This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

cannot remove Rootkit.TDSS.v3 from XP system [Solved]

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Cavan and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
Hello Cavan

Please download OTL to your desktop.
  • If you are using Firefox, make sure that your download settings are as follows:

    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


netsvcs
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lîk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Deskuop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results Install|LastSuccessTime /rs
%USERPROFILE%\..|smtmp;true;true;true /FP
%temp%\smtmp\*.* /s >
/md5start
iexplore.*
explorer.*
winlogon.*
dll
zx.dll
hlp.dat
/md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.txt and Extras.txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Next,

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.

    Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]


In your next post, please include:
  • OTL.txt
  • Extras.txt
  • The aswMBR log
OTL logfile created on: 1/22/2012 12:17:02 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Emmet Smith\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.98 Mb Total Physical Memory | 97.23 Mb Available Physical Memory | 19.03% Memory free
1.22 Gb Paging File | 0.45 Gb Available in Paging File | 37.24% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 90.35 Gb Free Space | 80.87% Space Free | Partition Type: NTFS

Computer Name: EMMET | User Name: Emmet Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Emmet Smith\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\AOL\1285387552\ee\aolsoftware.exe (AOL LLC)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\America Online 9.0\waol.exe (America Online, Inc.)
PRC - C:\Program Files\America Online 9.0\shellmon.exe (America Online, Inc.)
PRC - C:\Program Files\America Online 9.0\aolwbspd.exe (America Online Inc)
PRC - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\PC Tools Security\NetworkLayer\PCTCFHook.dll ()
MOD - C:\Program Files\PC Tools Security\avengine\sdkBSCtrl.dll ()
MOD - C:\Program Files\PC Tools Security\BDT\BSPatch.dll ()
MOD - C:\WINDOWS\system32\dlcdcfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 944\dlcdcnv4.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
MOD - C:\Program Files\Adobe\Photoshop Elements 3.0\platform.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()
MOD - C:\Program Files\America Online 9.0\xmltok.dll ()
MOD - C:\Program Files\America Online 9.0\zlib.dll ()
MOD - C:\Program Files\America Online 9.0\xmlparse.dll ()


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (HidServ) – File not found
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (dlcd_device) – C:\WINDOWS\System32\dlcdcoms.exe ( )
SRV - (AdobeActiveFileMonitor) – C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
SRV - (PhotoshopElementsDeviceConnect) – C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (NMSSvc) Intel® – C:\WINDOWS\system32\NMSSvc.Exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctBTFix) – C:\WINDOWS\System32\Drivers\pctBTFix.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (PCTBD) – C:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (BCMModem) – C:\WINDOWS\system32\drivers\BCMSM.sys (Broadcom Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (NMSCFG) – C:\WINDOWS\system32\drivers\NMSCFG.SYS (Intel Corporation)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.95\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.95\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/01/12 03:21:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2012/01/21 16:12:53 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/09/26 12:49:47 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1285387552\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/Dcode/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1254091013500 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} https://www1.gotomeeting.com/default/applets/g2mdlax.cab (GoToMeeting Web Starter)
O16 - DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_15)
O16 - DPF: {CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA} http://javadl-esd.sun.com/update/1.5.0/jin…indows-i586.cab (Java Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://trademonster.webex.com/client/T27LB/nbr/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{02E61563-0C41-44B6-8C5D-2779E66A070B}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{26FE9057-D82E-4A03-B091-0E49DD630A76}: NameServer = 205.188.146.145
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/14 00:01:20 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/22 12:12:50 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Emmet Smith\Desktop\OTL.exe
[2012/01/21 23:57:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\Application Data\isoburnerdata
[2012/01/21 18:13:11 | 000,574,424 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2012/01/21 18:13:11 | 000,054,328 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2012/01/21 18:13:11 | 000,035,264 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2012/01/21 16:12:48 | 000,056,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTBD.sys
[2012/01/21 16:12:45 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2012/01/21 16:12:44 | 002,246,608 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2012/01/21 16:12:44 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2012/01/21 16:08:18 | 000,660,992 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2012/01/21 16:08:17 | 000,341,656 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2012/01/21 16:08:15 | 000,253,096 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/01/21 16:08:01 | 000,331,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2012/01/21 16:08:01 | 000,162,584 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012/01/21 16:07:47 | 000,185,560 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTSD.sys
[2012/01/21 16:07:47 | 000,017,848 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctBTFix.sys
[2012/01/21 16:07:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012/01/21 16:07:30 | 000,070,536 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2012/01/21 16:07:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2012/01/21 16:07:02 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2012/01/20 18:57:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\Malware Removal
[2012/01/20 14:48:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\529C535703E4E89B00006564D151FC4E
[2012/01/20 11:15:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\Start Menu\Programs\System Check
[2012/01/20 11:13:03 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Emmet Smith\Recent
[2012/01/17 10:03:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\GMS
[2012/01/12 18:12:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\New Folder
[2012/01/10 16:39:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\TJX
[2012/01/07 14:40:04 | 000,000,000 | —D | C] – C:\0758174999c09bc9a33e771d24a2fef8
[2012/01/07 14:23:19 | 000,000,000 | —D | C] – C:\9b4c345daa14880a3f1249ea
[2012/01/07 14:17:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\Application Data\TestApp
[2012/01/05 16:05:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\Avnet
[2011/12/28 15:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\Buildium
[2011/12/28 14:26:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\MicroSoft
[2011/12/28 13:48:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\DELL
[2011/12/27 17:55:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\2007 Resumes
[2011/12/27 17:48:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\Pitney Bowes
[2011/12/27 17:14:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\Plum Choice
[2011/12/27 15:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Emmet Smith\My Documents\GTech
[2009/09/27 20:31:12 | 000,638,976 | —- | C] ( ) – C:\WINDOWS\System32\dlcdpmui.dll
[2009/09/27 20:31:10 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\dlcdih.exe
[2009/09/27 20:31:09 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\dlcdcomm.dll
[2009/09/27 20:31:09 | 000,368,640 | —- | C] ( ) – C:\WINDOWS\System32\dlcdcfg.exe
[2009/09/27 20:31:09 | 000,114,688 | —- | C] ( ) – C:\WINDOWS\System32\dlcdpplc.dll
[2009/09/27 20:31:08 | 001,134,592 | —- | C] ( ) – C:\WINDOWS\System32\dlcdusb1.dll
[2009/09/27 20:31:08 | 000,774,144 | —- | C] ( ) – C:\WINDOWS\System32\dlcdhbn3.dll
[2009/09/27 20:31:08 | 000,483,328 | —- | C] ( ) – C:\WINDOWS\System32\dlcdlmpm.dll
[2009/09/27 20:31:07 | 000,704,512 | —- | C] ( ) – C:\WINDOWS\System32\dlcdcomc.dll
[2009/09/27 20:31:07 | 000,491,520 | —- | C] ( ) – C:\WINDOWS\System32\dlcdcoms.exe
[2009/09/27 20:31:07 | 000,155,648 | —- | C] ( ) – C:\WINDOWS\System32\dlcdprox.dll
[2009/09/27 20:31:06 | 001,183,744 | —- | C] ( ) – C:\WINDOWS\System32\dlcdserv.dll
[2002/04/10 23:41:00 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[4 C:\Documents and Settings\Emmet Smith\My Documents\*.tmp files -> C:\Documents and Settings\Emmet Smith\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/22 12:12:51 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Emmet Smith\Desktop\OTL.exe
[2012/01/22 12:01:02 | 000,000,246 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/01/22 11:43:02 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/22 11:29:19 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/22 10:00:54 | 001,125,768 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2012/01/22 09:55:56 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/22 09:55:11 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/22 09:54:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/22 09:54:50 | 535,871,488 | -HS- | M] () – C:\hiberfil.sys
[2012/01/21 16:07:51 | 000,001,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor.lnk
[2012/01/20 13:26:30 | 000,000,815 | —- | M] () – C:\Documents and Settings\Emmet Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/20 11:16:02 | 000,000,432 | —- | M] () – C:\Documents and Settings\All Users\Application Data\rWXWFl82Z9aMpR
[2012/01/20 11:15:39 | 000,000,296 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpR
[2012/01/20 11:15:39 | 000,000,176 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpRr
[2012/01/20 11:15:38 | 000,000,853 | —- | M] () – C:\Documents and Settings\Emmet Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/17 19:13:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/16 03:01:46 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/07 15:19:09 | 000,002,110 | —- | M] () – C:\Documents and Settings\Emmet Smith\Desktop\SDASET~1.EXE.lnk
[2012/01/07 14:17:33 | 000,002,110 | —- | M] () – C:\Documents and Settings\Emmet Smith\Desktop\sdasetup[1].exe.lnk
[2012/01/06 23:40:39 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/30 12:33:39 | 000,000,624 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[4 C:\Documents and Settings\Emmet Smith\My Documents\*.tmp files -> C:\Documents and Settings\Emmet Smith\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/21 16:12:47 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2012/01/21 16:12:45 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2012/01/21 16:12:45 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2012/01/21 16:12:44 | 000,003,488 | —- | C] () – C:\WINDOWS\UDB.zip
[2012/01/21 16:12:44 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2012/01/21 16:07:51 | 000,001,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor.lnk
[2012/01/20 11:15:39 | 000,000,296 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpR
[2012/01/20 11:15:39 | 000,000,176 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpRr
[2012/01/20 11:15:38 | 000,000,853 | —- | C] () – C:\Documents and Settings\Emmet Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/20 11:15:32 | 000,000,432 | —- | C] () – C:\Documents and Settings\All Users\Application Data\rWXWFl82Z9aMpR
[2012/01/07 14:38:42 | 000,002,110 | —- | C] () – C:\Documents and Settings\Emmet Smith\Desktop\SDASET~1.EXE.lnk
[2012/01/07 14:17:32 | 000,002,110 | —- | C] () – C:\Documents and Settings\Emmet Smith\Desktop\sdasetup[1].exe.lnk
[2011/12/30 12:33:39 | 000,000,624 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/03/18 10:55:28 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll0334.old
[2011/03/18 10:55:28 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll0146.old
[2010/09/21 15:39:25 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/18 18:09:09 | 000,004,608 | —- | C] () – C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/14 18:37:25 | 000,017,228 | -HS- | C] () – C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\i202
[2010/04/14 18:37:25 | 000,017,228 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\i202
[2010/04/14 14:46:34 | 000,763,832 | —- | C] () – C:\WINDOWS\BDTSupport.dll.old
[2010/03/06 16:53:04 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/09/28 21:08:28 | 000,000,715 | —- | C] () – C:\WINDOWS\aolback.exe.lnk
[2009/09/28 21:04:08 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/27 20:31:59 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2009/09/27 20:31:11 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2009/09/27 20:31:11 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2009/09/27 20:31:10 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2009/09/27 20:31:05 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2009/09/27 20:31:04 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2009/09/27 20:31:04 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2009/09/27 20:31:01 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2009/09/27 20:31:01 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2009/09/27 20:30:59 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2009/09/27 18:35:37 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2009/09/25 12:30:49 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/09/14 00:51:45 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/09/14 00:50:45 | 000,294,864 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/14 00:03:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/09/13 23:58:40 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2003/10/06 13:16:00 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\nvcod.dll
[2003/07/08 12:41:48 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2002/09/03 15:07:03 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/09/03 15:07:00 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/09/03 14:51:48 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2002/09/03 14:51:47 | 000,311,604 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2002/09/03 14:51:46 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2002/09/03 14:51:44 | 000,039,992 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2002/09/03 14:50:11 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/09/03 14:44:25 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2002/09/03 14:44:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2002/09/03 14:37:19 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2002/09/03 14:36:07 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/02/06 08:04:14 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\NMSInst.dll
[2002/01/21 13:17:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PROInst.dll

========== LOP Check ==========

[2012/01/20 14:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\529C535703E4E89B00006564D151FC4E
[2010/04/14 22:00:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avG
[2009/09/27 17:52:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2012/01/22 10:15:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/28 21:07:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/01/21 23:57:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\isoburnerdata
[2011/11/01 18:00:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\PCTools
[2011/08/02 22:13:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\TeamViewer
[2010/06/25 08:32:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\Teby
[2012/01/07 14:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\TestApp
[2010/06/09 19:17:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\Uniblue
[2010/06/24 21:01:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\Vyyxti
[2011/09/08 14:52:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Emmet Smith\Application Data\webex
[2012/01/22 12:01:02 | 000,000,246 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/09/14 00:01:20 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/09/27 19:47:14 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/09/25 11:04:34 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2009/09/14 00:01:20 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/09/26 14:45:20 | 000,009,515 | —- | M] () – C:\DellDriverDownloadManager.application
[2011/05/23 13:16:13 | 000,001,027 | —- | M] () – C:\dlcd.log
[2011/07/15 22:52:19 | 000,000,376 | —- | M] () – C:\dlcdscan.log
[2012/01/22 09:54:50 | 535,871,488 | -HS- | M] () – C:\hiberfil.sys
[2009/09/14 00:01:20 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/08 11:04:28 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/09/14 00:01:20 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/09/27 19:39:44 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/10/10 12:52:39 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/01/22 09:54:49 | 805,306,368 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/09/14 00:00:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/11/09 14:59:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcdPP5C.DLL
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/09/14 00:49:45 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/09/14 00:49:44 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/09/14 00:49:44 | 000,430,080 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2009/09/28 21:07:34 | 000,000,689 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\America Online 9.0.lnk
[2009/10/10 13:01:36 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2010/03/06 16:51:30 | 000,002,002 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Open Office Document.lnk
[2009/10/10 13:01:36 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2009/09/14 00:01:26 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/11/01 00:00:07 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2010/06/15 16:20:12 | 000,001,732 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\WinZip.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >
[2010/09/21 20:10:48 | 000,072,080 | —- | M] () – C:\WINDOWS\Java\g2mdlhlpx.exe
[2010/10/01 09:21:07 | 000,103,784 | —- | M] () – C:\WINDOWS\Java\GoToAssistDownloadHelper.exe

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results Install|LastSuccessTime /rs >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >


< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 02:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/01/22 07:12:14 | 000,035,266 | —- | M] () MD5=35A78068F04374DC3FC85A3129A990D0 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SCF >
[2002/09/03 14:37:53 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/04 02:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/04 02:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie8\iexplore.exe

< MD5 for: IEXPLORE.EXE.HDMP >
[2011/04/09 06:10:57 | 008,068,283 | —- | M] () MD5=12A12A1BE5FEF9224AA6521BB9E56F26 – C:\Documents and Settings\Joanne\Local Settings\temp\WER48c1.dir00\iexplore.exe.hdmp
[2011/04/04 19:59:44 | 008,585,188 | —- | M] () MD5=1733FB52B98EC96CC383C62BB0DCC439 – C:\Documents and Settings\Joanne\Local Settings\temp\WER10bf.dir00\iexplore.exe.hdmp
[2011/03/03 08:10:03 | 007,015,104 | —- | M] () MD5=22F0EC46F3DC84859B693A532CAEB107 – C:\Documents and Settings\Joanne\Local Settings\temp\WERafe8.dir00\iexplore.exe.hdmp
[2011/04/09 06:10:57 | 008,068,283 | —- | M] () MD5=2B8F6A52F74776349DF96368ADCA5D2B – C:\Documents and Settings\Joanne\Local Settings\temp\WER4a49.dir00\iexplore.exe.hdmp
[2011/06/13 20:37:43 | 007,867,800 | —- | M] () MD5=2FDBCBCF80762EA98A9B0E6FF7ACF9C0 – C:\Documents and Settings\Joanne\Local Settings\temp\WERcc5b.dir00\iexplore.exe.hdmp
[2011/06/30 05:28:57 | 007,399,416 | —- | M] () MD5=45785F15D51C4BC826353CFFB3BE0518 – C:\Documents and Settings\Joanne\Local Settings\temp\WER119f.dir00\iexplore.exe.hdmp
[2011/06/15 06:44:39 | 006,047,097 | —- | M] () MD5=4F943936200BF4E6595C062FB597DFEC – C:\Documents and Settings\Joanne\Local Settings\temp\WER5b1c.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:01 | 007,399,416 | —- | M] () MD5=6B8110E0E78F79D379030C3E558D8AD4 – C:\Documents and Settings\Joanne\Local Settings\temp\WER6379.dir00\iexplore.exe.hdmp
[2011/07/08 05:44:49 | 007,310,909 | —- | M] () MD5=89921E4D94F734F56CFB2174F5FAB5BA – C:\Documents and Settings\Joanne\Local Settings\temp\WER3c1b.dir00\iexplore.exe.hdmp
[2011/09/30 05:49:57 | 006,946,605 | —- | M] () MD5=9167A1B6116CD51F4D9946C7739E2925 – C:\Documents and Settings\Joanne\Local Settings\temp\WERc91b.dir00\iexplore.exe.hdmp
[2011/06/13 20:37:43 | 007,867,800 | —- | M] () MD5=919E3B096D208613F056C5EC46D37446 – C:\Documents and Settings\Joanne\Local Settings\temp\WERb265.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:01 | 007,399,416 | —- | M] () MD5=9EC7160DB775452C9ED75610327F539C – C:\Documents and Settings\Joanne\Local Settings\temp\WER6bc6.dir00\iexplore.exe.hdmp
[2011/06/13 20:37:43 | 007,867,800 | —- | M] () MD5=9F289B8EF35381BC560FC1A2A6492D4C – C:\Documents and Settings\Joanne\Local Settings\temp\WER6027.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:02 | 007,399,416 | —- | M] () MD5=A0F8C88E8BC6165D80B19DD10BDEB410 – C:\Documents and Settings\Joanne\Local Settings\temp\WER7f6e.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:02 | 007,399,416 | —- | M] () MD5=A121C540A29809B6B5C3DF0072DBDC82 – C:\Documents and Settings\Joanne\Local Settings\temp\WER89fd.dir00\iexplore.exe.hdmp
[2011/03/23 19:01:41 | 008,706,372 | —- | M] () MD5=A9285CE83B012FF47BBA3A48165524CF – C:\Documents and Settings\Joanne\Local Settings\temp\WER68bf.dir00\iexplore.exe.hdmp
[2011/03/16 19:36:00 | 006,251,409 | —- | M] () MD5=AED14EE8183D2400E2889E8911F16CB9 – C:\Documents and Settings\Joanne\Local Settings\temp\WER2eff.dir00\iexplore.exe.hdmp
[2011/11/23 07:47:14 | 006,736,102 | —- | M] () MD5=B0B2C6D9E43D40C75763D3D65E66C42B – C:\Documents and Settings\Joanne\Local Settings\temp\WER0fb2.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:01 | 007,399,416 | —- | M] () MD5=B9BAC2CBC67C9365063260078BDC4D4E – C:\Documents and Settings\Joanne\Local Settings\temp\WERe152.dir00\iexplore.exe.hdmp
[2011/04/04 19:59:44 | 008,585,188 | —- | M] () MD5=BE2863B590EA56707EFA36E7D73812B7 – C:\Documents and Settings\Joanne\Local Settings\temp\WER1e27.dir00\iexplore.exe.hdmp
[2011/05/08 09:05:55 | 006,954,773 | —- | M] () MD5=C055D9992B592D8FE14364A1197BAFDC – C:\Documents and Settings\Joanne\Local Settings\temp\WER7622.dir00\iexplore.exe.hdmp
[2011/07/20 01:22:06 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WERa087.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:02 | 007,399,416 | —- | M] () MD5=D49D5B5BAD01CFA9E23999A90F15BC15 – C:\Documents and Settings\Joanne\Local Settings\temp\WERba4a.dir00\iexplore.exe.hdmp
[2011/05/07 22:35:32 | 012,757,413 | —- | M] () MD5=DACF683A49B82A73C9F315437FAA1283 – C:\Documents and Settings\Joanne\Local Settings\temp\WERa467.dir00\iexplore.exe.hdmp
[2011/04/26 14:32:11 | 016,527,085 | —- | M] () MD5=E35D5B4D8D7340448FCC4EB043195F62 – C:\Documents and Settings\Emmet Smith\Local Settings\temp\WER3a09.dir00\iexplore.exe.hdmp
[2011/05/07 22:35:29 | 012,757,413 | —- | M] () MD5=F03F5EC0B4F6FDFA7F24A032ADC617A9 – C:\Documents and Settings\Joanne\Local Settings\temp\WER087c.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:00 | 007,399,416 | —- | M] () MD5=F7D78ED38E77B591B720D978BA64A764 – C:\Documents and Settings\Joanne\Local Settings\temp\WER7427.dir00\iexplore.exe.hdmp

< MD5 for: IEXPLORE.EXE.MDMP >
[2011/09/30 05:49:52 | 000,066,029 | —- | M] () MD5=0EDE45D62762758A21D5F970AFD5AB5C – C:\Documents and Settings\Joanne\Local Settings\temp\WERc91b.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=0F5EFB1E7FD593FC28EFC4F8DDAEE6A6 – C:\Documents and Settings\Joanne\Local Settings\temp\WER6379.dir00\iexplore.exe.mdmp
[2011/04/09 06:10:25 | 000,084,343 | —- | M] () MD5=1188C8D17744E250F3DB51455E0B8E7C – C:\Documents and Settings\Joanne\Local Settings\temp\WER4a49.dir00\iexplore.exe.mdmp
[2011/05/08 09:05:24 | 000,080,161 | —- | M] () MD5=16D4EFBC90E59878333ABB95E9289681 – C:\Documents and Settings\Joanne\Local Settings\temp\WER7622.dir00\iexplore.exe.mdmp
[2011/07/20 01:22:05 | 000,078,441 | —- | M] () MD5=1D1D0DCBC5911ADE1808169D18287A15 – C:\Documents and Settings\Joanne\Local Settings\temp\WERa087.dir00\iexplore.exe.mdmp
[2011/03/16 19:35:57 | 000,070,009 | —- | M] () MD5=2F04FCE5E7C5BCAA44E4C9601E6DE660 – C:\Documents and Settings\Joanne\Local Settings\temp\WER2eff.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=42EF5A36FF6E2FC5F3473802F752051F – C:\Documents and Settings\Joanne\Local Settings\temp\WER6bc6.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=468390D89FF599854720F913355AB9A0 – C:\Documents and Settings\Joanne\Local Settings\temp\WERba4a.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=486763DF86A815A06093EF0A032B2A6D – C:\Documents and Settings\Joanne\Local Settings\temp\WER119f.dir00\iexplore.exe.mdmp
[2011/06/15 06:44:13 | 000,068,717 | —- | M] () MD5=5C23DB75DC3828BCC4AFA7EBC4C7507D – C:\Documents and Settings\Joanne\Local Settings\temp\WER5b1c.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=62563AEA24851900755DDFA1C8525BF8 – C:\Documents and Settings\Joanne\Local Settings\temp\WERe152.dir00\iexplore.exe.mdmp
[2011/06/13 20:37:30 | 000,082,000 | —- | M] () MD5=64A4966EAB3C10B58CCF4C34B20D78AE – C:\Documents and Settings\Joanne\Local Settings\temp\WERcc5b.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=6BDF2FE74FAF47B723CA91802DD10CC6 – C:\Documents and Settings\Joanne\Local Settings\temp\WER89fd.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=6DBD28A90BF6BBA6D4DB7155DAB20ACD – C:\Documents and Settings\Joanne\Local Settings\temp\WER7f6e.dir00\iexplore.exe.mdmp
[2011/11/23 07:47:08 | 000,070,786 | —- | M] () MD5=70BAADD2B2401003EDB72DD504C683CD – C:\Documents and Settings\Joanne\Local Settings\temp\WER0fb2.dir00\iexplore.exe.mdmp
[2011/04/26 14:31:29 | 000,107,757 | —- | M] () MD5=91FEDE8FF9F8B2BDAACE7AC45E948D36 – C:\Documents and Settings\Emmet Smith\Local Settings\temp\WER3a09.dir00\iexplore.exe.mdmp
[2011/03/23 19:01:36 | 000,088,908 | —- | M] () MD5=946FB7159E43AF2B4BF4A7C6F390A0FF – C:\Documents and Settings\Joanne\Local Settings\temp\WER68bf.dir00\iexplore.exe.mdmp
[2011/04/04 19:59:35 | 000,086,524 | —- | M] () MD5=9C8690FB127C4A98C6EC37B9F6D14452 – C:\Documents and Settings\Joanne\Local Settings\temp\WER10bf.dir00\iexplore.exe.mdmp
[2011/05/07 22:33:56 | 000,123,489 | —- | M] () MD5=AA4857A2AFE4AFA01032DC50E3F5F710 – C:\Documents and Settings\Joanne\Local Settings\temp\WERa467.dir00\iexplore.exe.mdmp
[2011/04/09 06:10:25 | 000,084,343 | —- | M] () MD5=B3A7EE09742172A4E7D816A3AF7A37E7 – C:\Documents and Settings\Joanne\Local Settings\temp\WER48c1.dir00\iexplore.exe.mdmp
[2011/04/04 19:59:35 | 000,086,524 | —- | M] () MD5=B5836AA11B074897EBA6090D9EC54952 – C:\Documents and Settings\Joanne\Local Settings\temp\WER1e27.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | —- | M] () MD5=B9CAE4D19B5755266E678762F2284D70 – C:\Documents and Settings\Joanne\Local Settings\temp\WER7427.dir00\iexplore.exe.mdmp
[2011/07/08 05:44:24 | 000,084,009 | —- | M] () MD5=BD30E24C25A0321A117CFFB03FC02E44 – C:\Documents and Settings\Joanne\Local Settings\temp\WER3c1b.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:40 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WER0905.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:47 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WER2ba6.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:53 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WER39ad.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:57 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WER4f58.dir00\iexplore.exe.mdmp
[2011/07/20 01:22:01 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WER5c8c.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:26 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WERd22c.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:31 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WERee7e.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:36 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Joanne\Local Settings\temp\WERfcc6.dir00\iexplore.exe.mdmp
[2011/06/13 20:37:27 | 000,082,000 | —- | M] () MD5=EB4107227227CDA6B1F7E17D078AEADB – C:\Documents and Settings\Joanne\Local Settings\temp\WERb265.dir00\iexplore.exe.mdmp
[2011/05/07 22:33:40 | 000,123,489 | —- | M] () MD5=ED1EF1D3E076775CF3C88AF2058DBAFD – C:\Documents and Settings\Joanne\Local Settings\temp\WER087c.dir00\iexplore.exe.mdmp
[2011/06/13 20:37:17 | 000,082,000 | —- | M] () MD5=F30D4C9DE7CA512C1F2C21938D119983 – C:\Documents and Settings\Joanne\Local Settings\temp\WER6027.dir00\iexplore.exe.mdmp
[2011/03/03 08:09:53 | 000,068,908 | —- | M] () MD5=FB80D67431F629326F3EBD9B61289F7A – C:\Documents and Settings\Joanne\Local Settings\temp\WERafe8.dir00\iexplore.exe.mdmp

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/01/22 07:33:35 | 000,094,468 | —- | M] () MD5=3F85C009B337859E5E65C055AD42CD5B – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2002/09/03 14:40:05 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2004/08/04 02:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< MD5 for: WINLOGON.EXE-0957F9B2.PF >
[2012/01/21 22:06:29 | 000,010,994 | —- | M] () MD5=25E53C9F40D62D79B87CC990FC58CC87 – C:\WINDOWS\Prefetch\WINLOGON.EXE-0957F9B2.pf

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
OTL Extras logfile created on: 1/22/2012 12:17:02 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Emmet Smith\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.98 Mb Total Physical Memory | 97.23 Mb Available Physical Memory | 19.03% Memory free
1.22 Gb Paging File | 0.45 Gb Available in Paging File | 37.24% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 90.35 Gb Free Space | 80.87% Space Free | Partition Type: NTFS

Computer Name: EMMET | User Name: Emmet Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer – (Microsoft Corporation)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{199C20D6-10D3-4210-B361-4760209F56AE}" = Citrix online plug-in (Web)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{3248F0A8-6813-11D6-A77B-00B0D0150150}" = J2SE Runtime Environment 5.0 Update 15
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3E5CBADD-2E51-47C1-BBE2-B802DB6DA56A}" = FXDD Malta - MetaTrader 4 4.00
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{678094A1-6250-476B-9AFF-4376E48F135C}" = Citrix online plug-in (DV)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{851C67EF-068A-4060-9EF5-2E3DDCD68382}" = Adobe Photoshop Elements 3.0
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8F1A20DC-251D-47B0-91B7-DCA2523EE6C9}" = McAfee Virtual Technician
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B88DD94-1AAE-41C4-BD95-2D8737D5E9E2}" = Watson
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}" = Avery Wizard 3.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster
"{FA365307-1963-4D16-BD44-113C8F037AAD}" = Citrix online plug-in (HDX)
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"America Online us" = America Online (Choose which version to remove)
"AolCoach" = AOL Coach Version 1.0(Build:20030807.3)
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"Browser Defender_is1" = Browser Defender 4.0
"Dell Photo AIO Printer 944" = Dell Photo AIO Printer 944
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"McAfee Security Scan" = McAfee Security Scan Plus
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Display Driver" = NVIDIA Display Driver
"PROSet" = Intel® PRO Ethernet Adapter and Software
"RealPlayer 6.0" = RealPlayer Basic
"Spyware Doctor" = PC Tools Spyware Doctor 9.0
"StreetPlugin" = Learn2 Player (Uninstall Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.8.0.723

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/21/2012 7:27:36 PM | Computer Name = EMMET | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x00dae1fd.

Error - 1/21/2012 8:35:37 PM | Computer Name = EMMET | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x00dae1fd.

Error - 1/21/2012 8:35:47 PM | Computer Name = EMMET | Source = Application Error | ID = 1001
Description = Fault bucket -1501321604.

Error - 1/21/2012 10:55:32 PM | Computer Name = EMMET | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x00b3e1fd.

Error - 1/21/2012 11:19:59 PM | Computer Name = EMMET | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x00dae1fd.

Error - 1/22/2012 8:38:16 AM | Computer Name = EMMET | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/22/2012 10:08:33 AM | Computer Name = EMMET | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 8.0.6001.19170, fault address 0x00067978.

Error - 1/22/2012 10:50:10 AM | Computer Name = EMMET | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 1/22/2012 10:51:31 AM | Computer Name = EMMET | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 1/22/2012 10:52:27 AM | Computer Name = EMMET | Source = Application Error | ID = 1001
Description = Fault bucket 223121472.

[ System Events ]
Error - 1/22/2012 2:29:33 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 1/22/2012 2:40:56 AM | Computer Name = EMMET | Source = System Error | ID = 1003
Description = Error code 10000050, parameter1 e277bc48, parameter2 00000000, parameter3
f8679c54, parameter4 00000001.

Error - 1/22/2012 2:44:08 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 1/22/2012 2:44:08 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 1/22/2012 2:44:08 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NVSvc service.

Error - 1/22/2012 2:44:51 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the sdCoreService service.

Error - 1/22/2012 2:44:59 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the ThreatFire service to
connect.

Error - 1/22/2012 2:44:59 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7000
Description = The ThreatFire service failed to start due to the following error:
%%1053

Error - 1/22/2012 10:56:28 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NVSvc service.

Error - 1/22/2012 10:57:58 AM | Computer Name = EMMET | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the WZCSVC service.


< End of report >
Hello Cavan

Let's see if we can't get aswMBR to give up a listing for us…

Download RogueKiller to your desktop

  • Quit all running programs
  • For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • When prompted, type 2 and validate
  • The RKreport.txt shall be generated next to the executable.
  • If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply


Then re-try aswMBR…
  • Double click the aswMBR icon to run it.

    Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]

Hi Sunyata,

The link for roguekiller directs me to a http://www.geekstogo.com/forum/files/file/413-roguekiller/ site then to another, is this correct?
Hello Cavan

The link for roguekiller directs me to a http://www.geekstogo.com/forum/files/file/413-roguekiller/ site then to another, is this correct?

Yes. It is correct. On the second site, the download button for the application looks like this:

[external image: Posted Image]
Thanks Sunyata, here is the RKreport:

RogueKiller V6.2.4 [01/12/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Emmet Smith [Admin rights]
Mode: Remove – Date : 01/22/2012 17:00:41

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 1 ¤¤¤
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[257] : NtTerminateProcess @ 0x805839B9 -> HOOKED (TfSysMon.sys @ 0xF84B4930)
SSDT[247] : NtSetValueKey @ 0x8057BC5B -> HOOKED (TfSysMon.sys @ 0xF84B27C0)
SSDT[119] : NtOpenKey @ 0x80568F68 -> HOOKED (TfSysMon.sys @ 0xF84B2130)
SSDT[65] : NtDeleteValueKey @ 0x80595C1A -> HOOKED (TfSysMon.sys @ 0xF84B25C0)
SSDT[63] : NtDeleteKey @ 0x80597FFA -> HOOKED (TfSysMon.sys @ 0xF84B2500)
SSDT[41] : NtCreateKey @ 0x8057376F -> HOOKED (TfSysMon.sys @ 0xF84B2290)

¤¤¤ Infection : Root.MBR ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++
— User —
[MBR] a383a678cd224af9ca496c06637b93d2
[BSP] f0531316a6163d16f4ba254ab3fe3bf4 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT16 [HIDDEN!] Offset (sectors): 63 | Size: 41 Mo
1 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 80325 | Size: 119957 Mo
User != LL1 … KO!
— LL1 —
[MBR] 6670c6d98edebcbd126fe5a6d7238054
[BSP] f0531316a6163d16f4ba254ab3fe3bf4 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT16 [HIDDEN!] Offset (sectors): 63 | Size: 41 Mo
1 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 80325 | Size: 119957 Mo
2 - [ACTIVE] NTFS [HIDDEN!] Offset (sectors): 234372285 | Size: 1 Mo
User != LL2 … KO!
— LL2 —
[MBR] 6670c6d98edebcbd126fe5a6d7238054
[BSP] f0531316a6163d16f4ba254ab3fe3bf4 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT16 [HIDDEN!] Offset (sectors): 63 | Size: 41 Mo
1 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 80325 | Size: 119957 Mo
2 - [ACTIVE] NTFS [HIDDEN!] Offset (sectors): 234372285 | Size: 1 Mo

Finished : << RKreport[1].txt >>
RKreport[1].txt
Hello Cavan

It looks like you have a TDL4 rootkit on your machine. We will have to setup a Linux bootable environment to address this issue…
  • Download and save a copy of the latest Puppy ISO file
  • Download and save a copy of Unetbootin for Windows.
  • Insert an empty USB drive into a USB port on the computer that's being used to create the bootable USB.
  • Launch Unetbootin ….

    [external image: Posted Image]
  • Ensure that Disk Image is selected.
  • Using the browse button … browse to and select the Puppy ISO file.
  • Ensure that Type: is set to USB Drive and that the Drive: letter corresponds to the USB drive.
  • Click OK

Unetbootin will now copy the Puppy files to the USB and make it a bootable device.

Next,

You need to change the boot order of the computer to boot from a USB drive ….

  • Read HERE for instructions how to do this.


Next,

Boot into Puppy Linux. You should see a screen similar to the one below:

[external image: Posted Image]

Next,

Click on each of the drive items found in the bottom left corner to mount them (when mounted they will have a red cross next to them). In this example SDA is the hard drive and has 3 partitions, SDB is the USB drive that Puppy was loaded from.

[external image: Posted Image]

Next,

Launch GParted which is found at Menu > System > GParted partition manager, when launched the following box will open ….

[external image: Posted Image]

Click to select All Drives then click Okay

GParted will scan the computer and then display a window similar to this ….

[external image: Posted Image]


With the GParted window open …

  • Click menu > Graphic > mtPaint-snapshot screen capture
  • A small window will open ….
    • Click Capture Now
    • Click OK
  • The mtPaint program will open ….
    • Click File > Save
    • Double click on ../
    • Double click on mnt/
    • Double click on sdb1/
    • Set File Format to JPEG
    • Enter screenshot1 into the text box
    • Click OK
This will save a file screenshot1.jpeg into the USB drive

Please upload that screenshot in your next post
Hello Cavan

I do not have an option for Removable devices in my setup - Dell Dimension 8250

That's ok. We can still fix you up…


We'll use a CD that we will make bootable. We also need a USB flashdrive that has some space on it. We will not be changing any of the data on the usb device just using it for a file.

If you have an problems with these steps please let me know. These may look complicated but it's fairly straight forward and for the most part automated.

Please note commands used with this tool are case sensitive and must be typed exactly as shown.


Download GETxPUD.exe to the desktop of your clean computer
  • Run GETxPUD.exe by double clicking it.
  • A new folder will appear on the desktop.
  • Open the GETxPUD folder and click on the get&burn.bat
  • The program will download xpud_0.9.2.iso, and when finished, it will open BurnCDCC which will be ready to burn the image.
  • Click on Start and follow the prompts to burn the image to a CD

You may want to print out this part as you will not be able to view these instructions.

  • Attach the usb device attached to the computer
  • Boot the infected computer with the CD you just burned
    • with the CD in the computer, restart the computer
    • The computer must be set to boot from the CD,depending on your computer you can either do this by pressing F12 and selecting the CD as the first boot option or it can be set in the BIOS
  • Once you have the computer set to boot from the CD allow it to boot
  • A Welcome to xPUD screen will appear
  • Click on File
  • Expand mnt
  • sda1,2…usually corresponds to your HDD
  • sdb1 is likely your USB
  • Click on the folder that represents your USB drive (sdb1 ?)
    (you will be able to tell if it the right one as the screen will populate with your files)
  • Press Tool at the top
  • Choose Open Terminal
  • Type the following and press enter:

    dd if=/dev/sda of=mbr.bin bs=512 count=1

    (note there is a space after dd and a space after sda, a space after bin and after 512)
  • After it has finished a file will be located on your USB drive named mbr.bin

To exit out of Xpud
  • close the terminal window
  • click the Home icon
  • Remove the CD and click Power off
  • Click restart system

Once the computer has rebooted open the usb device and locate mbr.bin, zip it up and attach it to your next reply.
Sunyata, I only have the infected computer and I notice instructions are for Clean computer ? Is this a problem? Download GETxPUD.exe to the desktop of your CLEAN computer

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI