ€“ C:\WINDOWS\System32\emptyregdb.dat
[2006/08/23 19:33:46 | 000,006,144 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ff_vfw.dll
[2006/02/25 21:12:34 | 000,180,224 | โ€”- | C] () โ€“ C:\WINDOWS\System32\xvidvfw.dll
[2006/02/25 21:09:38 | 000,774,144 | โ€”- | C] () โ€“ C:\WINDOWS\System32\xvidcore.dll
[2005/12/14 16:51:00 | 001,662,976 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvwdmcpl.dll
[2005/12/14 16:51:00 | 001,519,616 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nwiz.exe
[2005/12/14 16:51:00 | 001,466,368 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nview.dll
[2005/12/14 16:51:00 | 001,339,392 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvdspsch.exe
[2005/12/14 16:51:00 | 001,019,904 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvwimg.dll
[2005/12/14 16:51:00 | 000,573,440 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvhwvid.dll
[2005/12/14 16:51:00 | 000,466,944 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvshell.dll
[2005/12/14 16:51:00 | 000,442,368 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvappbar.exe
[2005/12/14 16:51:00 | 000,425,984 | โ€”- | C] () โ€“ C:\WINDOWS\System32\keystone.exe
[2005/12/14 16:51:00 | 000,286,720 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvnt4cpl.dll
[2005/12/14 16:51:00 | 000,090,112 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvapi.dll
[2004/08/04 01:07:22 | 000,001,804 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | โ€”- | C] () โ€“ C:\WINDOWS\System32\secupd.dat
[2002/11/19 02:02:58 | 000,040,960 | โ€”- | C] () โ€“ C:\WINDOWS\System32\MMAVILNG.exe
[2002/11/15 23:11:28 | 000,077,824 | โ€”- | C] () โ€“ C:\WINDOWS\System32\MMSwitch.dll
[2002/10/07 05:42:58 | 000,237,568 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OggDS.dll
[2002/10/05 10:04:26 | 000,921,600 | โ€”- | C] () โ€“ C:\WINDOWS\System32\vorbisenc.dll
[2002/10/05 10:04:26 | 000,188,416 | โ€”- | C] () โ€“ C:\WINDOWS\System32\VORBIS.DLL
[2002/10/05 10:04:18 | 000,045,056 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGG.DLL
[2001/08/23 22:00:00 | 013,107,200 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.bin
[2001/08/23 22:00:00 | 000,004,463 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.dat
[2001/08/18 22:00:00 | 000,673,088 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mlang.dat
[2001/08/18 22:00:00 | 000,436,012 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2001/08/18 22:00:00 | 000,272,128 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfi009.dat
[2001/08/18 22:00:00 | 000,218,003 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dssec.dat
[2001/08/18 22:00:00 | 000,068,782 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2001/08/18 22:00:00 | 000,046,258 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mib.bin
[2001/08/18 22:00:00 | 000,028,626 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfd009.dat
[2001/08/18 22:00:00 | 000,000,741 | โ€”- | C] () โ€“ C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2009/12/03 21:47:16 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Autodesk
[2011/03/20 12:43:18 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/06/11 11:06:28 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\CheckPoint
[2011/06/11 13:09:11 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2008/02/09 12:36:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/01/01 13:06:14 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\MyHeritage
[2008/03/16 18:33:29 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Nokia
[2008/03/16 18:11:15 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\PC Suite
[2008/03/30 17:21:16 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/03/29 21:49:26 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/05/18 19:00:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/05 20:46:53 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/16 21:00:04 | 000,000,000 | -H-D | M] โ€“ C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/06/11 20:24:40 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/09/02 20:41:40 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\Canneverbe Limited
[2010/01/31 16:07:57 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\Canneverbe_Limited
[2011/06/15 16:04:21 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\CheckPoint
[2010/08/19 19:58:55 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\Leadertech
[2011/06/18 16:38:42 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\MailFrontier
[2011/07/23 16:53:01 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\MyHeritage
[2008/03/16 18:48:27 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\Nokia
[2008/03/19 18:00:11 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\Nokia Multimedia Player
[2008/03/22 09:31:30 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\NSeries
[2008/03/22 09:31:38 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\PC Suite
[2011/11/03 12:45:30 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\PhotobookShop.com.au
[2009/12/28 19:17:51 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\ScanSoft
[2008/06/08 21:55:06 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\The Complete Genealogy Reporter - FTB
[2011/04/10 18:18:21 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Jolene\Application Data\uTorrent
[2009/12/03 21:47:16 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Autodesk
[2008/04/25 14:26:45 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\AVGTOOLBAR
[2010/02/06 16:56:00 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Canneverbe Limited
[2009/10/05 12:53:29 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Canneverbe_Limited
[2011/06/11 11:10:11 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\CheckPoint
[2011/11/02 23:11:49 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Galu
[2008/05/10 21:06:24 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\iolo
[2011/12/12 09:12:24 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Juniper Networks
[2011/06/11 12:16:53 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\MailFrontier
[2011/06/01 19:44:04 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\MyHeritage
[2008/03/16 19:34:19 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Nokia
[2008/03/16 19:34:03 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\PC Suite
[2009/02/19 06:46:29 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\ScanSoft
[2011/12/10 16:27:40 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\uTorrent
[2008/08/16 11:06:04 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\vghd
[2008/05/08 22:33:58 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Vso
[2011/11/05 17:44:48 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Scotty\Application Data\Xyyq
[2011/07/02 13:17:38 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Visitor\Application Data\CheckPoint
[2010/09/19 21:33:46 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Visitor\Application Data\PC Suite
[2011/12/08 22:02:29 | 000,000,472 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2011/12/12 10:20:12 | 000,019,286 | โ€”- | M] () โ€“ C:\cleanup.exe
[2011/12/12 10:20:12 | 000,135,168 | โ€”- | M] () โ€“ C:\zip.exe


< MD5 for: EXPLORER.EXE >
[2008/04/14 10:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 10:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\explorer.exe
[2008/04/14 10:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 10:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2007/06/13 21:26:03 | 001,033,216 | โ€”- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 โ€“ C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 20:23:07 | 001,033,216 | โ€”- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 โ€“ C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 00:56:50 | 001,032,192 | โ€”- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 โ€“ C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 10:12:36 | 000,014,336 | โ€”- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 โ€“ C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/14 10:12:36 | 000,014,336 | โ€”- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 โ€“ C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 10:12:36 | 000,014,336 | โ€”- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 โ€“ C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe
[2008/04/14 10:12:36 | 000,014,336 | โ€”- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 โ€“ C:\WINDOWS\system32\svchost.exe
[2004/08/04 00:56:58 | 000,014,336 | โ€”- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 โ€“ C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 00:56:58 | 000,024,576 | โ€”- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF โ€“ C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 10:12:38 | 000,026,112 | โ€”- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 โ€“ C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/14 10:12:38 | 000,026,112 | โ€”- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 โ€“ C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 10:12:38 | 000,026,112 | โ€”- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 โ€“ C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[2008/04/14 10:12:38 | 000,026,112 | โ€”- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 โ€“ C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 00:56:58 | 000,502,272 | โ€”- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE โ€“ C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 10:12:39 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 10:12:39 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 10:12:39 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
[2008/04/14 10:12:39 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\system32\winlogon.exe

< End of report >
Hi

Please do the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKLM..\Run: [ISW] File not found
    [2011/12/08 23:09:23 | 000,000,000 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Application Data\I03I1M7LM.dat
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT


Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java SE 6 Update 29
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Javaโ„ข 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u29-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Please advise how the computer is running now and if there are any outstanding issues
OTL file is below. I'll update the other stuff now. Thanks for everything so far!


All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISW deleted successfully.
C:\Documents and Settings\All Users\Application Data\I03I1M7LM.dat moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Scotty\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Scotty\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes

User: Jolene
->Temp folder emptied: 1163693248 bytes
->Temporary Internet Files folder emptied: 435935299 bytes
->Java cache emptied: 316359 bytes
->Google Chrome cache emptied: 6138516 bytes
->Apple Safari cache emptied: 1043456 bytes
->Flash cache emptied: 48100 bytes

User: LocalService
->Temp folder emptied: 990760 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 995848 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 8800 bytes

User: Scotty
->Temp folder emptied: 1254407 bytes
->Temporary Internet Files folder emptied: 28664273 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 14336 bytes
->Flash cache emptied: 259335 bytes

User: Visitor
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
->Google Chrome cache emptied: 6138516 bytes
->Flash cache emptied: 1885 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 16753165 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1124691 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,587.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12122011_151142

Files\Folders moved on Rebootโ€ฆ

Registry entries deleted on Rebootโ€ฆ

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI