This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

DLL problem;can't connect to wifi [Solved]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My daughter's computer seemed to be infected. Loaded Norton 360 and cleaned up some things, but apparently that altered some needed files. now, she can't connect to wifi. gets a missing dll message. here are the scans from OTL:

OTL logfile created on: 12/30/2011 9:33:09 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Repair
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1011.88 Mb Total Physical Memory | 621.05 Mb Available Physical Memory | 61.38% Memory free
2.37 Gb Paging File | 1.93 Gb Available in Paging File | 81.39% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.20 Gb Total Space | 93.15 Gb Free Space | 65.05% Space Free | Partition Type: NTFS
Drive D: | 3.74 Gb Total Space | 1.78 Gb Free Space | 47.71% Space Free | Partition Type: FAT32

Computer Name: CHELSEA | User Name: KarenAltman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Repair\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\WINDOWS\svcs.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\KarenAltman\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\WINDOWS\svcs.exe ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_ba7110a3\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_4d46fcdb\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_024297bf\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_c92131cd\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_78bb3b99\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\hpqprrsc\3.0.0.0__a53cf5803f4c3827\hpqprrsc.dll ()
MOD - c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll ()
MOD - c:\windows\assembly\gac\hpqmdmr\3.0.0.0__a53cf5803f4c3827\hpqmdmr.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.89__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.89__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.89__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.89__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\interop.hpdarc\1.0.0.0__19565c63d39c2842\interop.hpdarc.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\hpqntrop\3.0.0.0__a53cf5803f4c3827\hpqntrop.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Acer\Empowering Technology\eRecovery\it41.dll ()
MOD - C:\Acer\Empowering Technology\eRecovery\imagefile.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (NetworkLog) – C:\WINDOWS\svcs.exe ()
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (PTDUMdm) – C:\WINDOWS\system32\drivers\PTDUMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWWAN) – C:\WINDOWS\system32\drivers\PTDUWWAN.sys (DEVGURU Co., LTD.)
DRV - (PTDUBus) – C:\WINDOWS\system32\drivers\PTDUBus.sys (DEVGURU Co., LTD.)
DRV - (PTDUVsp) – C:\WINDOWS\system32\drivers\PTDUVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWFLT) – C:\WINDOWS\system32\drivers\PTDUWFLT.sys (DEVGURU Co., LTD.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (JMCR) – C:\WINDOWS\system32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (NetBT) – C:\WINDOWS\system32\drivers\netbt.sys ()
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (int15.sys) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…09&m=aoa150
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sherman.edu/default.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 08 CD EE DC 07 3D CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/11/25 12:21:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn\ [2011/11/25 12:09:49 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/12/18 19:18:03 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe File not found
O4 - HKCU..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler File not found
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\nwprovau.dll File not found
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1238028596453 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{209B0746-82B1-4AA0-B55C-2B9D77AB1DEF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\KarenAltman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\KarenAltman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/20 13:11:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{69c368c9-537d-11de-8af1-00242baaab14}\Shell - "" = AutoRun
O33 - MountPoints2\{69c368c9-537d-11de-8af1-00242baaab14}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{69c368c9-537d-11de-8af1-00242baaab14}\Shell\AutoRun\command - "" = D:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/30 09:27:49 | 000,000,000 | —D | C] – C:\Repair
[2011/12/25 08:47:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Chlesea other
[2011/12/25 08:47:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Chelsea Music
[2011/11/26 09:21:59 | 000,591,712 | —- | C] (SlimWare Utilities, Inc.) – C:\Program Files\FixCleanerSetup.exe
[2009/03/24 07:11:25 | 000,016,384 | —- | C] ( ) – C:\WINDOWS\System32\ClearEvent.exe
[2007/04/02 14:40:54 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2005/11/23 09:55:32 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\KarenAltman\My Documents\*.tmp files -> C:\Documents and Settings\KarenAltman\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\KarenAltman\Desktop\*.tmp files -> C:\Documents and Settings\KarenAltman\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/25 21:00:37 | 000,443,034 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/25 21:00:37 | 000,072,134 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/25 21:00:12 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/25 20:56:28 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/25 20:56:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/25 20:56:13 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2011/12/25 08:50:28 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/12/25 08:50:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/12/18 19:18:03 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/18 18:51:04 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2011/12/18 18:51:04 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2011/12/18 18:25:15 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2011/12/18 17:53:05 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2011/12/18 17:53:05 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2011/12/18 17:50:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\u46W0cH5.exe.b
[2011/12/18 16:51:39 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2011/12/18 16:51:34 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2011/12/18 16:22:54 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/05 20:50:52 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2011/12/05 20:50:44 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2011/12/05 19:50:53 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2011/12/05 19:50:52 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2011/12/05 17:58:21 | 000,002,515 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\Microsoft Office Word 2007.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\KarenAltman\My Documents\*.tmp files -> C:\Documents and Settings\KarenAltman\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\KarenAltman\Desktop\*.tmp files -> C:\Documents and Settings\KarenAltman\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/18 17:50:31 | 000,111,616 | —- | C] () – C:\Documents and Settings\All Users\Application Data\u46W0cH5.exe
[2011/12/18 17:50:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\u46W0cH5.exe.b
[2011/11/25 13:50:25 | 000,111,616 | —- | C] () – C:\WINDOWS\System32\76F48.com_
[2011/11/25 11:53:44 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\76F48.com.b
[2011/11/19 13:21:42 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kLagm2.dat
[2011/11/19 09:29:31 | 000,508,928 | —- | C] () – C:\WINDOWS\svcs.exe
[2011/10/19 19:12:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/11 10:21:04 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2011/06/02 03:48:12 | 000,565,827 | —- | C] () – C:\WINDOWS\System32\sqlite3.dll
[2011/04/08 21:42:30 | 000,013,624 | -HS- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\17qem3l4c6h5k
[2011/04/08 21:42:30 | 000,013,624 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\17qem3l4c6h5k
[2011/02/08 14:45:53 | 000,008,192 | —- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 21:22:03 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/02/04 22:58:37 | 000,000,134 | —- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\fusioncache.dat
[2010/02/03 16:07:12 | 000,068,976 | —- | C] () – C:\WINDOWS\hpoins05.dat
[2010/02/03 16:07:12 | 000,019,696 | —- | C] () – C:\WINDOWS\hpomdl05.dat
[2009/09/11 21:26:45 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2009/02/22 12:17:10 | 000,001,233 | —- | C] () – C:\WINDOWS\SASETS.INI
[2009/01/20 18:12:56 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/20 18:12:26 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/20 15:20:46 | 000,443,034 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/20 15:20:46 | 000,072,134 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/20 15:04:02 | 000,249,496 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/20 13:11:22 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/20 13:09:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/08/21 15:43:36 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX2.dat
[2008/07/30 21:37:26 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/06/07 00:08:56 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/05/16 18:12:30 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2008/04/14 15:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 15:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 15:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 15:00:00 | 000,162,816 | —- | C] () – C:\WINDOWS\System32\drivers\netbt.sys
[2008/04/14 15:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 15:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 15:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 15:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 15:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/04/14 15:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/02/15 15:21:56 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2007/10/01 16:59:46 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2007/07/13 16:11:56 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2007/05/09 17:16:40 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2005/08/26 15:28:34 | 000,143,360 | —- | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 15:27:58 | 000,045,056 | —- | C] () – C:\WINDOWS\devenum.exe
[2005/06/27 07:29:50 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX0.dat
[2005/06/27 07:29:28 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX1.dat
[2005/03/28 17:45:26 | 000,000,135 | —- | C] () – C:\WINDOWS\ALaunch.ini
[2002/11/22 05:57:26 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2002/11/22 05:57:26 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2002/11/22 05:57:26 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2002/11/22 05:57:26 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2002/11/22 05:57:26 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2002/11/22 05:57:24 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2002/05/24 18:34:46 | 000,032,768 | —- | C] () – C:\WINDOWS\AMove.exe
[2001/08/26 19:04:08 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/26 19:02:42 | 000,004,524 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========

[2011/10/26 18:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ascentive
[2009/02/22 12:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eSobi
[2009/10/03 19:14:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/18 18:03:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/06/07 21:38:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/11/25 12:13:41 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\8F574
[2009/03/26 07:16:16 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\eSobi
[2009/03/26 07:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\InterVideo
[2009/04/18 21:47:16 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Octoshape
[2009/09/11 21:26:40 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Research In Motion
[2010/01/29 15:03:19 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Smith Micro
[2011/11/25 12:32:45 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Tific
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2011/12/25 08:50:28 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2011/12/25 08:50:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2011/11/26 09:50:34 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/11/26 09:50:34 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2011/11/26 10:50:55 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2011/11/26 10:50:55 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2011/11/25 11:50:03 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2011/11/25 11:50:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2011/11/25 12:50:01 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At25.job
[2011/11/25 13:14:44 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At26.job
[2011/11/25 13:50:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At27.job
[2011/11/25 13:50:26 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At28.job
[2011/11/25 14:50:30 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At29.job
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/11/25 14:50:50 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At30.job
[2011/11/25 15:50:59 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At31.job
[2011/11/25 15:50:54 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At32.job
[2011/12/18 16:51:39 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At33.job
[2011/12/18 16:51:34 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At34.job
[2011/12/18 17:53:05 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At35.job
[2011/12/18 17:53:05 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At36.job
[2011/12/18 18:51:04 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At37.job
[2011/12/18 18:51:04 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At38.job
[2011/12/05 19:50:52 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At39.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/12/05 19:50:53 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At40.job
[2011/12/05 20:50:52 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At41.job
[2011/12/05 20:50:44 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At42.job
[2011/11/25 21:51:01 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At43.job
[2011/11/25 21:51:02 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At44.job
[2011/11/25 22:52:32 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At45.job
[2011/11/25 22:52:35 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At46.job
[2011/11/26 08:35:46 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At47.job
[2011/11/26 08:35:46 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At48.job
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2011/11/19 13:21:36 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2011/11/19 13:21:36 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At9.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/01/20 13:11:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/03/24 07:08:08 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2009/01/20 13:11:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/12/25 20:56:13 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2009/01/20 13:11:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/20 13:11:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 15:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 15:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/25 20:56:11 | 1585,446,912 | -HS- | M] () – C:\pagefile.sys
[2009/01/20 17:14:20 | 000,000,079 | RHS- | M] () – C:\Preload.aaa
[2009/01/20 13:39:06 | 000,001,623 | —- | M] () – C:\RHDSetup.log
[1999/11/11 02:17:54 | 000,000,049 | —- | M] () – C:\XPH.TAG

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/20 13:11:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 13:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2005/07/20 13:23:58 | 000,024,576 | —- | M] () – C:\WINDOWS\3D Marine & Tropical Aquarium Screensaver.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/11/26 09:17:46 | 000,591,712 | —- | M] (SlimWare Utilities, Inc.) – C:\Program Files\FixCleanerSetup.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/20 05:03:20 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/01/20 05:03:20 | 001,064,960 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/01/20 05:03:20 | 000,897,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/20 13:11:46 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/03/24 07:09:31 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\KarenAltman\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/20 13:19:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\KarenAltman\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/11/25 11:58:08 | 000,397,864 | —- | M] (Symantec Corporation) – C:\Documents and Settings\KarenAltman\Desktop\N360Downloader.exe
[1 C:\Documents and Settings\KarenAltman\Desktop\*.tmp files -> C:\Documents and Settings\KarenAltman\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-24 02:01:19

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB19790$] -> Error: Cannot create file handle -> Unknown point type
[C:\WINDOWS\$NtUninstallKB45745$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 212 bytes -> C:\WINDOWS\System32\msln.exe:5a504841a9fe46c47f7d0ae4768f2fac
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29

< End of report >



OTL Extras logfile created on: 12/30/2011 9:33:09 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Repair
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1011.88 Mb Total Physical Memory | 621.05 Mb Available Physical Memory | 61.38% Memory free
2.37 Gb Paging File | 1.93 Gb Available in Paging File | 81.39% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.20 Gb Total Space | 93.15 Gb Free Space | 65.05% Space Free | Partition Type: NTFS
Drive D: | 3.74 Gb Total Space | 1.78 Gb Free Space | 47.71% Space Free | Partition Type: FAT32

Computer Name: CHELSEA | User Name: KarenAltman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{069730C2-755A-485B-A205-27A1AAFA836A}" = InstantShareAlert
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}" = Scan
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{17293791-C82E-476C-9997-9A0FF234A19B}" = HP Product Assistant
"{181821B7-82AA-44DA-9DAF-EF254CCB670A}" = Fax
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 23
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{342C7C88-D335-4bc2-8CF1-281857629CE2}" = HP PSC & OfficeJet 4.7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{391E18CE-7D3B-45E9-A8F0-34E77F14F47A}" = ProductContext
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye webcam
"{442BE28B-782B-4DC0-B490-E70A403B1C69}" = Readme
"{461073BF-9642-4A73-B58E-157358D412AB}" = 6200
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{6518675B-CC8D-4AB3-A3F6-CC02FF6548D7}" = 6200_Help
"{655CB07D-C944-40BE-B93F-55957CAC7625}" = AiO_Scan
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{85CFD253-38AE-4DB1-ACB7-F0F4C791990D}" = AiOSoftware
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C13AF9C7-8E06-4354-B629-DF6192CE4A66}" = PANTECH UM175 Driver
"{C3F81504-72F3-4262-9449-487404DA75BB}" = 6200Trb
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CDAFD956-97BE-443D-8EF7-F4F094EB5766}_SAV_3DAQUARIUM" = Crawler 3D Marine & Tropical Aquarium Screensaver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photo & Imaging" = HP Image Zone 4.7
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSNINST" = MSN
"N360" = Norton 360
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Windows Media Format Runtime" = Windows Media Format Runtime

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Octoshape Streaming Services" = Octoshape Streaming Services

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/25/2011 10:01:09 PM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/25/2011 10:01:09 PM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 19625

Error - 12/25/2011 10:01:09 PM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 19625

Error - 12/25/2011 10:01:11 PM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/25/2011 10:01:11 PM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 21594

Error - 12/25/2011 10:01:11 PM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 21594

Error - 12/30/2011 10:24:57 AM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/30/2011 10:24:57 AM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 390247328

Error - 12/30/2011 10:24:57 AM | Computer Name = CHELSEA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 390247328

Error - 12/30/2011 10:26:00 AM | Computer Name = CHELSEA | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 5.5.0.114, faulting module
skype.exe, version 5.5.0.114, fault address 0x00f6d7ac.

[ System Events ]
Error - 12/30/2011 10:28:09 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:29:42 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:30:29 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:31:14 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:32:46 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:34:18 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:35:50 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:37:23 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:38:55 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/30/2011 10:40:27 AM | Computer Name = CHELSEA | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127


< End of report >


Thanks!

Jeremy
Hi Jeremy in SC, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks, Oldman960, running combo fix. Problem: Don't have Windows Microsoft Recovery Console. Can't download it using damaged computer (connecting to internet is the problem). Can't find downloadable file using other PC. Maybe when I get home I can get it from an XP disk. Running Combofix without it, it says I have Rootkit.ZeroAccess. Continuing on, however does not seem to resolve the problem. If I can't get the Revocery Console, do you have suggestions? Thanks! Jeremy
Hi Jeremy in SC, If you have an XP disk don't worry about not being able to install the Recovery Console with combofix. If we need the Recovery Console we can use the disk to access it. The one that would have been installed is the same one that is on the disk. They are the same program except one is on the disk while the other would have been on the hard drive. We can install the Recovery Console later. Go ahead and run combofix.
Oldman960, Finally got Combofix to finish its scan (It had been cyciling through telling me that I had Rootkit and telling me it would take a while to solve. here is the log: ComboFix 11-12-30.01 - KarenAltman 12/30/2011 15:10:07.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.726 [GMT -5:00] Running from: C:\Repair\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Documents and Settings\All Users\Application Data\TEMP C:\Documents and Settings\All Users\Application Data\u46W0cH5.exe C:\Documents and Settings\All Users\Start Menu\E-Set 2011 C:\Documents and Settings\All Users\Start Menu\E-Set 2011\E-Set Antivirus 2011.lnk C:\Documents and Settings\All Users\Start Menu\E-Set 2011\Uninstall.lnk C:\Documents and Settings\KarenAltman\Application Data\Adobe\plugs C:\Documents and Settings\KarenAltman\Application Data\Adobe\shed C:\Documents and Settings\KarenAltman\Local Settings\Application Data\defb6c4a C:\Documents and Settings\KarenAltman\Local Settings\Application Data\defb6c4a\@ C:\Documents and Settings\KarenAltman\Local Settings\Application Data\defb6c4a\U\80000000.$ C:\Documents and Settings\KarenAltman\Local Settings\Application Data\defb6c4a\U\800000cb.$ C:\Documents and Settings\KarenAltman\Local Settings\Application Data\defb6c4a\X C:\Documents and Settings\KarenAltman\My Documents\~WRL0001.tmp C:\Program Files\LP C:\Program Files\LP\C238\11.tmp C:\Program Files\LP\C238\D.tmp C:\Program Files\LP\C238\E.tmp C:\Program Files\Shared C:\Program Files\Shared\shared.sig C:\WINDOWS\svcs.exe C:\WINDOWS\system32\sqlite3.dll ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_NetworkLog ——-\Service_NetworkLog ((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-30 ))))))))))))))))))))))))))))))) 2011-12-30 19:49:16 . 2011-12-30 19:49:16 ——– d—–w- C:\Documents and Settings\All Users\Application Data\PC Tools 2011-12-30 19:49:15 . 2011-12-30 19:49:15 ——– d—–w- C:\Documents and Settings\KarenAltman\Application Data\TestApp 2011-12-30 14:50:24 . 2011-11-25 16:53:17 111616 —-a-w- C:\WINDOWS\system32\76F48.com 2011-12-30 14:27:49 . 2011-12-30 19:51:38 ——– d—–w- C:\Repair 2011-12-25 13:47:37 . 2011-12-25 14:21:32 ——– d—–w- C:\Documents and Settings\All Users\Chlesea other 2011-12-25 13:47:09 . 2011-12-25 13:49:51 ——– d—–w- C:\Documents and Settings\All Users\Chelsea Music . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2011-12-30 19:56:01 . 2008-04-14 20:00:00 138496 —-a-w- C:\WINDOWS\system32\drivers\afd.sys 2011-11-26 14:17:46 . 2011-11-26 14:21:59 591712 —-a-w- C:\Program Files\FixCleanerSetup.exe 2011-11-25 18:11:36 . 2011-11-25 17:31:41 46640 —-a-w- C:\WINDOWS\system32\msln.exe 2011-11-25 17:11:25 . 2011-11-25 17:11:26 60872 —-a-w- C:\WINDOWS\system32\S32EVNT1.DLL 2011-11-25 17:11:25 . 2011-11-25 17:11:26 126584 —-a-w- C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2011-11-25 16:53:17 . 2011-11-25 18:50:25 111616 —-a-w- C:\WINDOWS\system32\76F48.com_ 2011-11-25 16:20:28 . 2011-11-25 16:20:28 41272 —-a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-24 12:12:57 68856] "Octoshape Streaming Services"="C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-12 13:42:35 70936] "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2011-08-18 21:04:48 17360520] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-25 16:15:25 4617600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" [X] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-28 22:00:20 141848] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-28 22:00:04 166424] "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2008-02-28 22:00:14 137752] "RTHDCPL"="RTHDCPL.EXE" [2008-12-30 21:58:28 18082304] "AzMixerSel"="C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-18 05:40:30 53248] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 16:32:08 1044480] "LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 03:14:34 821768] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 20:00:00 208952] "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 20:00:00 59392] "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 20:00:00 455168] "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 20:00:00 455168] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-16 22:48:39 30192] "PLFSetL"="C:\WINDOWS\PLFSetL.exe" [2007-07-05 16:35:54 94208] "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-09-04 02:46:04 425984] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 21:10:28 35696] "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 16:44:46 248552] "Microsoft Default Manager"="C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 16:12:14 288080] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2010-11-29 21:38:18 421888] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 06:41:12 49208] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048] HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-6-4 114688] McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 00:02:18 113024] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2011-05-04 17:54:14 551296 —-a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27:02 AM 12880] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55:22 PM 67664] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38:07 PM 116608] S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [9/1/2010 9:20:24 PM 136176] S3 BBSvc;Bing Bar Update Service;C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2/28/2011 6:44:14 PM 183560] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1/20/2009 2:22:52 PM 30192] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files\Google\Update\GoogleUpdate.exe [9/1/2010 9:20:24 PM 136176] S3 JMCR;JMCR;C:\WINDOWS\system32\drivers\jmcr.sys [7/8/2008 12:16:26 PM 96856] S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49:20 AM 227232] S3 PTDUBus;PANTECH UM175 Composite Device Driver ;C:\WINDOWS\system32\drivers\PTDUBus.sys [1/29/2010 3:16:32 PM 54416] S3 PTDUMdm;PANTECH UM175 Drivers;C:\WINDOWS\system32\drivers\PTDUMdm.sys [1/29/2010 3:16:33 PM 160272] S3 PTDUVsp;PANTECH UM175 Diagnostic Port;C:\WINDOWS\system32\drivers\PTDUVsp.sys [1/29/2010 3:16:34 PM 160272] S3 PTDUWFLT;PTDUWWAN Filter Driver;C:\WINDOWS\system32\drivers\PTDUWFLT.sys [1/29/2010 3:16:38 PM 11920] S3 PTDUWWAN;PANTECH UM175 WWAN Driver;C:\WINDOWS\system32\drivers\PTDUWWAN.sys [1/29/2010 3:16:38 PM 113680] Contents of the 'Scheduled Tasks' folder 2011-10-31 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50:20 . 2009-10-22 15:50:20] 2011-11-19 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At11.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-25 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-25 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At2.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At25.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-25 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-25 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\At30.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-25 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-25 C:\WINDOWS\Tasks\At32.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-18 C:\WINDOWS\Tasks\At33.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-18 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-18 C:\WINDOWS\Tasks\At35.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-18 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-18 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-18 C:\WINDOWS\Tasks\At38.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-06 C:\WINDOWS\Tasks\At39.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-06 C:\WINDOWS\Tasks\At40.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-12-06 C:\WINDOWS\Tasks\At41.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-06 C:\WINDOWS\Tasks\At42.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-26 C:\WINDOWS\Tasks\At43.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-26 C:\WINDOWS\Tasks\At44.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-26 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-26 C:\WINDOWS\Tasks\At46.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-26 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-26 C:\WINDOWS\Tasks\At48.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\system32\76F48.com_ [2011-11-25 18:50:25 . 2011-11-25 16:53:17] 2011-11-19 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\system32\76F48.com [2011-12-30 14:50:24 . 2011-11-25 16:53:17] 2011-12-30 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-02 02:20:24 . 2010-09-02 02:19:44] 2011-12-30 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-02 02:20:24 . 2010-09-02 02:19:44] ——- Supplementary Scan ——- uStart Page = hxxp://www.sherman.edu/default.asp uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.1 - - - - ORPHANS REMOVED - - - - HKCU-Run-ISUSPM - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe HKLM-Run-snp2uvc - C:\WINDOWS\vsnp2uvc.exe SafeBoot-86932179.sys SafeBoot-mcmscsvc SafeBoot-MCODS Thanks! Jeremy
Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\WINDOWS\Tasks\At*.job
C:\WINDOWS\system32\76F48.com_ 
C:\WINDOWS\system32\76F48.com

:Commands
[purity]
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL fix log.


Next



  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following

    /md5start
    afd.*
    netbt.*
    consrv.dll
    /md5stop
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt, no Extras.Txt this time.

Please post back with
  • OTL fix log
  • OTL.txt
How's the computer?
Just got home from work….no internet access on damaged computer….will run the fix from the previous post. Thanks so much for your help! Jeremy
Oldman960,

Ran the fix, but got an error message "cannot create log." Ran the scan, and will post log below. Still not getting IP connection. do you think I'm missing a dll?

OTL logfile created on: 12/30/2011 5:34:11 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Repair
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1011.88 Mb Total Physical Memory | 539.69 Mb Available Physical Memory | 53.34% Memory free
2.37 Gb Paging File | 1.93 Gb Available in Paging File | 81.22% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.20 Gb Total Space | 93.40 Gb Free Space | 65.23% Space Free | Partition Type: NTFS

Computer Name: CHELSEA | User Name: KarenAltman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Repair\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\KarenAltman\Local Settings\temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_ba7110a3\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_4d46fcdb\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_024297bf\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_c92131cd\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_78bb3b99\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\hpqprrsc\3.0.0.0__a53cf5803f4c3827\hpqprrsc.dll ()
MOD - c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll ()
MOD - c:\windows\assembly\gac\hpqmdmr\3.0.0.0__a53cf5803f4c3827\hpqmdmr.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.89__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.89__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.89__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.89__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\interop.hpdarc\1.0.0.0__19565c63d39c2842\interop.hpdarc.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\hpqntrop\3.0.0.0__a53cf5803f4c3827\hpqntrop.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - C:\Acer\Empowering Technology\eRecovery\it41.dll ()
MOD - C:\Acer\Empowering Technology\eRecovery\imagefile.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (PTDUMdm) – C:\WINDOWS\system32\drivers\PTDUMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWWAN) – C:\WINDOWS\system32\drivers\PTDUWWAN.sys (DEVGURU Co., LTD.)
DRV - (PTDUBus) – C:\WINDOWS\system32\drivers\PTDUBus.sys (DEVGURU Co., LTD.)
DRV - (PTDUVsp) – C:\WINDOWS\system32\drivers\PTDUVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWFLT) – C:\WINDOWS\system32\drivers\PTDUWFLT.sys (DEVGURU Co., LTD.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (JMCR) – C:\WINDOWS\system32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (NetBT) – C:\WINDOWS\system32\drivers\netbt.sys ()
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (int15.sys) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sherman.edu/default.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 08 CD EE DC 07 3D CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/11/25 12:21:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn\ [2011/11/25 12:09:49 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/12/30 15:26:28 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe File not found
O4 - HKCU..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler File not found
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1238028596453 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{209B0746-82B1-4AA0-B55C-2B9D77AB1DEF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\KarenAltman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\KarenAltman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/20 13:11:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/30 17:04:56 | 000,000,000 | —D | C] – C:\_OTL
[2011/12/30 16:59:44 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/30 15:00:19 | 000,000,000 | —D | C] – C:\ComboFix
[2011/12/30 14:49:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2011/12/30 14:49:15 | 000,000,000 | —D | C] – C:\Documents and Settings\KarenAltman\Application Data\TestApp
[2011/12/30 13:06:51 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/12/30 13:06:51 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/12/30 13:06:51 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/12/30 13:06:51 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/12/30 13:05:32 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/12/30 13:04:15 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/30 13:03:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\KarenAltman\My Documents\My Videos
[2011/12/30 13:03:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2011/12/30 13:03:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\KarenAltman\Start Menu\Programs\Administrative Tools
[2011/12/30 09:27:49 | 000,000,000 | —D | C] – C:\Repair
[2011/12/25 08:47:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Chlesea other
[2011/12/25 08:47:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Chelsea Music
[2011/11/26 09:21:59 | 000,591,712 | —- | C] (SlimWare Utilities, Inc.) – C:\Program Files\FixCleanerSetup.exe
[2009/03/24 07:11:25 | 000,016,384 | —- | C] ( ) – C:\WINDOWS\System32\ClearEvent.exe
[2007/04/02 14:40:54 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2005/11/23 09:55:32 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[1 C:\Documents and Settings\KarenAltman\Desktop\*.tmp files -> C:\Documents and Settings\KarenAltman\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/30 17:34:01 | 000,443,034 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/30 17:34:01 | 000,072,134 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/30 17:29:45 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/30 17:29:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/30 17:29:39 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2011/12/30 17:00:10 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/30 15:26:28 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/30 14:49:17 | 000,001,339 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\sdsetup_aff.exe.lnk
[2011/12/30 13:57:52 | 000,000,774 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\Norton Installation Files.lnk
[2011/12/18 18:25:15 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2011/12/18 17:50:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\u46W0cH5.exe.b
[2011/12/18 16:22:54 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/05 17:58:21 | 000,002,515 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\Microsoft Office Word 2007.lnk
[1 C:\Documents and Settings\KarenAltman\Desktop\*.tmp files -> C:\Documents and Settings\KarenAltman\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/30 14:49:17 | 000,001,339 | —- | C] () – C:\Documents and Settings\KarenAltman\Desktop\sdsetup_aff.exe.lnk
[2011/12/30 13:06:51 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/12/30 13:06:51 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/12/30 13:06:51 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/12/30 13:06:51 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/12/30 13:06:51 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/12/18 17:50:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\u46W0cH5.exe.b
[2011/11/25 11:53:44 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\76F48.com.b
[2011/11/19 13:21:42 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kLagm2.dat
[2011/10/19 19:12:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/11 10:21:04 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2011/04/08 21:42:30 | 000,013,624 | -HS- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\17qem3l4c6h5k
[2011/04/08 21:42:30 | 000,013,624 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\17qem3l4c6h5k
[2011/02/08 14:45:53 | 000,008,192 | —- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 21:22:03 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/02/04 22:58:37 | 000,000,134 | —- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\fusioncache.dat
[2010/02/03 16:07:12 | 000,068,976 | —- | C] () – C:\WINDOWS\hpoins05.dat
[2010/02/03 16:07:12 | 000,019,696 | —- | C] () – C:\WINDOWS\hpomdl05.dat
[2009/09/11 21:26:45 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2009/02/22 12:17:10 | 000,001,233 | —- | C] () – C:\WINDOWS\SASETS.INI
[2009/01/20 18:12:56 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/20 18:12:26 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/20 15:20:46 | 000,443,034 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/20 15:20:46 | 000,072,134 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/20 15:04:02 | 000,249,496 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/20 13:11:22 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/20 13:09:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/08/21 15:43:36 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX2.dat
[2008/07/30 21:37:26 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/06/07 00:08:56 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/05/16 18:12:30 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2008/04/14 15:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 15:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 15:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 15:00:00 | 000,162,816 | —- | C] () – C:\WINDOWS\System32\drivers\netbt.sys
[2008/04/14 15:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 15:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 15:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 15:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 15:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/04/14 15:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/02/15 15:21:56 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2007/10/01 16:59:46 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2007/07/13 16:11:56 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2007/05/09 17:16:40 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2005/08/26 15:28:34 | 000,143,360 | —- | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 15:27:58 | 000,045,056 | —- | C] () – C:\WINDOWS\devenum.exe
[2005/06/27 07:29:50 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX0.dat
[2005/06/27 07:29:28 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX1.dat
[2005/03/28 17:45:26 | 000,000,135 | —- | C] () – C:\WINDOWS\ALaunch.ini
[2002/11/22 05:57:26 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2002/11/22 05:57:26 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2002/11/22 05:57:26 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2002/11/22 05:57:26 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2002/11/22 05:57:26 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2002/11/22 05:57:24 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2002/05/24 18:34:46 | 000,032,768 | —- | C] () – C:\WINDOWS\AMove.exe
[2001/08/26 19:04:08 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/26 19:02:42 | 000,004,524 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========

[2011/10/26 18:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ascentive
[2009/02/22 12:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eSobi
[2010/08/18 18:03:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/06/07 21:38:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/11/25 12:13:41 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\8F574
[2009/03/26 07:16:16 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\eSobi
[2009/03/26 07:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\InterVideo
[2009/04/18 21:47:16 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Octoshape
[2009/09/11 21:26:40 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Research In Motion
[2010/01/29 15:03:19 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Smith Micro
[2011/12/30 14:49:15 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\TestApp
[2011/11/25 12:32:45 | 000,000,000 | —D | M] – C:\Documents and Settings\KarenAltman\Application Data\Tific

========== Purity Check ==========



========== Custom Scans ==========



< MD5 for: AFD.SY_ >
[2008/04/14 15:00:00 | 000,071,436 | —- | M] () MD5=357C2764E26F517D52DB78734758868A – C:\I386\AFD.SY_

< MD5 for: AFD.SYS >
[2008/04/14 15:00:00 | 000,138,112 | —- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD – C:\WINDOWS\$NtUninstallKB951748$\afd.sys
[2008/08/14 05:34:26 | 000,138,496 | —- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C – C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys
[2008/08/14 05:04:36 | 000,138,496 | —- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 – C:\WINDOWS\system32\dllcache\afd.sys
[2011/12/30 14:56:01 | 000,138,496 | —- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 – C:\WINDOWS\system32\drivers\afd.sys
[2008/06/20 06:48:03 | 000,138,496 | —- | M] (Microsoft Corporation) MD5=D6EE6014241D034E63C49A50CB2B442A – C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys
[2008/06/20 06:40:08 | 000,138,496 | —- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C – C:\WINDOWS\$NtUninstallKB956803$\afd.sys

< MD5 for: AFD.SYS.000 >
[2008/06/20 06:40:08 | 000,138,496 | —- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C – C:\WINDOWS\$NtUninstallKB956803$\afd.sys.000

< MD5 for: NETBT.SY_ >
[2008/04/14 15:00:00 | 000,090,332 | —- | M] () MD5=5283D951FE9596543E17457B6BAE87F9 – C:\I386\NETBT.SY_

< MD5 for: NETBT.SYS >
[2008/04/14 15:00:00 | 000,162,816 | —- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D – C:\WINDOWS\system32\dllcache\netbt.sys
[2008/04/14 15:00:00 | 000,162,816 | —- | M] () MD5=7E31598FB5D3712BD5E1623D5445C7CF – C:\WINDOWS\system32\drivers\netbt.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 212 bytes -> C:\WINDOWS\System32\msln.exe:5a504841a9fe46c47f7d0ae4768f2fac

< End of report >

Thanks!

Jeremy
Hi Jeremy in SC,

There is a patched file that is used for internet connection. We'll take care of that now.

We'll use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

FCopy::
C:\WINDOWS\system32\dllcache\netbt.sys | C:\WINDOWS\system32\drivers\netbt.sys

File::
C:\Documents and Settings\All Users\Application Data\u46W0cH5.exe.b
C:\WINDOWS\System32\76F48.com.b
C:\Documents and Settings\All Users\Application Data\kLagm2.dat
C:\Documents and Settings\KarenAltman\Local Settings\Application Data\17qem3l4c6h5k
C:\Documents and Settings\All Users\Application Data\17qem3l4c6h5k

DirLook::
C:\Documents and Settings\KarenAltman\Application Data\8F574

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again. Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Please post back with the combofix log.

Any better?
Oldman,

sorry, went to dinner. Ran the Combofix. (Still doesn't like not having the Recovery Console.) And…..WE HAVE INTERNET!!! YEAH!!!

here is the log:


ComboFix 11-12-30.01 - KarenAltman 12/30/2011 20:31:42.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.729 [GMT -5:00]
Running from: c:\repair\ComboFix.exe
Command switches used :: c:\documents and settings\KarenAltman\Desktop\CFScript.txt
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
FILE ::
"c:\documents and settings\All Users\Application Data\17qem3l4c6h5k"
"c:\documents and settings\All Users\Application Data\kLagm2.dat"
"c:\documents and settings\All Users\Application Data\u46W0cH5.exe.b"
"c:\documents and settings\KarenAltman\Local Settings\Application Data\17qem3l4c6h5k"
"c:\windows\System32\76F48.com.b"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\17qem3l4c6h5k
c:\documents and settings\All Users\Application Data\kLagm2.dat
c:\documents and settings\All Users\Application Data\u46W0cH5.exe.b
c:\documents and settings\KarenAltman\Local Settings\Application Data\17qem3l4c6h5k
c:\windows\System32\76F48.com.b
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\u46W0cH5.exe
c:\documents and settings\All Users\Start Menu\E-Set 2011\E-Set Antivirus 2011.lnk
c:\documents and settings\All Users\Start Menu\E-Set 2011\Uninstall.lnk
c:\documents and settings\KarenAltman\Local Settings\Application Data\defb6c4a\@
c:\documents and settings\KarenAltman\Local Settings\Application Data\defb6c4a\U\80000000.$
c:\documents and settings\KarenAltman\Local Settings\Application Data\defb6c4a\U\800000cb.$
c:\documents and settings\KarenAltman\Local Settings\Application Data\defb6c4a\X
c:\documents and settings\KarenAltman\My Documents\~WRL0001.tmp
c:\program files\LP\C238\11.tmp
c:\program files\LP\C238\D.tmp
c:\program files\LP\C238\E.tmp
c:\program files\Shared\shared.sig
c:\windows\svcs.exe
c:\windows\system32\sqlite3.dll
.
.
————— FCopy —————
.
c:\windows\system32\dllcache\netbt.sys –> c:\windows\system32\drivers\netbt.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NetworkLog
——-\Service_NetworkLog
.
.
((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-31 )))))))))))))))))))))))))))))))
.
.
2011-12-30 22:04 . 2011-12-30 22:04 ——– d—–w- C:\_OTL
2011-12-30 19:49 . 2011-12-30 19:49 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2011-12-30 19:49 . 2011-12-30 19:49 ——– d—–w- c:\documents and settings\KarenAltman\Application Data\TestApp
2011-12-30 14:27 . 2011-12-31 01:18 ——– d—–w- C:\Repair
2011-12-25 13:47 . 2011-12-25 14:21 ——– d—–w- c:\documents and settings\All Users\Chlesea other
2011-12-25 13:47 . 2011-12-25 13:49 ——– d—–w- c:\documents and settings\All Users\Chelsea Music
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-30 19:56 . 2008-04-14 20:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-11-26 14:17 . 2011-11-26 14:21 591712 —-a-w- c:\program files\FixCleanerSetup.exe
2011-11-25 18:11 . 2011-11-25 17:31 46640 —-a-w- c:\windows\system32\msln.exe
2011-11-25 17:11 . 2011-11-25 17:11 60872 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-11-25 17:11 . 2011-11-25 17:11 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-11-25 16:20 . 2011-11-25 16:20 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\KarenAltman\Application Data\8F574 —-
.
2011-10-22 22:34 . 2011-10-24 21:49 3839 —-a-w- c:\documents and settings\KarenAltman\Application Data\8F574\492E.F57
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-30_20.26.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-31 01:29 . 2011-12-31 01:29 16384 c:\windows\Temp\Perflib_Perfdata_7c8.dat
+ 2009-01-20 20:20 . 2011-12-31 01:34 72134 c:\windows\system32\perfc009.dat
- 2009-01-20 20:20 . 2011-12-30 20:28 72134 c:\windows\system32\perfc009.dat
+ 2009-01-20 20:20 . 2011-12-31 01:34 443034 c:\windows\system32\perfh009.dat
- 2009-01-20 20:20 . 2011-12-30 20:28 443034 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))).
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-24 68856]
"Octoshape Streaming Services"="c:\documents and settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-12 70936]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [BU]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-08-18 17360520]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-25 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-30 18082304]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-18 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-16 30192]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [BU]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-09-04 425984]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-6-4 114688]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 9:20 PM 136176]
S3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2/28/2011 6:44 PM 183560]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/20/2009 2:22 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 9:20 PM 136176]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [7/8/2008 12:16 PM 96856]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [1/29/2010 3:16 PM 54416]
S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [1/29/2010 3:16 PM 160272]
S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [1/29/2010 3:16 PM 160272]
S3 PTDUWFLT;PTDUWWAN Filter Driver;c:\windows\system32\drivers\PTDUWFLT.sys [1/29/2010 3:16 PM 11920]
S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [1/29/2010 3:16 PM 113680]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
2011-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-02 02:19]
.
2011-12-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-02 02:19]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.sherman.edu/default.asp
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\KarenAltman\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-30 20:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(708)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-12-30 20:44:59
ComboFix-quarantined-files.txt 2011-12-31 01:44
.
Pre-Run: 100,863,979,520 bytes free
Post-Run: 100,864,729,088 bytes free
.
- - End Of File - - DACC248A2CA860E375F78D911D725910


What else should I do? Should i run Combofix and have it install the Recovery Console?

Thanks!

Jeremy
Hi Jeremy in SC,

I need some information on a unidentified file. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

VirusTotal

copy and paste the following into the upload a file box (if you unable to copy and paste the filepath use the browse button)

c:\documents and settings\KarenAltman\Application Data\8F574\492E.F57


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed .


Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • VirusTotal results
  • MBAM log
Oldman, thanks for all the help. Here is the VirusTotal: 492E.F57 Submission date: 2011-12-31 02:15:33 (UTC) Current status: queued (#3) queued analysing finished Result: 3/ 43 (7.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.12.30.02 2011.12.30 - AntiVir 7.11.20.97 2011.12.30 - Antiy-AVL 2.0.3.7 2011.12.30 - Avast 6.0.1289.0 2011.12.30 INI:Cycbot-gen [Trj] AVG 10.0.0.1190 2011.12.30 - BitDefender 7.2 2011.12.31 - ByteHero 1.0.0.1 2011.12.07 - CAT-QuickHeal 12.00 2011.12.30 - ClamAV 0.97.3.0 2011.12.31 - Commtouch 5.3.2.6 2011.12.31 - Comodo 11146 2011.12.31 - DrWeb 5.0.2.03300 2011.12.31 - Emsisoft 5.1.0.11 2011.12.31 - eSafe 7.0.17.0 2011.12.29 - eTrust-Vet 37.0.9655 2011.12.30 - F-Prot 4.6.5.141 2011.12.30 - F-Secure 9.0.16440.0 2011.12.31 - Fortinet 4.3.388.0 2011.12.30 - GData 22 2011.12.31 INI:Cycbot-gen Ikarus T3.1.1.109.0 2011.12.30 - Jiangmin 13.0.900 2011.12.30 - K7AntiVirus 9.120.5819 2011.12.30 - Kaspersky 9.0.0.837 2011.12.31 - McAfee 5.400.0.1158 2011.12.31 - McAfee-GW-Edition 2010.1E 2011.12.30 - Microsoft 1.7903 2011.12.30 - NOD32 6756 2011.12.31 - Norman 6.07.13 2011.12.31 - nProtect 2011-12-30.01 2011.12.30 - Panda 10.0.3.5 2011.12.30 - PCTools 8.0.0.5 2011.12.31 - Prevx 3.0 2011.12.31 - Rising 23.90.04.02 2011.12.30 - Sophos 4.72.0 2011.12.31 Troj/CycBotCn-A SUPERAntiSpyware 4.40.0.1006 2011.12.30 - Symantec 20111.2.0.82 2011.12.31 - TheHacker 6.7.0.1.368 2011.12.31 - TrendMicro 9.500.0.1008 2011.12.30 - TrendMicro-HouseCall 9.500.0.1008 2011.12.31 - VBA32 3.12.16.4 2011.12.30 - VIPRE 11328 2011.12.30 - ViRobot 2011.12.30.4855 2011.12.30 - VirusBuster 14.1.142.0 2011.12.30 - Additional informationShow all MD5 : a7a737195544d01ebe39954af807997f SHA1 : eb64031d66a3f4f717b4718a8eb2548c3b18884a SHA256: 3af138538e8f93e6b5fdfad3cfbe05049864da65ac0d9883dc9eb6a54d157fc1 And here is MBAM Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2011.12.31.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 KarenAltman :: CHELSEA [administrator] 12/30/2011 9:29:51 PM mbam-log-2011-12-30 (21-29-51).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 166363 Time elapsed: 7 minute(s), Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) No infections! Yeah!!! Anything else??? jeremy
Hi Jeremy in SC,

Looking pretty good so far. A few things to do yet.

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
c:\documents and settings\KarenAltman\Application Data\8F574
ipconfig /flushdns /c

:Commands
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL fix log.


Next

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.



Please obtain a new OTL scan log after all other steps are taken.

Please post back with
  • OTL fix log
  • ESET log if there was one produced
  • OTL.txt
Everything still ok?

Thanks
Oldman,


I'm afraid i srewed up. I ran the OTL fix (log below). Ran the ESET, but I think I checked "remove threats" and did not check "search archives". Found 64 threats. Log below. Ran final OTL (didn't know whether to check "lop" and "purity" so left unchecked. Now having trouble connecting to internet again.

do i need to restore to the OTL restore point from the fix and run the fix, the ESET, and the final OTL again?

Logs:

OTL Fix

All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
c:\documents and settings\KarenAltman\Application Data\8F574 folder moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Repair\cmd.bat deleted successfully.
C:\Repair\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: KarenAltman
->Temp folder emptied: 907599 bytes
->Temporary Internet Files folder emptied: 4609991 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 949 bytes

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 16786 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 39525608 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 43.00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.31.0 log created on 12312011_093530

Files\Folders moved on Reboot…
C:\Documents and Settings\KarenAltman\Local Settings\Temporary Internet Files\Content.IE5\R9FGE9WL\index[2].htm moved successfully.
C:\Documents and Settings\KarenAltman\Local Settings\Temporary Internet Files\Content.IE5\E2GR2VDL\iframe[1].htm moved successfully.
C:\Documents and Settings\KarenAltman\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_6d4.dat not found!

Registry entries deleted on Reboot…


ESET

C:\Qoobox\Quarantine\C\WINDOWS\svcs.exe.vir probably a variant of Win32/Spy.KeyLogger.LFJNMOG trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0049089.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0050089.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0051089.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0052089.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0053089.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0054089.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0054103.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0054130.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0054139.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP109\A0055140.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP110\A0061141.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP111\A0061211.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP111\A0061220.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP111\A0062220.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP111\A0063220.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP111\A0064220.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP111\A0065220.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP112\A0065229.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP112\A0065243.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP112\A0066243.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP113\A0066256.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP114\A0066294.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP114\A0066310.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0067310.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0067327.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0067345.com Win32/TrojanDownloader.Unruy.BN trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0067354.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0068354.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0069354.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0070354.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0071354.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0072354.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP115\A0073357.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073376.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073392.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073401.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073417.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073433.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073449.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073467.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073483.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073499.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0073520.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0074520.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0074536.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0074552.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP116\A0074575.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074598.com a variant of Win32/Kryptik.VRX trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074602.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074633.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074649.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074667.exe a variant of Win32/Kryptik.VRX trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074668.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074684.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074699.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074714.com a variant of Win32/Kryptik.VRX trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP117\A0074716.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP118\A0074737.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP118\A0074751.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP118\A0074860.sys a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP118\A0075013.exe a variant of Win32/Kryptik.VRX trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP118\A0075016.exe probably a variant of Win32/Spy.KeyLogger.LFJNMOG trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{67C4541F-D3F2-450D-8BA3-DE79D55388CD}\RP118\A0075068.com a variant of Win32/Kryptik.VRX trojan cleaned by deleting - quarantined



Final OTL

OTL logfile created on: 12/31/2011 12:02:30 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Repair
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1011.88 Mb Total Physical Memory | 426.75 Mb Available Physical Memory | 42.17% Memory free
2.37 Gb Paging File | 1.56 Gb Available in Paging File | 65.85% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.20 Gb Total Space | 92.46 Gb Free Space | 64.57% Space Free | Partition Type: NTFS
Drive D: | 3.74 Gb Total Space | 1.77 Gb Free Space | 47.41% Space Free | Partition Type: FAT32

Computer Name: CHELSEA | User Name: KarenAltman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\KarenAltman\Local Settings\temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Repair\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_4211ca63\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_3f9cecc5\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_339e87c6\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_b7407c7b\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b54f917d\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\hpqprrsc\3.0.0.0__a53cf5803f4c3827\hpqprrsc.dll ()
MOD - c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll ()
MOD - c:\windows\assembly\gac\hpqmdmr\3.0.0.0__a53cf5803f4c3827\hpqmdmr.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.89__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.89__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.89__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.89__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\interop.hpdarc\1.0.0.0__19565c63d39c2842\interop.hpdarc.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\hpqntrop\3.0.0.0__a53cf5803f4c3827\hpqntrop.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - C:\Acer\Empowering Technology\eRecovery\it41.dll ()
MOD - C:\Acer\Empowering Technology\eRecovery\imagefile.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (N360) – C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111230.025\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111230.025\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111228.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111221.003\BHDrvx86.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (PTDUMdm) – C:\WINDOWS\system32\drivers\PTDUMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWWAN) – C:\WINDOWS\system32\drivers\PTDUWWAN.sys (DEVGURU Co., LTD.)
DRV - (PTDUBus) – C:\WINDOWS\system32\drivers\PTDUBus.sys (DEVGURU Co., LTD.)
DRV - (PTDUVsp) – C:\WINDOWS\system32\drivers\PTDUVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWFLT) – C:\WINDOWS\system32\drivers\PTDUWFLT.sys (DEVGURU Co., LTD.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (JMCR) – C:\WINDOWS\system32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (int15.sys) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sherman.edu/default.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 08 CD EE DC 07 3D CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/12/31 09:41:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_2_3 [2011/12/31 11:38:05 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/12/30 20:40:27 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe File not found
O4 - HKCU..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler File not found
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\KarenAltman\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1238028596453 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1 [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{209B0746-82B1-4AA0-B55C-2B9D77AB1DEF}: DhcpNameServer = [removed] [removed] 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\KarenAltman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\KarenAltman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/20 13:11:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/09/29 13:14:06 | 000,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O32 - AutoRun File - [2007/09/25 15:00:00 | 000,000,064 | —- | M] () - D:\AUTORUN.FCB – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/31 09:48:07 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/12/30 23:45:26 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/12/30 23:45:26 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/12/30 23:45:26 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/12/30 23:40:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/30 22:46:19 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/12/30 21:58:25 | 000,126,584 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/12/30 21:58:25 | 000,060,872 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2011/12/30 21:58:25 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/12/30 21:57:50 | 000,744,568 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymEFA.sys
[2011/12/30 21:57:50 | 000,516,216 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\srtsp.sys
[2011/12/30 21:57:50 | 000,369,784 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\symtdi.sys
[2011/12/30 21:57:50 | 000,340,088 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymDS.sys
[2011/12/30 21:57:50 | 000,331,384 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\symtdiv.sys
[2011/12/30 21:57:50 | 000,296,568 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\symnets.sys
[2011/12/30 21:57:50 | 000,136,312 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\Ironx86.sys
[2011/12/30 21:57:50 | 000,050,168 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0501000.01D\srtspx.sys
[2011/12/30 21:57:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2011/12/30 21:57:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0501000.01D
[2011/12/30 21:57:10 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2011/12/30 21:57:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Norton 360
[2011/12/30 21:56:28 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/12/30 17:04:56 | 000,000,000 | —D | C] – C:\_OTL
[2011/12/30 14:49:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2011/12/30 14:49:15 | 000,000,000 | —D | C] – C:\Documents and Settings\KarenAltman\Application Data\TestApp
[2011/12/30 13:06:51 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/12/30 13:06:51 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/12/30 13:06:51 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/12/30 13:06:51 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/12/30 13:05:32 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/12/30 13:04:15 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/30 13:03:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\KarenAltman\My Documents\My Videos
[2011/12/30 13:03:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2011/12/30 13:03:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\KarenAltman\Start Menu\Programs\Administrative Tools
[2011/12/30 09:27:49 | 000,000,000 | —D | C] – C:\Repair
[2011/12/25 08:47:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Chlesea other
[2011/12/25 08:47:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Chelsea Music
[2011/11/26 09:21:59 | 000,591,712 | —- | C] (SlimWare Utilities, Inc.) – C:\Program Files\FixCleanerSetup.exe
[2009/03/24 07:11:25 | 000,016,384 | —- | C] ( ) – C:\WINDOWS\System32\ClearEvent.exe
[2007/04/02 14:40:54 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2005/11/23 09:55:32 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[1 C:\Documents and Settings\KarenAltman\Desktop\*.tmp files -> C:\Documents and Settings\KarenAltman\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/31 12:00:00 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/31 11:42:23 | 000,443,482 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/31 11:42:23 | 000,072,582 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/31 11:38:33 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/31 11:37:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/31 11:37:34 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2011/12/31 09:34:28 | 000,000,451 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\Shortcut to OTL.exe.lnk
[2011/12/30 23:07:57 | 000,249,496 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/30 22:49:07 | 000,633,476 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\Cat.DB
[2011/12/30 22:48:51 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/30 21:58:25 | 000,126,584 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/12/30 21:58:25 | 000,060,872 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2011/12/30 21:58:25 | 000,007,468 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/12/30 21:58:25 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/12/30 21:57:57 | 000,001,904 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2011/12/30 21:55:27 | 000,000,774 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\Norton Installation Files.lnk
[2011/12/30 21:28:48 | 000,000,806 | —- | M] () – C:\Documents and Settings\KarenAltman\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2011/12/30 21:11:25 | 000,002,515 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\Microsoft Office Word 2007.lnk
[2011/12/30 20:40:27 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/30 20:18:10 | 000,000,510 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\Shortcut to ComboFix.exe.lnk
[2011/12/30 14:49:17 | 000,001,339 | —- | M] () – C:\Documents and Settings\KarenAltman\Desktop\sdsetup_aff.exe.lnk
[2011/12/18 18:25:15 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2011/12/18 16:22:54 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[1 C:\Documents and Settings\KarenAltman\Desktop\*.tmp files -> C:\Documents and Settings\KarenAltman\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/31 09:34:28 | 000,000,451 | —- | C] () – C:\Documents and Settings\KarenAltman\Desktop\Shortcut to OTL.exe.lnk
[2011/12/30 21:59:00 | 000,633,476 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\Cat.DB
[2011/12/30 21:58:25 | 000,007,468 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/12/30 21:58:25 | 000,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/12/30 21:57:57 | 000,001,904 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2011/12/30 21:57:50 | 000,000,000 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymDS.cat
[2011/12/30 21:57:21 | 000,001,474 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymNetV.inf
[2011/12/30 21:57:21 | 000,001,446 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymNet.inf
[2011/12/30 21:57:20 | 000,003,373 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymEFA.inf
[2011/12/30 21:57:20 | 000,002,792 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymDS.inf
[2011/12/30 21:57:20 | 000,001,389 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\srtspx.inf
[2011/12/30 21:57:20 | 000,001,383 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\srtsp.inf
[2011/12/30 21:57:20 | 000,000,742 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\Iron.inf
[2011/12/30 21:57:16 | 000,007,877 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\symnetv.cat
[2011/12/30 21:57:16 | 000,007,528 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\iron.cat
[2011/12/30 21:57:16 | 000,007,458 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymNet.cat
[2011/12/30 21:57:16 | 000,007,456 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\SymEFA.cat
[2011/12/30 21:57:16 | 000,007,454 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\srtspx.cat
[2011/12/30 21:57:16 | 000,007,450 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\srtsp.cat
[2011/12/30 21:57:15 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0501000.01D\isolate.ini
[2011/12/30 21:28:48 | 000,000,806 | —- | C] () – C:\Documents and Settings\KarenAltman\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2011/12/30 20:18:10 | 000,000,510 | —- | C] () – C:\Documents and Settings\KarenAltman\Desktop\Shortcut to ComboFix.exe.lnk
[2011/12/30 14:49:17 | 000,001,339 | —- | C] () – C:\Documents and Settings\KarenAltman\Desktop\sdsetup_aff.exe.lnk
[2011/12/30 13:06:51 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/12/30 13:06:51 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/12/30 13:06:51 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/12/30 13:06:51 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/12/30 13:06:51 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/10/19 19:12:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/11 10:21:04 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2011/02/08 14:45:53 | 000,008,192 | —- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 21:22:03 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/02/04 22:58:37 | 000,000,134 | —- | C] () – C:\Documents and Settings\KarenAltman\Local Settings\Application Data\fusioncache.dat
[2010/02/03 16:07:12 | 000,068,976 | —- | C] () – C:\WINDOWS\hpoins05.dat
[2010/02/03 16:07:12 | 000,019,696 | —- | C] () – C:\WINDOWS\hpomdl05.dat
[2009/09/11 21:26:45 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2009/02/22 12:17:10 | 000,001,233 | —- | C] () – C:\WINDOWS\SASETS.INI
[2009/01/20 18:12:56 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/20 18:12:26 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/20 15:20:46 | 000,443,482 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/20 15:20:46 | 000,072,582 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/20 15:04:02 | 000,249,496 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/20 13:11:22 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/20 13:09:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/08/21 15:43:36 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX2.dat
[2008/07/30 21:37:26 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/06/07 00:08:56 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/05/16 18:12:30 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2008/04/14 15:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 15:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 15:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 15:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 15:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 15:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 15:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 15:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/04/14 15:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/02/15 15:21:56 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2007/10/01 16:59:46 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys[2007/07/13 16:11:56 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2007/05/09 17:16:40 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2005/08/26 15:28:34 | 000,143,360 | —- | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 15:27:58 | 000,045,056 | —- | C] () – C:\WINDOWS\devenum.exe
[2005/06/27 07:29:50 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX0.dat
[2005/06/27 07:29:28 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\RTEQEX1.dat
[2005/03/28 17:45:26 | 000,000,135 | —- | C] () – C:\WINDOWS\ALaunch.ini
[2002/11/22 05:57:26 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2002/11/22 05:57:26 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2002/11/22 05:57:26 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2002/11/22 05:57:26 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2002/11/22 05:57:26 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2002/11/22 05:57:24 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2002/05/24 18:34:46 | 000,032,768 | —- | C] () – C:\WINDOWS\AMove.exe
[2001/08/26 19:04:08 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/26 19:02:42 | 000,004,524 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 212 bytes -> C:\WINDOWS\System32\msln.exe:5a504841a9fe46c47f7d0ae4768f2fac

< End of report >



Sorry. I am an idiot sometimes!

Thanks!
Jeremy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI