shadow5
Topic Starter
Spyware / Malware / Virus Removal
"XP Antispyware 2012" with WinXP Pro SP3 [Solved]
19 min read
shadow5
oldman960
Hi shadow5, welcome to the forum.
To make cleaning this machine easier
When you download this next tool please rename it to OTL.scr before you download it.
Download OTL to your desktop.
Next, Double click on OTL.exe
Then click the Run Fix button at the top
Next
When running this next tool when asked to download Avast's definitions please click yes.
Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
Please post back with
Thanks
To make cleaning this machine easier
- Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs. - Please do not run any scans other than those requested
- Please follow all instructions in the order posted
- All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
- Do not attach any logs/reports, etc.. unless specifically requested to do so.
- If you have problems with or do not understand the instructions, Please ask before continuing.
- Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
When you download this next tool please rename it to OTL.scr before you download it.
Download OTL to your desktop.
Next, Double click on OTL.exe
- Under the Custom Scans/Fixes box at the bottom, paste in the following
- Do Not copy the word CODE
- please note the fix starts with the :
:Services :Reg [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "a29a5f0c"=- :Files c:\documents and settings\user\local settings\application data\qkm.exe :Commands [purity] [createrestorepoint]
Then click the Run Fix button at the top
- Let the program run unhindered
- Please save the resulting log to be posted in your next reply.
- Reboot your computer
Next
When running this next tool when asked to download Avast's definitions please click yes.
Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
Please post back with
- OTL fix log
- aswMBR log
- mbr.zip (attached)
Thanks
shadow5
Thank you! The virus won't let me change the name. I d/l'd it on another computer, renaming it as you asked, copied to thumb drive, and tried to move that, renamed, to desktop of affected computer. It would not copy as anything but "OTL". I then put a shortcut to OTL.scr on my bad desktop–tried to double-click it, & virus blocked even that (as it was trying to execute a screen). What should I try next? s
oldman960
Hi shadow5,
Since you got DDS.scr to run try downloading a new copy of OTL renamed to DDS.scr
If you still can't get it to run let me know we still have some other tricks.
shadow5
Sorry I was not clear–I never got DDS.scr to run. Closest was when I downloaded it with new name to a thumb drive on a clean computer, then put thumb drive into bad computer, added a shortcut to thumb drive onto desktop, and "attempted" to execute it. Virus immediately blocked it from running. ALSO: virus will not allow me to open "notepad". Help is still very much appreciated. s
oldman960
Hi shadow5,
Sorry I'm a bit confused. The first log you posted was from DDS.scr How did you manage to get that log?
Try running OTL in Safe Mode. We'll change the operating instructions a bit.
On your clean machine download and save a copy of OTL to your thumbdrive.
Copy and paste the all the text in the codebox into a notepad
(Do Not copy the word CODE
please note the fix starts with the :)
In the notepad
Transfer the thumbdrive to the sick computer:
Please then reboot your computer in Safe Mode by doing the following :
I'm not sure if OTL will run from the thumb drive so try moving it to the desktop.
Sorry I'm a bit confused. The first log you posted was from DDS.scr How did you manage to get that log?
Try running OTL in Safe Mode. We'll change the operating instructions a bit.
On your clean machine download and save a copy of OTL to your thumbdrive.
Copy and paste the all the text in the codebox into a notepad
(Do Not copy the word CODE
please note the fix starts with the :)
:Services :Reg [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "a29a5f0c"=- :Files c:\documents and settings\user\local settings\application data\qkm.exe :Commands
In the notepad
- Click File, Save as…, and set the Save in to your thumbdrive
- In the filename box, type (including quotation marks) as the filename: "scan.txt"
- Click save
Transfer the thumbdrive to the sick computer:
Please then reboot your computer in Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, a menu with options should appear;
- Select the first option, to run Windows in Safe Mode, then press "Enter".
- Choose your usual account.
I'm not sure if OTL will run from the thumb drive so try moving it to the desktop.
- transfer both OTL and scan.txt to the infected computer's desktop
- Open OTL by double clicking it
- double click in the white window at the bottom
- a message will appear asking if you want to load a custom scan, click yes
- navigate to where you saved the notepad scan.txt and click on it
- click open
- the text should appear in the window.
- Click the run Fix button
shadow5
Hi, oldman60. I tried your last directions. The scan, in safe mode, showed in its log "Error:could not determine(?)…" all thru the log. I cannot open any…none…Notepad in the sick computer while in normal (not "SAFE") mode. This forum-program will not respond to its "Browse" function either. I tried copying log file while opened in Safe Mode, but when rebooting to normal, the copy was lost during reboot to normal.
All seemed to work up to where I ran OTL in Safe Mode; that is until the results log showed all errors.
Any other ideas? This seems to be an updated version of the malware, as I cannot use my Notepad or Forum's "Browse".
s
shadow5
I just realized an error I reported: I DID get DDS.scr to run. But I am offered no chance to rename OTL(to "DDS.scr") before downloading it. Even when I d/l it, renamed, on my laptop & copy to thumb drive, it copies to my sick computer as un-renamed–just "OTL"–which is blocked by malware when I try to run it on sick comp. When I ran DDS.scr, I had to copy/paste one log to other one (while both were open as I could not later open them or attach them into the "Browser function" on the forum.), and then paste the entire 'modified log' which I then pasted to the forum message-box.
s
oldman960
Hi shadow5,
Let's try this. When booting ti safe mode make sure you boot into your usual account.
After your computer restarts in safe mofe:
Open windows explorer (right click the Start button and click Explore)
At the top of windows explorer, click tools, folder options, click the
view tab
Navigate to this folder
c:\documents and settings\user\local settings\application data
Try moving OTL to the desktop. Open it and click the quick scan button. Save the log to the usb device.
Reboot to normal windows. You may recieve a message that windows cannot find a file, don't worry about that will be normal. See if you can access this forum with the infected computer and post the log log.
Let's try this. When booting ti safe mode make sure you boot into your usual account.
After your computer restarts in safe mofe:
Open windows explorer (right click the Start button and click Explore)
At the top of windows explorer, click tools, folder options, click the
view tab
- check Display the contents of system folders
- check Show hidden files and folders
- uncheck "Hide extensions for known file types" box
- uncheck "Hide protecting operating system files" box
Navigate to this folder
c:\documents and settings\user\local settings\application data
- in the right hand panel locate qkm.exe
- right click on it and click rename
- type qkm.old
- hit enter
- Accept any warning you may recieve.
- make sure the file name is now qkm.old
- Close windows explorer
Try moving OTL to the desktop. Open it and click the quick scan button. Save the log to the usb device.
Reboot to normal windows. You may recieve a message that windows cannot find a file, don't worry about that will be normal. See if you can access this forum with the infected computer and post the log log.
shadow5
Contained is the log u requested. Could not find "Browse" function; but I was able to open the log file, & copy/paste to this dialogue box. Hoping this is working. and, thx again for your help.
s
OTL logfile created on: 1/18/2012 4:09:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 3.22 Gb Available Physical Memory | 92.09% Memory free
5.34 Gb Paging File | 5.28 Gb Available in Paging File | 98.81% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 45.94 Gb Free Space | 19.73% Space Free | Partition Type: NTFS
Drive F: | 1.92 Gb Total Space | 0.13 Gb Free Space | 7.04% Space Free | Partition Type: FAT32
Computer Name: USER-A6AA68022B | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/07/15 08:26:19 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2005/10/07 15:05:32 | 000,125,440 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – – (Lavasoft Ad-Aware Service)
SRV - [2011/07/09 11:12:41 | 000,072,704 | —- | M] (Autodata Limited) [Auto | Stopped] – C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe – (Autodata Limited License Service)
SRV - [2011/02/28 17:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/07/21 07:57:49 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 08:26:40 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/07 17:48:38 | 000,817,264 | —- | M] (Acronis) [Auto | Stopped] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2004/03/18 15:55:48 | 000,065,536 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - [2011/09/13 08:47:23 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/25 01:00:36 | 000,064,512 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2011/05/05 08:57:46 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/11/29 07:35:17 | 000,594,208 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\timntr.sys – (timounter)
DRV - [2010/11/29 07:35:10 | 000,170,272 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2010/07/15 08:26:20 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/11/03 06:39:04 | 005,940,736 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/07/28 03:55:00 | 000,143,360 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/05/06 15:06:00 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2008/04/13 12:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/03/13 10:02:41 | 000,019,712 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2008/03/13 10:02:24 | 000,018,304 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2003/10/14 16:10:00 | 000,036,484 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SMBios.sys – (SMBios) Intel ®
DRV - [2002/06/03 11:20:36 | 000,072,704 | —- | M] (ESS Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\es1969.sys – (es1969) ESS 1969 Audio Driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 04:38:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/09 16:59:08 | 000,000,000 | —D | M]
[2012/01/18 10:38:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/11/12 09:29:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/30 04:38:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/12 09:29:49 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 09:29:49 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/08/29 12:39:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259740138859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pbells.broadjump.com/wizlet/attPreQ…otiveClient.cab (WebBrowserType Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{56181B06-BEDD-4D31-B675-B7E3A12166AF}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 13:58:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/07/14 19:07:26 | 000,186,168 | —- | M] () - F:\auto-speedo-meter hookup.png – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/18 11:15:09 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/18 11:13:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2012/01/18 10:18:52 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Application Data
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
[2012/01/18 10:18:52 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Templates
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Recent
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Favorites
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 15:55:28 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/18 15:55:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/18 15:11:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/18 15:03:45 | 000,009,849 | —- | M] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2012/01/18 12:02:59 | 000,272,537 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/01/18 12:02:57 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/18 08:07:02 | 091,852,927 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/01/15 13:37:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/14 09:59:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/12 17:00:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/12 16:56:28 | 000,475,262 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/12 16:56:28 | 000,085,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/04 18:28:43 | 000,001,334 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/18 10:18:52 | 000,001,599 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
[2012/01/18 10:18:52 | 000,000,792 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
[2012/01/17 10:45:14 | 000,009,849 | —- | C] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2011/08/22 18:28:51 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/08 09:49:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2011/06/08 09:27:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/08 09:27:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/07 19:30:42 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2011/06/07 19:30:42 | 000,028,885 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2011/06/07 19:10:52 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2011/05/25 12:30:48 | 359,953,472 | —- | C] () – C:\Program Files\gc_w01_ENU_NB.exe
[2011/05/25 09:59:20 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/25 09:59:20 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/05/25 07:05:27 | 000,103,703 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/05/25 07:05:27 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2011/05/25 06:29:25 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/05/24 02:18:00 | 000,000,120 | —- | C] () – C:\WINDOWS\Esiwof.dat
[2011/05/24 02:18:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Npuqut.bin
[2010/06/18 18:38:18 | 000,000,304 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2010/02/25 11:38:32 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2010/02/25 11:38:24 | 000,004,480 | —- | C] () – C:\WINDOWS\od5.ini
[2010/01/11 08:43:55 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/03 18:15:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/12/01 03:33:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2009/11/30 19:44:53 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2009/11/30 19:42:36 | 000,001,334 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/11/30 19:42:36 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2009/11/30 17:50:14 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/11/30 17:12:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/11/30 15:40:21 | 002,293,286 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/11/30 14:00:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/11/30 13:56:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/11/30 08:48:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/11/30 08:47:34 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,475,262 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,085,074 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/11/29 07:36:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/07/09 11:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodata Limited
[2009/11/30 17:27:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 07:27:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/31 10:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaRad
[2011/02/03 16:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2012/01/16 17:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE
< End of report >
s
OTL logfile created on: 1/18/2012 4:09:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 3.22 Gb Available Physical Memory | 92.09% Memory free
5.34 Gb Paging File | 5.28 Gb Available in Paging File | 98.81% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 45.94 Gb Free Space | 19.73% Space Free | Partition Type: NTFS
Drive F: | 1.92 Gb Total Space | 0.13 Gb Free Space | 7.04% Space Free | Partition Type: FAT32
Computer Name: USER-A6AA68022B | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/07/15 08:26:19 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2005/10/07 15:05:32 | 000,125,440 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – – (Lavasoft Ad-Aware Service)
SRV - [2011/07/09 11:12:41 | 000,072,704 | —- | M] (Autodata Limited) [Auto | Stopped] – C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe – (Autodata Limited License Service)
SRV - [2011/02/28 17:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/07/21 07:57:49 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 08:26:40 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/07 17:48:38 | 000,817,264 | —- | M] (Acronis) [Auto | Stopped] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2004/03/18 15:55:48 | 000,065,536 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - [2011/09/13 08:47:23 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/25 01:00:36 | 000,064,512 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2011/05/05 08:57:46 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/11/29 07:35:17 | 000,594,208 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\timntr.sys – (timounter)
DRV - [2010/11/29 07:35:10 | 000,170,272 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2010/07/15 08:26:20 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/11/03 06:39:04 | 005,940,736 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/07/28 03:55:00 | 000,143,360 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/05/06 15:06:00 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2008/04/13 12:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/03/13 10:02:41 | 000,019,712 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2008/03/13 10:02:24 | 000,018,304 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2003/10/14 16:10:00 | 000,036,484 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SMBios.sys – (SMBios) Intel ®
DRV - [2002/06/03 11:20:36 | 000,072,704 | —- | M] (ESS Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\es1969.sys – (es1969) ESS 1969 Audio Driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 04:38:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/09 16:59:08 | 000,000,000 | —D | M]
[2012/01/18 10:38:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/11/12 09:29:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/30 04:38:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/12 09:29:49 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 09:29:49 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/08/29 12:39:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259740138859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pbells.broadjump.com/wizlet/attPreQ…otiveClient.cab (WebBrowserType Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{56181B06-BEDD-4D31-B675-B7E3A12166AF}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 13:58:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/07/14 19:07:26 | 000,186,168 | —- | M] () - F:\auto-speedo-meter hookup.png – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/18 11:15:09 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/18 11:13:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2012/01/18 10:18:52 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Application Data
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
[2012/01/18 10:18:52 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Templates
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Recent
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Favorites
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 15:55:28 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/18 15:55:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/18 15:11:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/18 15:03:45 | 000,009,849 | —- | M] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2012/01/18 12:02:59 | 000,272,537 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/01/18 12:02:57 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/18 08:07:02 | 091,852,927 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/01/15 13:37:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/14 09:59:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/12 17:00:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/12 16:56:28 | 000,475,262 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/12 16:56:28 | 000,085,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/04 18:28:43 | 000,001,334 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/18 10:18:52 | 000,001,599 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
[2012/01/18 10:18:52 | 000,000,792 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
[2012/01/17 10:45:14 | 000,009,849 | —- | C] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2011/08/22 18:28:51 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/08 09:49:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2011/06/08 09:27:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/08 09:27:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/07 19:30:42 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2011/06/07 19:30:42 | 000,028,885 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2011/06/07 19:10:52 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2011/05/25 12:30:48 | 359,953,472 | —- | C] () – C:\Program Files\gc_w01_ENU_NB.exe
[2011/05/25 09:59:20 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/25 09:59:20 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/05/25 07:05:27 | 000,103,703 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/05/25 07:05:27 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2011/05/25 06:29:25 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/05/24 02:18:00 | 000,000,120 | —- | C] () – C:\WINDOWS\Esiwof.dat
[2011/05/24 02:18:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Npuqut.bin
[2010/06/18 18:38:18 | 000,000,304 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2010/02/25 11:38:32 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2010/02/25 11:38:24 | 000,004,480 | —- | C] () – C:\WINDOWS\od5.ini
[2010/01/11 08:43:55 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/03 18:15:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/12/01 03:33:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2009/11/30 19:44:53 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2009/11/30 19:42:36 | 000,001,334 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/11/30 19:42:36 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2009/11/30 17:50:14 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/11/30 17:12:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/11/30 15:40:21 | 002,293,286 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/11/30 14:00:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/11/30 13:56:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/11/30 08:48:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/11/30 08:47:34 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,475,262 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,085,074 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/11/29 07:36:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/07/09 11:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodata Limited
[2009/11/30 17:27:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 07:27:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/31 10:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaRad
[2011/02/03 16:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2012/01/16 17:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE
< End of report >
oldman960
Hi shadow5,
Are you refering to the browae button at the lower right of the reply windows?
Have you tried booting to normal windows?
shadow5
Yes, I was referring to the browse button at the lower right of the reply windows. And yes, I can now boot to normal windows. And all functions I've tried(Notepad, O/Exp., Internet sites) seem to work correctly/normally. Also, the Malware-Icon has disappeared from the lower right corner of my desktop–NO SIGNS of malware! Whoopee! You're the man–or 'oldman960' if you prefer. Anything else I need to do?
Thanks, s
oldman960
Hi shadow5,
Let's look a little deeper and see if there is anything remaining.
We'll see if we can resolve the browse button issue later. What is diplayed at the lower right where the button should be?
When running this next tool when asked to download Avast's definitions please click yes.
Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Please post back with
Thanks
Let's look a little deeper and see if there is anything remaining.
We'll see if we can resolve the browse button issue later. What is diplayed at the lower right where the button should be?
When running this next tool when asked to download Avast's definitions please click yes.
Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Please post back with
- OTL fix log
- aswMBR log
Thanks
shadow5
Here are the files/logs I believe you are asking for. The OTL log is what I had saved in my thumbdrive. The aswMBR log is the saved log from running the aswMBR.exe from my previously-sick computer's desktop. I just realized I do not know how to attach files via the Forum's Browser-Add Attachment function–I can only access it by first clicking on "New Topic". Rather than going further at that point, I just opened the Notebook-files, copied the info via "Select All", and pasted it into Forum's "Fast Reply" box.
s
posted files:
OTL.Txt log:
OTL logfile created on: 1/18/2012 4:09:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 3.22 Gb Available Physical Memory | 92.09% Memory free
5.34 Gb Paging File | 5.28 Gb Available in Paging File | 98.81% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 45.94 Gb Free Space | 19.73% Space Free | Partition Type: NTFS
Drive F: | 1.92 Gb Total Space | 0.13 Gb Free Space | 7.04% Space Free | Partition Type: FAT32
Computer Name: USER-A6AA68022B | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/07/15 08:26:19 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2005/10/07 15:05:32 | 000,125,440 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – – (Lavasoft Ad-Aware Service)
SRV - [2011/07/09 11:12:41 | 000,072,704 | —- | M] (Autodata Limited) [Auto | Stopped] – C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe – (Autodata Limited License Service)
SRV - [2011/02/28 17:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/07/21 07:57:49 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 08:26:40 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/07 17:48:38 | 000,817,264 | —- | M] (Acronis) [Auto | Stopped] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2004/03/18 15:55:48 | 000,065,536 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - [2011/09/13 08:47:23 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/25 01:00:36 | 000,064,512 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2011/05/05 08:57:46 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/11/29 07:35:17 | 000,594,208 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\timntr.sys – (timounter)
DRV - [2010/11/29 07:35:10 | 000,170,272 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2010/07/15 08:26:20 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/11/03 06:39:04 | 005,940,736 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/07/28 03:55:00 | 000,143,360 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/05/06 15:06:00 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2008/04/13 12:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/03/13 10:02:41 | 000,019,712 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2008/03/13 10:02:24 | 000,018,304 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2003/10/14 16:10:00 | 000,036,484 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SMBios.sys – (SMBios) Intel ®
DRV - [2002/06/03 11:20:36 | 000,072,704 | —- | M] (ESS Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\es1969.sys – (es1969) ESS 1969 Audio Driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 04:38:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/09 16:59:08 | 000,000,000 | —D | M]
[2012/01/18 10:38:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/11/12 09:29:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/30 04:38:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/12 09:29:49 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 09:29:49 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/08/29 12:39:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259740138859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pbells.broadjump.com/wizlet/attPreQ…otiveClient.cab (WebBrowserType Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{56181B06-BEDD-4D31-B675-B7E3A12166AF}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 13:58:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/07/14 19:07:26 | 000,186,168 | —- | M] () - F:\auto-speedo-meter hookup.png – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/18 11:15:09 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/18 11:13:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2012/01/18 10:18:52 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Application Data
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
[2012/01/18 10:18:52 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Templates
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Recent
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Favorites
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 15:55:28 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/18 15:55:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/18 15:11:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/18 15:03:45 | 000,009,849 | —- | M] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2012/01/18 12:02:59 | 000,272,537 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/01/18 12:02:57 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/18 08:07:02 | 091,852,927 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/01/15 13:37:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/14 09:59:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/12 17:00:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/12 16:56:28 | 000,475,262 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/12 16:56:28 | 000,085,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/04 18:28:43 | 000,001,334 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/18 10:18:52 | 000,001,599 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
[2012/01/18 10:18:52 | 000,000,792 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
[2012/01/17 10:45:14 | 000,009,849 | —- | C] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2011/08/22 18:28:51 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/08 09:49:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2011/06/08 09:27:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/08 09:27:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/07 19:30:42 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2011/06/07 19:30:42 | 000,028,885 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2011/06/07 19:10:52 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2011/05/25 12:30:48 | 359,953,472 | —- | C] () – C:\Program Files\gc_w01_ENU_NB.exe
[2011/05/25 09:59:20 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/25 09:59:20 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/05/25 07:05:27 | 000,103,703 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/05/25 07:05:27 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2011/05/25 06:29:25 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/05/24 02:18:00 | 000,000,120 | —- | C] () – C:\WINDOWS\Esiwof.dat
[2011/05/24 02:18:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Npuqut.bin
[2010/06/18 18:38:18 | 000,000,304 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2010/02/25 11:38:32 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2010/02/25 11:38:24 | 000,004,480 | —- | C] () – C:\WINDOWS\od5.ini
[2010/01/11 08:43:55 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/03 18:15:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/12/01 03:33:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2009/11/30 19:44:53 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2009/11/30 19:42:36 | 000,001,334 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/11/30 19:42:36 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2009/11/30 17:50:14 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/11/30 17:12:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/11/30 15:40:21 | 002,293,286 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/11/30 14:00:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/11/30 13:56:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/11/30 08:48:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/11/30 08:47:34 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,475,262 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,085,074 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/11/29 07:36:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/07/09 11:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodata Limited
[2009/11/30 17:27:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 07:27:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/31 10:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaRad
[2011/02/03 16:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2012/01/16 17:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE
< End of report >
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
aswMBR.txt log:
aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-18 19:38:14
—————————–
19:38:14.953 OS Version: Windows 5.1.2600 Service Pack 3
19:38:14.953 Number of processors: 2 586 0x1706
19:38:14.953 ComputerName: USER-A6AA68022B UserName: USER
19:38:15.500 Initialize success
19:39:53.187 AVAST engine defs: 12011801
19:42:39.000 The log file has been saved successfully to "C:\Documents and Settings\USER\Desktop\aswMBR.txt"
s
posted files:
OTL.Txt log:
OTL logfile created on: 1/18/2012 4:09:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 3.22 Gb Available Physical Memory | 92.09% Memory free
5.34 Gb Paging File | 5.28 Gb Available in Paging File | 98.81% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 45.94 Gb Free Space | 19.73% Space Free | Partition Type: NTFS
Drive F: | 1.92 Gb Total Space | 0.13 Gb Free Space | 7.04% Space Free | Partition Type: FAT32
Computer Name: USER-A6AA68022B | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/07/15 08:26:19 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2005/10/07 15:05:32 | 000,125,440 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – – (Lavasoft Ad-Aware Service)
SRV - [2011/07/09 11:12:41 | 000,072,704 | —- | M] (Autodata Limited) [Auto | Stopped] – C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe – (Autodata Limited License Service)
SRV - [2011/02/28 17:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/07/21 07:57:49 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 08:26:40 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/07 17:48:38 | 000,817,264 | —- | M] (Acronis) [Auto | Stopped] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2004/03/18 15:55:48 | 000,065,536 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - [2011/09/13 08:47:23 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/25 01:00:36 | 000,064,512 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2011/05/05 08:57:46 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/11/29 07:35:17 | 000,594,208 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\timntr.sys – (timounter)
DRV - [2010/11/29 07:35:10 | 000,170,272 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2010/07/15 08:26:20 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/11/03 06:39:04 | 005,940,736 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/07/28 03:55:00 | 000,143,360 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/05/06 15:06:00 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2008/04/13 12:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/03/13 10:02:41 | 000,019,712 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2008/03/13 10:02:24 | 000,018,304 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2003/10/14 16:10:00 | 000,036,484 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SMBios.sys – (SMBios) Intel ®
DRV - [2002/06/03 11:20:36 | 000,072,704 | —- | M] (ESS Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\es1969.sys – (es1969) ESS 1969 Audio Driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 04:38:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/09 16:59:08 | 000,000,000 | —D | M]
[2012/01/18 10:38:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/11/12 09:29:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/30 04:38:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/12 09:29:49 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 09:29:49 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/08/29 12:39:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259740138859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pbells.broadjump.com/wizlet/attPreQ…otiveClient.cab (WebBrowserType Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{56181B06-BEDD-4D31-B675-B7E3A12166AF}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 13:58:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/07/14 19:07:26 | 000,186,168 | —- | M] () - F:\auto-speedo-meter hookup.png – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/18 11:15:09 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/18 11:13:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2012/01/18 10:18:52 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Application Data
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
[2012/01/18 10:18:52 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Templates
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Recent
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Favorites
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 15:55:28 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/18 15:55:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/18 15:11:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/18 15:03:45 | 000,009,849 | —- | M] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2012/01/18 12:02:59 | 000,272,537 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/01/18 12:02:57 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/18 08:07:02 | 091,852,927 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/01/15 13:37:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/14 09:59:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/12 17:00:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/12 16:56:28 | 000,475,262 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/12 16:56:28 | 000,085,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/04 18:28:43 | 000,001,334 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/18 10:18:52 | 000,001,599 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
[2012/01/18 10:18:52 | 000,000,792 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
[2012/01/17 10:45:14 | 000,009,849 | —- | C] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2011/08/22 18:28:51 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/08 09:49:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2011/06/08 09:27:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/08 09:27:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/07 19:30:42 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2011/06/07 19:30:42 | 000,028,885 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2011/06/07 19:10:52 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2011/05/25 12:30:48 | 359,953,472 | —- | C] () – C:\Program Files\gc_w01_ENU_NB.exe
[2011/05/25 09:59:20 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/25 09:59:20 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/05/25 07:05:27 | 000,103,703 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/05/25 07:05:27 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2011/05/25 06:29:25 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/05/24 02:18:00 | 000,000,120 | —- | C] () – C:\WINDOWS\Esiwof.dat
[2011/05/24 02:18:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Npuqut.bin
[2010/06/18 18:38:18 | 000,000,304 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2010/02/25 11:38:32 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2010/02/25 11:38:24 | 000,004,480 | —- | C] () – C:\WINDOWS\od5.ini
[2010/01/11 08:43:55 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/03 18:15:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/12/01 03:33:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2009/11/30 19:44:53 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2009/11/30 19:42:36 | 000,001,334 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/11/30 19:42:36 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2009/11/30 17:50:14 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/11/30 17:12:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/11/30 15:40:21 | 002,293,286 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/11/30 14:00:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/11/30 13:56:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/11/30 08:48:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/11/30 08:47:34 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,475,262 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,085,074 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/11/29 07:36:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/07/09 11:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodata Limited
[2009/11/30 17:27:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 07:27:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/31 10:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaRad
[2011/02/03 16:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2012/01/16 17:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE
< End of report >
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
aswMBR.txt log:
aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-18 19:38:14
—————————–
19:38:14.953 OS Version: Windows 5.1.2600 Service Pack 3
19:38:14.953 Number of processors: 2 586 0x1706
19:38:14.953 ComputerName: USER-A6AA68022B UserName: USER
19:38:15.500 Initialize success
19:39:53.187 AVAST engine defs: 12011801
19:42:39.000 The log file has been saved successfully to "C:\Documents and Settings\USER\Desktop\aswMBR.txt"
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI