This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"XP Antispyware 2012" with WinXP Pro SP3 [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair: Am I in correct place, since I'm not using Vista or 7? Thanks in advance. s dds IS ONLY TOOL THAT WORKED. Virus won't let "browse" function to work or let me open WinZip. . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 11/30/2009 2:00:01 PM System Uptime: 1/13/2012 11:26:49 PM (86 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | P35-DS3L Processor: Intel Pentium III Xeon processor | Socket 775 | 3000/333mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 233 GiB total, 45.967 GiB free. D: is CDROM () E: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP51: 10/19/2011 11:15:02 PM - System Checkpoint RP52: 10/24/2011 5:09:07 PM - Avg Update RP53: 10/24/2011 5:13:08 PM - Software Distribution Service 3.0 RP54: 10/25/2011 5:34:09 PM - System Checkpoint RP55: 10/26/2011 7:05:34 PM - System Checkpoint RP56: 10/27/2011 9:37:37 PM - System Checkpoint RP57: 10/28/2011 9:38:39 PM - System Checkpoint RP58: 10/29/2011 10:14:39 PM - System Checkpoint RP59: 10/30/2011 10:38:39 PM - System Checkpoint RP60: 10/31/2011 10:38:57 PM - System Checkpoint RP61: 11/2/2011 12:43:56 AM - System Checkpoint RP62: 11/3/2011 1:38:56 AM - System Checkpoint RP63: 11/4/2011 2:37:27 AM - System Checkpoint RP64: 11/5/2011 2:38:56 AM - System Checkpoint RP65: 11/6/2011 2:38:56 AM - System Checkpoint RP66: 11/7/2011 3:38:55 AM - System Checkpoint RP67: 11/8/2011 3:39:26 AM - System Checkpoint RP68: 11/9/2011 4:39:28 AM - System Checkpoint RP69: 11/10/2011 5:39:28 AM - System Checkpoint RP70: 11/11/2011 7:49:39 AM - System Checkpoint RP71: 11/12/2011 8:39:29 AM - System Checkpoint RP72: 11/12/2011 6:56:28 PM - Software Distribution Service 3.0 RP73: 11/13/2011 7:43:50 PM - System Checkpoint RP74: 11/15/2011 12:15:02 AM - System Checkpoint RP75: 11/16/2011 1:11:16 AM - System Checkpoint RP76: 11/17/2011 2:11:35 AM - System Checkpoint RP77: 11/18/2011 3:11:17 AM - System Checkpoint RP78: 11/19/2011 3:54:52 AM - System Checkpoint RP79: 11/21/2011 4:39:59 PM - System Checkpoint RP80: 11/22/2011 4:50:33 PM - System Checkpoint RP81: 11/27/2011 5:53:03 PM - System Checkpoint RP82: 11/28/2011 6:42:39 PM - System Checkpoint RP83: 11/29/2011 9:34:00 PM - System Checkpoint RP84: 11/30/2011 10:04:19 PM - System Checkpoint RP85: 12/1/2011 10:32:24 PM - System Checkpoint RP86: 12/2/2011 11:32:23 PM - System Checkpoint RP87: 12/3/2011 11:48:44 PM - System Checkpoint RP88: 12/5/2011 12:32:23 AM - System Checkpoint RP89: 12/6/2011 1:32:23 AM - System Checkpoint RP90: 12/7/2011 1:47:10 AM - System Checkpoint RP91: 12/8/2011 2:32:23 AM - System Checkpoint RP92: 12/9/2011 3:44:24 AM - System Checkpoint RP93: 12/10/2011 3:47:41 AM - System Checkpoint RP94: 12/11/2011 3:51:11 AM - System Checkpoint RP95: 12/12/2011 4:51:10 AM - System Checkpoint RP96: 12/12/2011 9:36:35 AM - Avg Update RP97: 12/13/2011 9:57:24 AM - System Checkpoint RP98: 12/14/2011 10:56:20 AM - System Checkpoint RP99: 12/15/2011 1:29:59 PM - System Checkpoint RP100: 12/16/2011 4:44:23 PM - System Checkpoint RP101: 12/17/2011 2:36:27 PM - Software Distribution Service 3.0 RP102: 12/18/2011 2:51:04 PM - System Checkpoint RP103: 12/19/2011 3:49:34 PM - System Checkpoint RP104: 12/20/2011 3:53:02 PM - System Checkpoint RP105: 12/21/2011 4:51:56 PM - System Checkpoint RP106: 12/29/2011 2:48:26 PM - System Checkpoint RP107: 12/30/2011 3:05:23 PM - System Checkpoint RP108: 12/31/2011 4:16:27 PM - System Checkpoint RP109: 1/1/2012 6:15:36 PM - System Checkpoint RP110: 1/2/2012 6:32:18 PM - System Checkpoint RP111: 1/3/2012 7:19:00 PM - System Checkpoint RP112: 1/4/2012 8:11:14 PM - System Checkpoint RP113: 1/5/2012 9:31:59 PM - System Checkpoint RP114: 1/6/2012 11:16:11 PM - System Checkpoint RP115: 1/8/2012 12:05:25 AM - System Checkpoint RP116: 1/9/2012 1:05:23 AM - System Checkpoint RP117: 1/10/2012 2:34:43 AM - System Checkpoint RP118: 1/11/2012 3:29:24 AM - System Checkpoint RP119: 1/12/2012 4:05:23 AM - System Checkpoint RP120: 1/12/2012 4:53:39 PM - Software Distribution Service 3.0 RP121: 1/13/2012 5:02:49 PM - System Checkpoint RP122: 1/14/2012 5:32:25 PM - System Checkpoint RP123: 1/15/2012 6:32:24 PM - System Checkpoint RP124: 1/16/2012 6:33:03 PM - System Checkpoint . ==== Installed Programs ====================== . 23_24_2500Tour 2400 2400_2500Help 2400_2500trb Acrobat.com Acronis True Image WD Edition Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3 Adobe SVG Viewer 3.0 AiO_Scan AiOSoftware Apple Application Support Apple Software Update AtomTime Pro 3.1d AVG Free 9.0 Bing Bar BufferChm Copy Coupon Printer for Windows CreativeProjects CreativeProjectsTemplates CueTour Destinations Director DocProc DocumentViewer Family Lawyer Deluxe 8.0 Fax Google Earth Plug-in Google Update Helper High Definition Audio Driver Package - KB888111 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Diagnostic Assistant HP Image Zone 4.2 HP Product Detection HP PSC & OfficeJet 4.2 HP Software Update HP Unload DLL Patch hpmdtab HPSystemDiagnostics InstantShare Java Auto Updater Java™ 6 Update 26 KMA LiveUpdate 2.6 (Symantec Corporation) Memories Disc Creator 2.0 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Mozilla Firefox 9.0.1 (x86 en-US) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero Suite NVIDIA Display Control Panel NVIDIA Drivers NVIDIA nView Desktop Manager NVIDIA PhysX OGA Notifier 2.0.0048.0 OnDemand5 Overland PhotoGallery Picasa 3 PrintScreen ProductContext QFolder Quicken 2003 Deluxe QuickProjects QuickTime Readme REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Scan Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2553089) Security Update for 2007 Microsoft Office System (KB2553090) Security Update for 2007 Microsoft Office System (KB2584063) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office Groove 2007 (KB2552997) Security Update for Microsoft Office InfoPath 2007 (KB2510061) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 7 (KB2183461) Security Update for Windows Internet Explorer 7 (KB2360131) Security Update for Windows Internet Explorer 7 (KB2416400) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB2618444) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974455) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) SkinsHP1 Spybot - Search & Destroy SpywareBlaster 4.4 TrayApp Unload Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596686) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office Outlook 2007 (KB2583910) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676-v2) Update for Windows XP (KB2641690) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB976749) Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP WebReg Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live ID Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinRAR archiver WinZip Yahoo! Detect . ==== Event Viewer Messages From Past Week ======== . 1/12/2012 5:46:52 PM, error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: The system cannot find the file specified. 1/12/2012 5:46:52 PM, error: Service Control Manager [7000] - The Lavasoft Ad-Aware Service service failed to start due to the following error: The system cannot find the file specified. . ==== End Of File =========================== >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>SECOND FILE<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 13:22:45.39 on Tue 01/17/2012 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_26 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2456 [GMT -5:00] . AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} . ============== Running Processes =============== . C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe svchost.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\Java\Java Update\jucheck.exe C:\DOCUME~1\USER\LOCALS~1\Temp\oiu0.9914124389852991.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\USER\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [a29a5f0c] c:\documents and settings\user\local settings\application data\qkm.exe mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe" mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\docume~1\user\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\billmi~1.lnk - c:\program files\quicken\billmind.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicke~1.lnk - c:\program files\quicken\bagent.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicke~2.lnk - c:\program files\quicken\QWDLLS.EXE IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1259740138859 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} - hxxps://pbells.broadjump.com/wizlet/attPreQual/static/controls/MotiveClient.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\v43p3nrj.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.wyff4.com/index.html FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;= FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-5-25 64512] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-30 216400] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-30 29712] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-30 243152] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-15 921952] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-15 308136] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-29 136176] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\AAWService.exe [?] S2 mrtRate;mrtRate; [x] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-12-1 1684736] S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-2-28 183560] S3 es1969;ESS 1969 Audio Driver (WDM);c:\windows\system32\drivers\es1969.sys [2010-4-3 72704] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-29 136176] S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys –> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520] . =============== Created Last 30 ================ . 2012-01-17 15:45:14 367104 —-a-w- c:\docume~1\user\locals~1\applic~1\qkm.exe 2011-12-30 09:38:35 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2011-12-30 09:38:35 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2011-12-30 09:38:35 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2011-12-30 09:38:35 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll . ==================== Find3M ==================== . 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe 2011-11-03 15:28:36 386048 —-a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28:36 1292288 —-a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-31 23:43:21 832512 —-a-w- c:\windows\system32\wininet.dll 2011-10-31 23:43:21 78336 —-a-w- c:\windows\system32\ieencode.dll 2011-10-31 23:43:21 1830912 ——w- c:\windows\system32\inetcpl.cpl 2011-10-31 23:43:20 17408 —-a-w- c:\windows\system32\corpol.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-05-25 17:30:49 359953472 —-a-w- c:\program files\gc_w01_ENU_NB.exe . ============= FINISH: 13:23:00.51 ===============
:pullhair: Am I in correct place, since I'm not using Vista or 7? Thanks in advance. s dds IS ONLY TOOL THAT WORKED. Virus won't let "browse" function to work. . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 11/30/2009 2:00:01 PM System Uptime: 1/13/2012 11:26:49 PM (86 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | P35-DS3L Processor: Intel Pentium III Xeon processor | Socket 775 | 3000/333mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 233 GiB total, 45.967 GiB free. D: is CDROM () E: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP51: 10/19/2011 11:15:02 PM - System Checkpoint RP52: 10/24/2011 5:09:07 PM - Avg Update RP53: 10/24/2011 5:13:08 PM - Software Distribution Service 3.0 RP54: 10/25/2011 5:34:09 PM - System Checkpoint RP55: 10/26/2011 7:05:34 PM - System Checkpoint RP56: 10/27/2011 9:37:37 PM - System Checkpoint RP57: 10/28/2011 9:38:39 PM - System Checkpoint RP58: 10/29/2011 10:14:39 PM - System Checkpoint RP59: 10/30/2011 10:38:39 PM - System Checkpoint RP60: 10/31/2011 10:38:57 PM - System Checkpoint RP61: 11/2/2011 12:43:56 AM - System Checkpoint RP62: 11/3/2011 1:38:56 AM - System Checkpoint RP63: 11/4/2011 2:37:27 AM - System Checkpoint RP64: 11/5/2011 2:38:56 AM - System Checkpoint RP65: 11/6/2011 2:38:56 AM - System Checkpoint RP66: 11/7/2011 3:38:55 AM - System Checkpoint RP67: 11/8/2011 3:39:26 AM - System Checkpoint RP68: 11/9/2011 4:39:28 AM - System Checkpoint RP69: 11/10/2011 5:39:28 AM - System Checkpoint RP70: 11/11/2011 7:49:39 AM - System Checkpoint RP71: 11/12/2011 8:39:29 AM - System Checkpoint RP72: 11/12/2011 6:56:28 PM - Software Distribution Service 3.0 RP73: 11/13/2011 7:43:50 PM - System Checkpoint RP74: 11/15/2011 12:15:02 AM - System Checkpoint RP75: 11/16/2011 1:11:16 AM - System Checkpoint RP76: 11/17/2011 2:11:35 AM - System Checkpoint RP77: 11/18/2011 3:11:17 AM - System Checkpoint RP78: 11/19/2011 3:54:52 AM - System Checkpoint RP79: 11/21/2011 4:39:59 PM - System Checkpoint RP80: 11/22/2011 4:50:33 PM - System Checkpoint RP81: 11/27/2011 5:53:03 PM - System Checkpoint RP82: 11/28/2011 6:42:39 PM - System Checkpoint RP83: 11/29/2011 9:34:00 PM - System Checkpoint RP84: 11/30/2011 10:04:19 PM - System Checkpoint RP85: 12/1/2011 10:32:24 PM - System Checkpoint RP86: 12/2/2011 11:32:23 PM - System Checkpoint RP87: 12/3/2011 11:48:44 PM - System Checkpoint RP88: 12/5/2011 12:32:23 AM - System Checkpoint RP89: 12/6/2011 1:32:23 AM - System Checkpoint RP90: 12/7/2011 1:47:10 AM - System Checkpoint RP91: 12/8/2011 2:32:23 AM - System Checkpoint RP92: 12/9/2011 3:44:24 AM - System Checkpoint RP93: 12/10/2011 3:47:41 AM - System Checkpoint RP94: 12/11/2011 3:51:11 AM - System Checkpoint RP95: 12/12/2011 4:51:10 AM - System Checkpoint RP96: 12/12/2011 9:36:35 AM - Avg Update RP97: 12/13/2011 9:57:24 AM - System Checkpoint RP98: 12/14/2011 10:56:20 AM - System Checkpoint RP99: 12/15/2011 1:29:59 PM - System Checkpoint RP100: 12/16/2011 4:44:23 PM - System Checkpoint RP101: 12/17/2011 2:36:27 PM - Software Distribution Service 3.0 RP102: 12/18/2011 2:51:04 PM - System Checkpoint RP103: 12/19/2011 3:49:34 PM - System Checkpoint RP104: 12/20/2011 3:53:02 PM - System Checkpoint RP105: 12/21/2011 4:51:56 PM - System Checkpoint RP106: 12/29/2011 2:48:26 PM - System Checkpoint RP107: 12/30/2011 3:05:23 PM - System Checkpoint RP108: 12/31/2011 4:16:27 PM - System Checkpoint RP109: 1/1/2012 6:15:36 PM - System Checkpoint RP110: 1/2/2012 6:32:18 PM - System Checkpoint RP111: 1/3/2012 7:19:00 PM - System Checkpoint RP112: 1/4/2012 8:11:14 PM - System Checkpoint RP113: 1/5/2012 9:31:59 PM - System Checkpoint RP114: 1/6/2012 11:16:11 PM - System Checkpoint RP115: 1/8/2012 12:05:25 AM - System Checkpoint RP116: 1/9/2012 1:05:23 AM - System Checkpoint RP117: 1/10/2012 2:34:43 AM - System Checkpoint RP118: 1/11/2012 3:29:24 AM - System Checkpoint RP119: 1/12/2012 4:05:23 AM - System Checkpoint RP120: 1/12/2012 4:53:39 PM - Software Distribution Service 3.0 RP121: 1/13/2012 5:02:49 PM - System Checkpoint RP122: 1/14/2012 5:32:25 PM - System Checkpoint RP123: 1/15/2012 6:32:24 PM - System Checkpoint RP124: 1/16/2012 6:33:03 PM - System Checkpoint . ==== Installed Programs ====================== . 23_24_2500Tour 2400 2400_2500Help 2400_2500trb Acrobat.com Acronis True Image WD Edition Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3 Adobe SVG Viewer 3.0 AiO_Scan AiOSoftware Apple Application Support Apple Software Update AtomTime Pro 3.1d AVG Free 9.0 Bing Bar BufferChm Copy Coupon Printer for Windows CreativeProjects CreativeProjectsTemplates CueTour Destinations Director DocProc DocumentViewer Family Lawyer Deluxe 8.0 Fax Google Earth Plug-in Google Update Helper High Definition Audio Driver Package - KB888111 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Diagnostic Assistant HP Image Zone 4.2 HP Product Detection HP PSC & OfficeJet 4.2 HP Software Update HP Unload DLL Patch hpmdtab HPSystemDiagnostics InstantShare Java Auto Updater Java™ 6 Update 26 KMA LiveUpdate 2.6 (Symantec Corporation) Memories Disc Creator 2.0 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Mozilla Firefox 9.0.1 (x86 en-US) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero Suite NVIDIA Display Control Panel NVIDIA Drivers NVIDIA nView Desktop Manager NVIDIA PhysX OGA Notifier 2.0.0048.0 OnDemand5 Overland PhotoGallery Picasa 3 PrintScreen ProductContext QFolder Quicken 2003 Deluxe QuickProjects QuickTime Readme REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Scan Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2553089) Security Update for 2007 Microsoft Office System (KB2553090) Security Update for 2007 Microsoft Office System (KB2584063) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office Groove 2007 (KB2552997) Security Update for Microsoft Office InfoPath 2007 (KB2510061) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 7 (KB2183461) Security Update for Windows Internet Explorer 7 (KB2360131) Security Update for Windows Internet Explorer 7 (KB2416400) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB2618444) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974455) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) SkinsHP1 Spybot - Search & Destroy SpywareBlaster 4.4 TrayApp Unload Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596686) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office Outlook 2007 (KB2583910) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676-v2) Update for Windows XP (KB2641690) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB976749) Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP WebReg Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live ID Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinRAR archiver WinZip Yahoo! Detect . ==== Event Viewer Messages From Past Week ======== . 1/12/2012 5:46:52 PM, error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: The system cannot find the file specified. 1/12/2012 5:46:52 PM, error: Service Control Manager [7000] - The Lavasoft Ad-Aware Service service failed to start due to the following error: The system cannot find the file specified. . ==== End Of File =========================== >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>SECOND FILE<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 13:22:45.39 on Tue 01/17/2012 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_26 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2456 [GMT -5:00] . AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} . ============== Running Processes =============== . C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe svchost.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\Java\Java Update\jucheck.exe C:\DOCUME~1\USER\LOCALS~1\Temp\oiu0.9914124389852991.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\USER\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [a29a5f0c] c:\documents and settings\user\local settings\application data\qkm.exe mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe" mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\docume~1\user\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\billmi~1.lnk - c:\program files\quicken\billmind.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicke~1.lnk - c:\program files\quicken\bagent.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicke~2.lnk - c:\program files\quicken\QWDLLS.EXE IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1259740138859 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} - hxxps://pbells.broadjump.com/wizlet/attPreQual/static/controls/MotiveClient.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\v43p3nrj.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.wyff4.com/index.html FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;= FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-5-25 64512] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-30 216400] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-30 29712] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-30 243152] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-15 921952] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-15 308136] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-29 136176] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\AAWService.exe [?] S2 mrtRate;mrtRate; [x] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-12-1 1684736] S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-2-28 183560] S3 es1969;ESS 1969 Audio Driver (WDM);c:\windows\system32\drivers\es1969.sys [2010-4-3 72704] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-29 136176] S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys –> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520] . =============== Created Last 30 ================ . 2012-01-17 15:45:14 367104 —-a-w- c:\docume~1\user\locals~1\applic~1\qkm.exe 2011-12-30 09:38:35 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2011-12-30 09:38:35 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2011-12-30 09:38:35 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2011-12-30 09:38:35 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll . ==================== Find3M ==================== . 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe 2011-11-03 15:28:36 386048 —-a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28:36 1292288 —-a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-31 23:43:21 832512 —-a-w- c:\windows\system32\wininet.dll 2011-10-31 23:43:21 78336 —-a-w- c:\windows\system32\ieencode.dll 2011-10-31 23:43:21 1830912 ——w- c:\windows\system32\inetcpl.cpl 2011-10-31 23:43:20 17408 —-a-w- c:\windows\system32\corpol.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-05-25 17:30:49 359953472 —-a-w- c:\program files\gc_w01_ENU_NB.exe . ============= FINISH: 13:23:00.51 ===============
Hi shadow5, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

When you download this next tool please rename it to OTL.scr before you download it.

Download OTL to your desktop.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a29a5f0c"=-
:Files
c:\documents and settings\user\local settings\application data\qkm.exe

:Commands
[purity]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer

Next

When running this next tool when asked to download Avast's definitions please click yes.

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • OTL fix log
  • aswMBR log
  • mbr.zip (attached)
Please discribe any and all symptoms.

Thanks
Thank you! The virus won't let me change the name. I d/l'd it on another computer, renaming it as you asked, copied to thumb drive, and tried to move that, renamed, to desktop of affected computer. It would not copy as anything but "OTL". I then put a shortcut to OTL.scr on my bad desktop–tried to double-click it, & virus blocked even that (as it was trying to execute a screen). What should I try next? s
Hi shadow5, Since you got DDS.scr to run try downloading a new copy of OTL renamed to DDS.scr If you still can't get it to run let me know we still have some other tricks.
Sorry I was not clear–I never got DDS.scr to run. Closest was when I downloaded it with new name to a thumb drive on a clean computer, then put thumb drive into bad computer, added a shortcut to thumb drive onto desktop, and "attempted" to execute it. Virus immediately blocked it from running. ALSO: virus will not allow me to open "notepad". Help is still very much appreciated. s
Hi shadow5,

Sorry I'm a bit confused. The first log you posted was from DDS.scr How did you manage to get that log?

Try running OTL in Safe Mode. We'll change the operating instructions a bit.

On your clean machine download and save a copy of OTL to your thumbdrive.

Copy and paste the all the text in the codebox into a notepad

(Do Not copy the word CODE
please note the fix starts with the :)

:Services

:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a29a5f0c"=-
:Files
c:\documents and settings\user\local settings\application data\qkm.exe

:Commands

In the notepad
  • Click File, Save as…, and set the Save in to your thumbdrive
  • In the filename box, type (including quotation marks) as the filename: "scan.txt"
  • Click save

Transfer the thumbdrive to the sick computer:

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.

I'm not sure if OTL will run from the thumb drive so try moving it to the desktop.
  • transfer both OTL and scan.txt to the infected computer's desktop
  • Open OTL by double clicking it
  • double click in the white window at the bottom
  • a message will appear asking if you want to load a custom scan, click yes
  • navigate to where you saved the notepad scan.txt and click on it
  • click open
  • the text should appear in the window.
  • Click the run Fix button
If OTL boots your computer please boot back to safe mode and let it finish. If there isn't a reboot save the log then boot to normal windows and post the log.
Hi, oldman60. I tried your last directions. The scan, in safe mode, showed in its log "Error:could not determine(?)…" all thru the log. I cannot open any…none…Notepad in the sick computer while in normal (not "SAFE") mode. This forum-program will not respond to its "Browse" function either. I tried copying log file while opened in Safe Mode, but when rebooting to normal, the copy was lost during reboot to normal. All seemed to work up to where I ran OTL in Safe Mode; that is until the results log showed all errors. Any other ideas? This seems to be an updated version of the malware, as I cannot use my Notepad or Forum's "Browse". s
I just realized an error I reported: I DID get DDS.scr to run. But I am offered no chance to rename OTL(to "DDS.scr") before downloading it. Even when I d/l it, renamed, on my laptop & copy to thumb drive, it copies to my sick computer as un-renamed–just "OTL"–which is blocked by malware when I try to run it on sick comp. When I ran DDS.scr, I had to copy/paste one log to other one (while both were open as I could not later open them or attach them into the "Browser function" on the forum.), and then paste the entire 'modified log' which I then pasted to the forum message-box. s
Hi shadow5,

Let's try this. When booting ti safe mode make sure you boot into your usual account.

After your computer restarts in safe mofe:

Open windows explorer (right click the Start button and click Explore)

At the top of windows explorer, click tools, folder options, click the
view tab
  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box
Click apply, click ok

Navigate to this folder
c:\documents and settings\user\local settings\application data
  • in the right hand panel locate qkm.exe
  • right click on it and click rename
  • type qkm.old
  • hit enter
  • Accept any warning you may recieve.
  • make sure the file name is now qkm.old
  • Close windows explorer

Try moving OTL to the desktop. Open it and click the quick scan button. Save the log to the usb device.

Reboot to normal windows. You may recieve a message that windows cannot find a file, don't worry about that will be normal. See if you can access this forum with the infected computer and post the log log.
Contained is the log u requested. Could not find "Browse" function; but I was able to open the log file, & copy/paste to this dialogue box. Hoping this is working. and, thx again for your help.
s

OTL logfile created on: 1/18/2012 4:09:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.50 Gb Total Physical Memory | 3.22 Gb Available Physical Memory | 92.09% Memory free
5.34 Gb Paging File | 5.28 Gb Available in Paging File | 98.81% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 45.94 Gb Free Space | 19.73% Space Free | Partition Type: NTFS
Drive F: | 1.92 Gb Total Space | 0.13 Gb Free Space | 7.04% Space Free | Partition Type: FAT32

Computer Name: USER-A6AA68022B | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/07/15 08:26:19 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2005/10/07 15:05:32 | 000,125,440 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (Lavasoft Ad-Aware Service)
SRV - [2011/07/09 11:12:41 | 000,072,704 | —- | M] (Autodata Limited) [Auto | Stopped] – C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe – (Autodata Limited License Service)
SRV - [2011/02/28 17:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/07/21 07:57:49 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 08:26:40 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/07 17:48:38 | 000,817,264 | —- | M] (Acronis) [Auto | Stopped] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2004/03/18 15:55:48 | 000,065,536 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - [2011/09/13 08:47:23 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/25 01:00:36 | 000,064,512 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2011/05/05 08:57:46 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/11/29 07:35:17 | 000,594,208 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\timntr.sys – (timounter)
DRV - [2010/11/29 07:35:10 | 000,170,272 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2010/07/15 08:26:20 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/11/03 06:39:04 | 005,940,736 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/07/28 03:55:00 | 000,143,360 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/05/06 15:06:00 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2008/04/13 12:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/03/13 10:02:41 | 000,019,712 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2008/03/13 10:02:24 | 000,018,304 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2003/10/14 16:10:00 | 000,036,484 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SMBios.sys – (SMBios) Intel ®
DRV - [2002/06/03 11:20:36 | 000,072,704 | —- | M] (ESS Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\es1969.sys – (es1969) ESS 1969 Audio Driver (WDM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 04:38:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/09 16:59:08 | 000,000,000 | —D | M]

[2012/01/18 10:38:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/11/12 09:29:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/30 04:38:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/12 09:29:49 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 09:29:49 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/08/29 12:39:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259740138859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pbells.broadjump.com/wizlet/attPreQ…otiveClient.cab (WebBrowserType Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{56181B06-BEDD-4D31-B675-B7E3A12166AF}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 13:58:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/07/14 19:07:26 | 000,186,168 | —- | M] () - F:\auto-speedo-meter hookup.png – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/18 11:15:09 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/18 11:13:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2012/01/18 10:18:52 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Application Data
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
[2012/01/18 10:18:52 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Templates
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Recent
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Favorites
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 15:55:28 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/18 15:55:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/18 15:11:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/18 15:03:45 | 000,009,849 | —- | M] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2012/01/18 12:02:59 | 000,272,537 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/01/18 12:02:57 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/18 08:07:02 | 091,852,927 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/01/15 13:37:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/14 09:59:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/12 17:00:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/12 16:56:28 | 000,475,262 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/12 16:56:28 | 000,085,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/04 18:28:43 | 000,001,334 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/18 10:18:52 | 000,001,599 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
[2012/01/18 10:18:52 | 000,000,792 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
[2012/01/17 10:45:14 | 000,009,849 | —- | C] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2011/08/22 18:28:51 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/08 09:49:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2011/06/08 09:27:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/08 09:27:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/07 19:30:42 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2011/06/07 19:30:42 | 000,028,885 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2011/06/07 19:10:52 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2011/05/25 12:30:48 | 359,953,472 | —- | C] () – C:\Program Files\gc_w01_ENU_NB.exe
[2011/05/25 09:59:20 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/25 09:59:20 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/05/25 07:05:27 | 000,103,703 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/05/25 07:05:27 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2011/05/25 06:29:25 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/05/24 02:18:00 | 000,000,120 | —- | C] () – C:\WINDOWS\Esiwof.dat
[2011/05/24 02:18:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Npuqut.bin
[2010/06/18 18:38:18 | 000,000,304 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2010/02/25 11:38:32 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2010/02/25 11:38:24 | 000,004,480 | —- | C] () – C:\WINDOWS\od5.ini
[2010/01/11 08:43:55 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/03 18:15:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/12/01 03:33:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2009/11/30 19:44:53 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2009/11/30 19:42:36 | 000,001,334 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/11/30 19:42:36 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2009/11/30 17:50:14 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/11/30 17:12:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/11/30 15:40:21 | 002,293,286 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/11/30 14:00:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/11/30 13:56:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/11/30 08:48:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/11/30 08:47:34 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,475,262 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,085,074 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2010/11/29 07:36:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/07/09 11:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodata Limited
[2009/11/30 17:27:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 07:27:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/31 10:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaRad
[2011/02/03 16:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2012/01/16 17:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE

< End of report >
Yes, I was referring to the browse button at the lower right of the reply windows. And yes, I can now boot to normal windows. And all functions I've tried(Notepad, O/Exp., Internet sites) seem to work correctly/normally. Also, the Malware-Icon has disappeared from the lower right corner of my desktop–NO SIGNS of malware! Whoopee! You're the man–or 'oldman960' if you prefer. Anything else I need to do? Thanks, s
Hi shadow5,

Let's look a little deeper and see if there is anything remaining.

We'll see if we can resolve the browse button issue later. What is diplayed at the lower right where the button should be?

When running this next tool when asked to download Avast's definitions please click yes.

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]



Please post back with
  • OTL fix log
  • aswMBR log
Please discribe any and all symptoms.

Thanks
Here are the files/logs I believe you are asking for. The OTL log is what I had saved in my thumbdrive. The aswMBR log is the saved log from running the aswMBR.exe from my previously-sick computer's desktop. I just realized I do not know how to attach files via the Forum's Browser-Add Attachment function–I can only access it by first clicking on "New Topic". Rather than going further at that point, I just opened the Notebook-files, copied the info via "Select All", and pasted it into Forum's "Fast Reply" box.
s

posted files:

OTL.Txt log:

OTL logfile created on: 1/18/2012 4:09:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.50 Gb Total Physical Memory | 3.22 Gb Available Physical Memory | 92.09% Memory free
5.34 Gb Paging File | 5.28 Gb Available in Paging File | 98.81% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 45.94 Gb Free Space | 19.73% Space Free | Partition Type: NTFS
Drive F: | 1.92 Gb Total Space | 0.13 Gb Free Space | 7.04% Space Free | Partition Type: FAT32

Computer Name: USER-A6AA68022B | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/07/15 08:26:19 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2005/10/07 15:05:32 | 000,125,440 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (Lavasoft Ad-Aware Service)
SRV - [2011/07/09 11:12:41 | 000,072,704 | —- | M] (Autodata Limited) [Auto | Stopped] – C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe – (Autodata Limited License Service)
SRV - [2011/02/28 17:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/07/21 07:57:49 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 08:26:40 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/07 17:48:38 | 000,817,264 | —- | M] (Acronis) [Auto | Stopped] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2004/03/18 15:55:48 | 000,065,536 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - [2011/09/13 08:47:23 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/25 01:00:36 | 000,064,512 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2011/05/05 08:57:46 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/11/29 07:35:17 | 000,594,208 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\timntr.sys – (timounter)
DRV - [2010/11/29 07:35:10 | 000,170,272 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2010/07/15 08:26:20 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/11/03 06:39:04 | 005,940,736 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/07/28 03:55:00 | 000,143,360 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/05/06 15:06:00 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2008/04/13 12:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/03/13 10:02:41 | 000,019,712 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2008/03/13 10:02:24 | 000,018,304 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2003/10/14 16:10:00 | 000,036,484 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SMBios.sys – (SMBios) Intel ®
DRV - [2002/06/03 11:20:36 | 000,072,704 | —- | M] (ESS Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\es1969.sys – (es1969) ESS 1969 Audio Driver (WDM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 04:38:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/09 16:59:08 | 000,000,000 | —D | M]

[2012/01/18 10:38:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/11/12 09:29:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/30 04:38:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/12 09:29:49 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 09:29:49 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/08/29 12:39:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259740138859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pbells.broadjump.com/wizlet/attPreQ…otiveClient.cab (WebBrowserType Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{56181B06-BEDD-4D31-B675-B7E3A12166AF}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 13:58:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/07/14 19:07:26 | 000,186,168 | —- | M] () - F:\auto-speedo-meter hookup.png – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/18 11:15:09 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/18 11:13:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
[2012/01/18 10:38:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2012/01/18 10:18:52 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo
[2012/01/18 10:18:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Application Data
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu
[2012/01/18 10:18:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
[2012/01/18 10:18:52 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Templates
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Recent
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood
[2012/01/18 10:18:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Favorites
[2012/01/18 10:18:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/18 16:08:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/01/18 15:55:28 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/18 15:55:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/18 15:11:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/18 15:03:45 | 000,009,849 | —- | M] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2012/01/18 12:02:59 | 000,272,537 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/01/18 12:02:57 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/18 08:07:02 | 091,852,927 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/01/15 13:37:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/14 09:59:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/12 17:00:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/12 16:56:28 | 000,475,262 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/12 16:56:28 | 000,085,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/04 18:28:43 | 000,001,334 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/18 10:18:52 | 000,001,599 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
[2012/01/18 10:18:52 | 000,000,792 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
[2012/01/17 10:45:14 | 000,009,849 | —- | C] () – C:\Documents and Settings\All Users\Application Data\95b76f01
[2011/08/22 18:28:51 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/08 09:49:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2011/06/08 09:27:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/08 09:27:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/07 19:30:42 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2011/06/07 19:30:42 | 000,028,885 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2011/06/07 19:10:52 | 000,034,468 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2011/05/25 12:30:48 | 359,953,472 | —- | C] () – C:\Program Files\gc_w01_ENU_NB.exe
[2011/05/25 09:59:20 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/25 09:59:20 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/05/25 07:05:27 | 000,103,703 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/05/25 07:05:27 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2011/05/25 06:29:25 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/05/24 02:18:00 | 000,000,120 | —- | C] () – C:\WINDOWS\Esiwof.dat
[2011/05/24 02:18:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Npuqut.bin
[2010/06/18 18:38:18 | 000,000,304 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2010/02/25 11:38:32 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2010/02/25 11:38:24 | 000,004,480 | —- | C] () – C:\WINDOWS\od5.ini
[2010/01/11 08:43:55 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/03 18:15:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/12/01 03:33:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2009/11/30 19:44:53 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2009/11/30 19:42:36 | 000,001,334 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/11/30 19:42:36 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2009/11/30 17:50:14 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/11/30 17:12:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/11/30 15:40:21 | 002,293,286 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/11/30 14:00:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/11/30 13:56:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/11/30 08:48:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/11/30 08:47:34 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,475,262 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,085,074 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2010/11/29 07:36:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/07/09 11:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodata Limited
[2009/11/30 17:27:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 07:27:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/31 10:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaRad
[2011/02/03 16:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2012/01/16 17:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/18 07:22:00 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE

< End of report >

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX


aswMBR.txt log:

aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-18 19:38:14
—————————–
19:38:14.953 OS Version: Windows 5.1.2600 Service Pack 3
19:38:14.953 Number of processors: 2 586 0x1706
19:38:14.953 ComputerName: USER-A6AA68022B UserName: USER
19:38:15.500 Initialize success
19:39:53.187 AVAST engine defs: 12011801
19:42:39.000 The log file has been saved successfully to "C:\Documents and Settings\USER\Desktop\aswMBR.txt"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI