This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect Help [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been getting google redirects on a regular basis. Once redirected, if I hit "back" about 4 times it gets me back to the original page I wanted to go to.

Here's the OTL.txt paste

OTL logfile created on: 12/31/2011 4:21:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Operator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.06% Memory free
3.85 Gb Paging File | 3.01 Gb Available in Paging File | 78.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 224.61 Gb Free Space | 75.35% Space Free | Partition Type: NTFS

Computer Name: NEOBOX | User Name: Operator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Operator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\uagqecsvc.exe (Microsoft ® Corporation)
PRC - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Cisco\Cisco HostScan\bin\ciscod.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Symantec\VIP Access Client\VIPAppService.exe (Symantec Corporation)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe (IDT, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Java\jre6\bin\jp2iexp.dll ()
MOD - C:\Program Files\Java\jre6\bin\jp2native.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\WINDOWS\system32\quartz.dll ()


========== Win32 Services (SafeList) ==========

SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) – File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (uagqecsvc) – C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\uagqecsvc.exe (Microsoft ® Corporation)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (ciscod.exe) – C:\Program Files\Cisco\Cisco HostScan\bin\ciscod.exe (Cisco Systems, Inc.)
SRV - (VIPAppService) – C:\Program Files\Symantec\VIP Access Client\VIPAppService.exe (Symantec Corporation)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (PLFlash DeviceIoControl Service) – C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (STacSV) – c:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe (IDT, Inc.)


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (acsmux) – C:\WINDOWS\system32\drivers\acsmux.sys (Cisco Systems, Inc.)
DRV - (acsint) – C:\WINDOWS\system32\drivers\acsint.sys (Cisco Systems, Inc.)
DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidEqd) – C:\WINDOWS\system32\drivers\LHidEqd.sys (Logitech, Inc.)
DRV - (LEqdUsb) – C:\WINDOWS\system32\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files\CyberLink\PowerDVD8\000.fcl (CyberLink Corp.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\l151x86.sys (Atheros Communications, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (amdide) – C:\WINDOWS\system32\DRIVERS\amdide.sys (Advanced Micro Devices)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (RTL85n86) – C:\WINDOWS\system32\drivers\RTL85n86.sys (Realtek)
DRV - (AmdTools) – C:\WINDOWS\system32\drivers\AmdTools.sys (AMD, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://us.etrade.com/e/t/user/login
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr;=&q;=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl;=en&ie;=UTF-8&q;=%s&btnG;=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l;=55α=%s&S;=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip;=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 49
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.496
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/05/15 22:14:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Symantec\VIP Access Client\ [2011/11/15 10:05:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/31 13:07:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/31 13:07:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/11/22 19:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/05/15 22:14:40 | 000,000,000 | —D | M]

[2009/11/18 17:46:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Operator\Application Data\Mozilla\Extensions
[2011/12/29 00:47:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\pltn1dws.default\extensions
[2010/08/22 00:47:19 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\pltn1dws.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2011/12/31 10:58:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/31 10:58:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\OPERATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PLTN1DWS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/27 21:17:10 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/06/21 17:39:18 | 000,034,376 | —- | M] () – C:\Program Files\mozilla firefox\plugins\logging.dll
[2011/11/10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/27 21:17:07 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/27 21:17:07 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/12/31 00:54:19 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [AttachmentWipermailadc.fmi.com] C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\AttachmentWiper.exeBatchRun\run.bat ()
O4 - Startup: C:\Documents and Settings\Operator\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Operator\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Operator\Start Menu\Programs\Startup\JMicron Button Manager.lnk = C:\Program Files\JMicron\JMBtnMgr.EXE (JMicron Technology Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33704B0F-9EB7-434B-B752-EA6CFFB87423} http://babyjoancam.viewnetcam.com/JpegInst.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.6.0.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A2A8145-77D0-4161-9819-B56481B30B4B}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87C853CB-5E40-4847-9422-C7C7EB90F223}: DhcpNameServer = 192.168.10.1 [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1179609-0B0F-4589-9F58-942E0FE88BD0}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/25 17:25:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/31 16:20:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/12/31 13:16:31 | 000,000,000 | —D | C] – C:\ComboFix
[2011/12/31 11:03:25 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Operator\Recent
[2011/12/31 10:58:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/12/31 10:58:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/31 10:58:16 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/12/31 10:58:16 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/12/31 10:58:16 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/12/31 10:58:16 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/12/31 10:56:24 | 000,910,112 | —- | C] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/30 17:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\Wak
[2011/12/30 17:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\Myy
[2011/12/30 14:45:17 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/30 13:03:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\.minecraft
[2011/12/29 01:09:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2011/12/29 01:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/12/29 00:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Local Settings\Application Data\Temp
[2011/12/29 00:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/12/29 00:56:40 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/12/29 00:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Local Settings\Application Data\Google
[2011/12/29 00:55:47 | 000,000,000 | —D | C] – C:\Program Files\Downloads
[2011/12/28 18:12:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/12/23 16:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/23 15:25:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/23 15:25:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/31 16:25:14 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/31 16:20:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/12/31 16:06:01 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/31 15:09:14 | 000,000,394 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Operator Logon.job
[2011/12/31 14:15:47 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/31 14:15:41 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/31 14:15:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/31 13:14:30 | 004,358,797 | R— | M] (Swearware) – C:\Documents and Settings\Operator\Desktop\ComboFix.exe
[2011/12/31 13:05:22 | 000,270,142 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/31 10:56:23 | 000,910,112 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/31 00:54:19 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/30 17:43:34 | 000,017,522 | -HS- | M] () – C:\Documents and Settings\Operator\Local Settings\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 17:43:34 | 000,017,522 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 14:45:37 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/12/30 13:15:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/29 01:09:37 | 000,001,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/29 01:09:37 | 000,001,798 | —- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/29 00:58:53 | 000,000,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/28 22:31:01 | 000,000,752 | —- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\iexplore.exe.lnk
[2011/12/28 18:50:52 | 000,000,752 | —- | M] () – C:\Documents and Settings\Operator\Desktop\iexplore.exe.lnk
[2011/12/28 18:26:38 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/28 17:59:16 | 000,017,544 | -HS- | M] () – C:\Documents and Settings\Operator\Local Settings\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/28 17:59:16 | 000,017,544 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/24 12:34:31 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\n6JNdr64.dat
[2011/12/24 12:34:31 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ssY84kwL.com.b
[2011/12/23 11:54:08 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/12/18 23:35:22 | 000,001,732 | -H– | M] () – C:\Documents and Settings\Operator\My Documents\Default.rdp
[2011/12/18 10:10:33 | 000,083,360 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIRfsClientNP.dll
[2011/12/18 10:10:32 | 000,087,424 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIinit.dll
[2011/12/18 10:10:32 | 000,030,592 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIport.dll
[2011/12/18 10:08:11 | 000,356,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/10 11:43:38 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/12/05 21:55:59 | 000,000,172 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Google.url
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/31 13:05:22 | 000,270,142 | —- | C] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/30 17:41:28 | 000,017,522 | -HS- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 17:41:28 | 000,017,522 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/29 01:09:37 | 000,001,820 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/29 01:09:37 | 000,001,798 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/29 00:56:44 | 000,000,890 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/29 00:56:44 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/28 22:31:01 | 000,000,752 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\iexplore.exe.lnk
[2011/12/28 18:50:52 | 000,000,752 | —- | C] () – C:\Documents and Settings\Operator\Desktop\iexplore.exe.lnk
[2011/12/28 18:26:38 | 000,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/24 12:34:31 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ssY84kwL.com.b
[2011/12/24 10:19:36 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\n6JNdr64.dat
[2011/12/23 15:26:54 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/23 15:13:49 | 000,017,544 | -HS- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/23 15:13:49 | 000,017,544 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/11/24 13:26:42 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/24 12:39:20 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/11/24 12:39:20 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/11/24 12:39:20 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/11/24 12:39:20 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/11/24 12:39:20 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/21 07:13:48 | 000,139,128 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/07/21 07:13:48 | 000,138,056 | —- | C] () – C:\Documents and Settings\Operator\Application Data\PnkBstrK.sys
[2011/07/21 07:13:23 | 000,215,128 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2011/07/21 07:13:21 | 002,434,856 | —- | C] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2011/07/21 07:13:21 | 000,075,064 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2011/05/15 22:05:56 | 000,205,918 | —- | C] () – C:\WINDOWS\hpoins46.dat
[2011/05/15 22:05:56 | 000,000,601 | —- | C] () – C:\WINDOWS\hpomdl46.dat
[2010/06/11 02:40:10 | 000,000,707 | —- | C] () – C:\Documents and Settings\Operator\Application Data\myMPQ.ini
[2010/02/28 13:40:03 | 000,004,430 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft Excel 97-2003.NOT
[2010/02/28 13:38:17 | 000,038,260 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft Excel 97-2003.ADR
[2009/12/30 22:00:31 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/21 20:27:20 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/21 18:25:29 | 000,043,520 | —- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/18 13:09:50 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2009/12/18 13:09:49 | 000,196,565 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2009/12/18 13:09:49 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2009/11/26 12:44:05 | 000,078,712 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/18 17:46:12 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/20 13:40:14 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/08/25 17:53:42 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2008/08/25 17:37:41 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2008/08/25 17:37:33 | 003,107,788 | R— | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2008/08/25 17:27:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/08/25 17:22:36 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/08/25 12:11:03 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/08/25 12:09:58 | 000,356,952 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/07/16 13:35:28 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 02:55:28 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/21 16:51:16 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2007/08/21 14:36:12 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2007/06/24 20:14:55 | 000,008,336 | —- | C] () – C:\WINDOWS\UN060501.INI
[2006/12/31 04:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 05:00:00 | 000,465,398 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 05:00:00 | 000,079,540 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 05:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/09/25 22:30:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/11/15 10:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco
[2011/03/20 11:56:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/02/05 15:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/12/31 00:17:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/11/24 12:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/02/28 12:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/08/27 12:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/26 12:37:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/12/30 13:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\.minecraft
[2011/06/04 16:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Audacity
[2011/11/06 11:01:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\AVG
[2011/12/31 13:03:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Dropbox
[2011/02/10 09:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\ICAClient
[2011/05/15 21:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Leadertech
[2011/12/31 13:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Myy
[2011/07/20 21:00:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\SystemRequirementsLab
[2010/03/10 01:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\TechSmith
[2011/09/11 23:22:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Thunderbird
[2011/12/31 11:03:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Wak
[2008/08/25 18:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Windows Desktop Search
[2010/01/01 13:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Windows Search
[2011/12/31 15:09:14 | 000,000,394 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Start On Operator Logon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/11/25 15:14:12 | 000,001,024 | —- | M] () – C:\.rnd
[2008/08/25 17:25:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/11/24 12:46:43 | 000,000,339 | —- | M] () – C:\Boot.bak
[2011/12/30 14:45:37 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/12/31 15:09:18 | 000,018,805 | —- | M] () – C:\ComboFix.txt
[2008/08/25 17:25:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/11/24 19:00:37 | 006,430,218 | —- | M] () – C:\immudebug.log
[2008/08/25 17:25:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/08/25 17:25:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 19:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 21:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/31 14:15:29 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/08/25 17:24:54 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/10/21 14:29:40 | 000,320,512 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp101.dll
[2011/12/18 10:10:33 | 000,052,096 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/08/25 12:09:18 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/08/25 12:09:18 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/08/25 12:09:18 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/25 17:25:21 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/25 17:29:35 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/11/23 16:27:45 | 003,511,776 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Operator\Desktop\ccsetup312.exe
[2011/12/31 13:14:30 | 004,358,797 | R— | M] (Swearware) – C:\Documents and Settings\Operator\Desktop\ComboFix.exe
[2011/12/31 10:56:23 | 000,910,112 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/31 13:05:22 | 000,270,142 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/31 16:20:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/11/06 22:01:53 | 002,167,144 | —- | M] (SolidQuest Inc. ) – C:\Documents and Settings\Operator\Desktop\RegTeck_setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-31 16:56:03

========== Alternate Data Streams ==========

@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, joshthegoat

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

First of all, Happy New Year! :)

As you may or may not know, we generally do not advise people to run Combofix without helper's supervision. Anyhow, please post the CF log in your next reply. Thanks.

—————————————————————————————————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI